This document explains, step by step, the combined Python async and PowerShell scripts used to provision a Windows VM in Azure, capture a snapshot, and automatically convert/export it as a bootable VHD.
- Loads environment variables for Azure credentials, SMTP, and webhook configuration.
- Sets global variables for:
- Storage account keys
- Snapshot URLs
- SAS tokens for secure access
- Prepares helper functions for:
- Logging (
print_info,print_warn,print_error,print_success) - Sending webhook status updates (
post_status_update)
- Logging (
-
Stop VM safely:
- Calls
stop_vm_to_snapshotto deallocate the VM. - Ensures the OS disk is in a consistent state.
- Calls
-
Create snapshot:
- Copies the VM OS disk using
compute_client.snapshots.begin_create_or_update.
- Copies the VM OS disk using
-
Generate SAS URL for snapshot:
- Uses
compute_client.disks.begin_exportto produce a secure, temporary download link.
- Uses
-
Restart VM:
- Calls
restart_vmafter snapshot creation.
- Calls
- Creates a temporary Azure storage account for storing VHD exports.
- Creates a container (
vhdusb) and generates a SAS token for uploading fixed-size bootable VHD files using AzCopy.
- Dynamically generates a
setup.ps1script with placeholders replaced for:SNAPSHOT_URLAZURE_SAS_TOKENWEBHOOK_URL
- The script is uploaded to blob storage and executed on the VM using
CustomScriptExtension.
- Virtual Network and Subnet: Creates VNet and subnet for the VM.
- Public IP: Assigns public IP to VM NIC.
- Network Security Group (NSG): Adds inbound rules for required ports (
PORTS_TO_OPEN). - Network Interface (NIC): Attaches subnet, public IP, and NSG.
- Defines OS disk and VM image (fresh Windows Marketplace image).
- Sets admin credentials and security profile (Trusted Launch).
- Creates VM using
compute_client.virtual_machines.begin_create_or_update.
- Verifies public IP assignment.
- Creates DNS zone and A records:
pin.{subdomain}drop.{subdomain}web.{subdomain}
- Retries NS delegation verification using public resolvers.
- Installs
CustomScriptExtensionon VM. - Executes uploaded PowerShell setup script.
- Updates webhook with success/failure of script execution.
-
Admin Elevation:
- Checks for admin privileges; relaunches if necessary.
-
System Debloat:
- Registry tweaks for telemetry, Cortana, Windows Search, Edge first-run, and Windows Update auto settings.
- Disables unnecessary services (
WSearch,DiagTrack,WerSvc).
-
User Debloat:
- Adjusts HKCU keys for OneDrive, Xbox, GameBar, Office, notifications, and lock screen features.
-
Network Profile Enforcement:
- Forces all network profiles to Private.
- Disables discovery-related firewall rules.
-
Post-Reboot Helper:
- Ensures all tweaks persist after Hyper-V installation.
- Creates a watchdog script to enforce Private network profiles.
- Registers scheduled tasks for post-reboot execution.
-
Enable Hyper-V:
- Checks if
Microsoft-Hyper-V-Allis installed. - Enables Hyper-V if not already enabled and schedules a reboot.
- Checks if
-
VHD Download & Conversion:
- Downloads snapshot VHD via
wget(resumable). - Converts dynamic VHD to fixed-size VHD using
Convert-VHD.
- Downloads snapshot VHD via
-
Free Space Zeroing:
- Uses
sdeleteorcipher /wto zero unused space, optimizing for USB export.
- Uses
-
VHD Optimization:
- Compacts VHD using
Optimize-VHDto minimize size.
- Compacts VHD using
-
VHD Upload:
- Uploads fixed VHD to Azure via AzCopy with SAS token.
- Script ensures:
- All network profiles remain Private.
NlaSvcand discovery-related services stay disabled.- Scheduled tasks enforce network settings across reboots.
- Removes temporary helper scripts.
- Unregisters scheduled tasks.
- Logs progress and errors to:
C:\Program Files\Logs\setup_hyperv_log.txt
- Sends webhook notifications at each significant step.
- Sends
completedwebhook status. - Optionally, sends email with:
- VM details
- VHD download link
- AzCopy release link
- Each major step wrapped in
try/catch. - On failure:
- Sends
failedwebhook status. - Cleans up Azure resources.
- Sends
- Ensures robust handling of partial failures, network issues, or file download errors.
The combined Python and PowerShell automation pipeline allows:
- Fully automated VM provisioning in Azure.
- Snapshot creation and export to storage.
- Hyper-V setup on Windows VM, including debloating and network hardening.
- Conversion to bootable fixed VHD with free-space zeroing and optimization.
- Automated upload to Azure storage or local USB export.
- Webhook and email notifications at every step.
- Post-reboot persistence with watchdog scripts.
This enables a reliable cloud → bootable Hyper-V/USB workflow with minimal manual intervention.