---
title: microvm build
description: Build a MicroVM image and wait for it to be usable
---

## 1. Synopsis

Build a MicroVM image and wait for it to be usable

```sh
microvm build [binary] [options]
```

## 2. Parameters

| Parameter | Kind | Type | Required | Default | Choices | Help |
| --- | --- | --- | --- | --- | --- | --- |
| `binary` | positional | `path` | no | none | any | The aarch64 agentd binary to bake in as the image CMD |
| `--state-dir` | flag | `path` | no | none | any | Where the provisioned-daemon cache lives. Defaults to $MICROVM\_STATE\_DIR or ~/.microvm/runs — the same directory `run`'s ledger uses, so the two commands share one cache |
| `--artifact-uri` | flag | `string` | no | none | any | Where the build artifact already is, as an s3:// URI. See `run --artifact-uri` |
| `--name` | flag | `string` | no | none | any | Image name. Defaults to a per-invocation name |
| `--memory` | flag | `enum` | no | `2048` | `512`, `1024`, `2048`, `4096`, `8192` | Baseline MiB, selecting a documented size class |
| `--dockerfile` | flag | `path` | no | none | any | A Dockerfile to use instead of the library's default |
| `--project` | flag | `path` | no | none | any | A project directory whose dependency files bake an environment layer into the image (#74) |
| `--base-image-version` | flag | `string` | no | none | any | Pin the managed base image to one version instead of taking the service's default |
| `--log-group` | flag | `string` | no | none | any | CloudWatch log group for the build's logs, instead of the service-created `/aws/lambda-microvms/<image-name>`. See `run --log-group` |
| `--log-stream` | flag | `string` | no | none | any | Log stream name prefix inside `--log-group`. The client appends `/<16 hex>` per build attempt and the envelope reports the resolved exact name as `logStream`. See `run --log-stream`. Requires `--log-group` — `build` reads no config file, so the flag is the only place a group can come from |
| `--repair-identity` | flag | `boolean` | no | none | any | Widen the guest so `sethostname` and the boot\_id bind mount work |
| `--reuse` | flag | `boolean` | no | none | any | Reuse an existing image whose build inputs match, instead of building |
| `--port` | flag | `string` | no | none | any | The daemon's port inside the guest |
| `--region` | flag | `enum` | no | none | `us-east-1`, `us-east-2`, `us-west-2`, `eu-west-1`, `ap-northeast-1` | AWS region. Defaults to $AWS\_REGION, then $AWS\_DEFAULT\_REGION, then us-east-1 |
| `--unlisted-region` | flag | `string` | no | none | any | Use a region this client has not seen carry MicroVMs. Costs you the diagnostic |
| `--bucket` | flag | `string` | no | none | any | S3 bucket for the build artifact. Defaults to $MICROVM\_BUCKET |
| `--build-role-arn` | flag | `string` | no | none | any | Build role ARN. Defaults to $MICROVM\_BUILD\_ROLE\_ARN |
| `--execution-role-arn` | flag | `string` | no | none | any | Execution role ARN. Defaults to $MICROVM\_EXECUTION\_ROLE\_ARN |

The 3 global flags (`--json`, `--dense`, `--quiet`) are accepted here as on every command, and are left out of the table above for that reason; see [Global flags](/microvms-agentd/reference/#3-global-flags).

## 3. Response

On success stdout carries one envelope whose `type` is `microvm.image`. Its `data` object carries these keys: `imageIdentifier`, `imageName`, `buildLogGroup`, `logStream`, `size`, `reused`, `agentd`.

[The envelope](/microvms-agentd/reference/envelope/) describes the fields around `data`. [Response types](/microvms-agentd/reference/response-types/) lists every `type` the CLI emits and which commands share each one.

## 4. Failures

A failure exits with one of the statuses on [Exit codes](/microvms-agentd/reference/exit-codes/) and writes the error shape on [The envelope](/microvms-agentd/reference/envelope/): a stable `code` to branch on, an `exitCode` that matches the process status, a human-readable `error`, and `suggestions`.

Where a failure is one this project has measured on the platform, the envelope's `finding` names the section of the platform notes that documents it. The exit-code table links each one.

## 5. Provenance

This page is generated from `docs/manifest.json`, the output of `microvm manifest`, which the CLI derives from its own argument tree. This page reads the `build` entry of `data.commands`. `site/scripts/gen-reference.mjs` writes it into the site's content directory on every `pnpm run sync`, so an edit made here is overwritten by the next run.

To change the page, change the source. Regenerate the source with `mise run manifest` from the repository root; `mise run manifest:check` fails when the committed file no longer matches what the binary emits.