# Chef-metal and security groups

**URL:** https://discourse.chef.io/t/chef-metal-and-security-groups/5809
**Category:** Chef Infra (archive)
**Created:** [October 15, 2014, 6:03pm UTC](https://discourse.chef.io/t/chef-metal-and-security-groups/5809 "2014-10-15T18:03:55Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Douglas\_Garstang](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@Douglas\_Garstang](https://discourse.chef.io/u/Douglas_Garstang)
#### Post date: [October 15, 2014, 6:03pm UTC](https://discourse.chef.io/t/chef-metal-and-security-groups/5809/1 "2014-10-15T18:03:55Z")

</div>

Can I provision EC2 security groups with chef-metal? Seems like it might be  
a nice idea. You certainly don’t want to provision security groups from  
chef on a running instance due to security issues, and since chef-metal is  
designed to start clusters of machines, it follows that it should also  
create the security groups that those instances need to talk to each other.

Doug

---

<div class="post-metadata">

### Author: ![John\_Ewart](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/john_ewart/32/229_2.png) [@John\_Ewart](https://discourse.chef.io/u/John_Ewart)
#### Post date: [October 15, 2014, 7:53pm UTC](https://discourse.chef.io/t/chef-metal-and-security-groups/5809/2 "2014-10-15T19:53:42Z")

</div>

That's on the roadmap for the chef-metal-aws driver and resources, yes;  
along with as many of the other AWS things we can manage via an API.

-John

_John Ewart_ - Sr. Software Engineer

[jewart@getchef.com](mailto:jewart@getchef.com) – \*my: \*Linkedin [http://www.linkedin.com/in/johnwewart](http://www.linkedin.com/in/johnwewart)  
Twitter [http://www.twitter.com/soysamurai](http://www.twitter.com/soysamurai)

_CHEF_

[GETCHEF.COM](http://GETCHEF.COM) [http://www.getchef.com/](http://www.getchef.com/)

TM

_[getchef.com](http://getchef.com)_ [http://www.getchef.com/](http://www.getchef.com/) Blog  
[http://www.opscode.com/blog/](http://www.opscode.com/blog/) Facebook  
[https://www.facebook.com/getchefdotcom](https://www.facebook.com/getchefdotcom) Twitter  
[https://twitter.com/chef](https://twitter.com/chef) Youtube [https://www.youtube.com/getchef](https://www.youtube.com/getchef)

On Wed, Oct 15, 2014 at 11:03 AM, Douglas Garstang [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
wrote:

> Can I provision EC2 security groups with chef-metal? Seems like it might  
> be a nice idea. You certainly don't want to provision security groups from  
> chef on a running instance due to security issues, and since chef-metal is  
> designed to start clusters of machines, it follows that it should also  
> create the security groups that those instances need to talk to each other.
> 
> Doug

---

<div class="post-metadata">

### Author: ![Douglas\_Garstang](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@Douglas\_Garstang](https://discourse.chef.io/u/Douglas_Garstang)
#### Post date: [October 15, 2014, 10:54pm UTC](https://discourse.chef.io/t/chef-metal-and-security-groups/5809/3 "2014-10-15T22:54:39Z")

</div>

Thanks John!

On Wed, Oct 15, 2014 at 12:53 PM, John Ewart [jewart@getchef.com](mailto:jewart@getchef.com) wrote:

> That's on the roadmap for the chef-metal-aws driver and resources, yes;  
> along with as many of the other AWS things we can manage via an API.
> 
> -John
> 
> _John Ewart_ - Sr. Software Engineer
> 
> [jewart@getchef.com](mailto:jewart@getchef.com) – \*my: \*Linkedin  
> [http://www.linkedin.com/in/johnwewart](http://www.linkedin.com/in/johnwewart) Twitter  
> [http://www.twitter.com/soysamurai](http://www.twitter.com/soysamurai)
> 
> _CHEF_
> 
> [GETCHEF.COM](http://GETCHEF.COM) [http://www.getchef.com/](http://www.getchef.com/)
> 
> TM
> 
> _[getchef.com](http://getchef.com)_ [http://www.getchef.com/](http://www.getchef.com/) Blog  
> [http://www.opscode.com/blog/](http://www.opscode.com/blog/) Facebook  
> [https://www.facebook.com/getchefdotcom](https://www.facebook.com/getchefdotcom) Twitter  
> [https://twitter.com/chef](https://twitter.com/chef) Youtube [https://www.youtube.com/getchef](https://www.youtube.com/getchef)
> 
> On Wed, Oct 15, 2014 at 11:03 AM, Douglas Garstang \<  
> [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)\> wrote:
> 
> > Can I provision EC2 security groups with chef-metal? Seems like it might  
> > be a nice idea. You certainly don't want to provision security groups from  
> > chef on a running instance due to security issues, and since chef-metal is  
> > designed to start clusters of machines, it follows that it should also  
> > create the security groups that those instances need to talk to each other.
> > 
> > Doug

--  
Regards,

Douglas Garstang  
[http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
Cell: +1-805-340-5627
