# ChefSpec Encrypted Data Bag Items

**URL:** <https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598>\
**Category:** Chef Infra (archive)\
**Created:** [May 31, 2016, 6:12pm UTC](https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598 "2016-05-31T18:12:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ff-pspiess](https://avatars.discourse-cdn.com/v4/letter/f/d78d45/32.png) [@ff-pspiess](https://discourse.chef.io/u/ff-pspiess)\
**Post date:** [May 31, 2016, 6:12pm UTC](https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598/1 "2016-05-31T18:12:50Z")

</div>

I have read through some other threads and data on the web and have found that the syntax mentioned here ([https://github.com/sethvargo/chefspec/issues/249](https://github.com/sethvargo/chefspec/issues/249)) requires me to use this syntax in my recipe code:

Chef::EncryptedDataBagItem.load(‘test’,‘item’,‘secret’)

rather than the syntax I had been using:

data\_bag\_item(‘test’,‘item’,‘secret’)

For example, if I try to stub the data bag item call, I get this error:

```
  Failure/Error:
    stub_data_bag_item('ff_iblogix', 'peter','peterkey').and_return(
      { 'db' => 'iblogix'}
    )

  ArgumentError:
    wrong number of arguments (3 for 2)

```

And if I change the stub to have only two arguments then my recipe fails to compile with a similar error, “wrong number of arguments (3 for 2)”

Just wondering if I’m doing something wrong in my stub or whether the data\_bag\_item syntax is out of date.

---

<div class="post-metadata">

**Author:** ![jeffbyrnes](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jeffbyrnes/32/1478_2.png) [@jeffbyrnes](https://discourse.chef.io/u/jeffbyrnes)\
**Post date:** [June 6, 2016, 2:13pm UTC](https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598/2 "2016-06-06T14:13:09Z")

</div>

From the [Chef docs on `data_bag_item`](https://docs.chef.io/dsl_recipe.html#data-bag-item):

> If `secret` is not specified, the chef-client looks for a secret at the path specified by the `encrypted_data_bag_secret` setting in the `client.rb` file.

So, in your recipe(s), do is this:

```
data_bag_item 'test', 'item'

```

and, in your tests, you either stub the data bag item or, for an experience more like what you’d have in production, you can have [ChefSpec use a Chef server](https://github.com/sethvargo/chefspec#using-a-chef-server).

If, however, you have the third argument to supply a secret directly, I think ChefSpec will act exactly how you’ve experienced.

---

<div class="post-metadata">

**Author:** ![ff-pspiess](https://avatars.discourse-cdn.com/v4/letter/f/d78d45/32.png) [@ff-pspiess](https://discourse.chef.io/u/ff-pspiess)\
**Post date:** [June 7, 2016, 7:53pm UTC](https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598/3 "2016-06-07T19:53:36Z")

</div>

Thanks Jeff. I have been passing the secret directly in recipes, so I do want to have a third argument. I had read about using the ServerRunner but it isn’t obvious to me how that solves my problem. I still need to provide the data bag contents to it some how. From what I can tell the [ServerRunner](http://www.rubydoc.info/github/sethvargo/chefspec/ChefSpec/ServerRunner) doesn’t provide a method for creating an encrypted data bag.

---

<div class="post-metadata">

**Author:** ![jeffbyrnes](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jeffbyrnes/32/1478_2.png) [@jeffbyrnes](https://discourse.chef.io/u/jeffbyrnes)\
**Post date:** [June 9, 2016, 7:31pm UTC](https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598/4 "2016-06-09T19:31:52Z")

</div>

Well, the idea is, in a test run, you wouldn’t actually be dealing with an encrypted data bag. That’s one reason why the design of `data_bag_item` allows for automatically handling encrypted data bags if necessary.

In our case, we use the `encrypted_data_bag_secret` setting in `client.rb` (which is set as part of an instance’s bootstrap), and omit the third arg (`secret`). In our test cases, we have test data bag items set up, and validate against those non-sensitive test values.

Have you tried just using the [data bag mocking available via the `SoloRunner`](https://github.com/sethvargo/chefspec#data-bag--data-bag-item)? While still leaving `data_bag_item` as-is in your recipe. E.g.,

```
describe 'example::default' do
  before do
    allow(Chef::EncryptedDataBagItem).to receive(:load).with('users', 'svargo').and_return(...)
  end
end
```

---

<div class="post-metadata">

**Author:** ![ff-pspiess](https://avatars.discourse-cdn.com/v4/letter/f/d78d45/32.png) [@ff-pspiess](https://discourse.chef.io/u/ff-pspiess)\
**Post date:** [June 16, 2016, 5:40pm UTC](https://discourse.chef.io/t/chefspec-encrypted-data-bag-items/8598/5 "2016-06-16T17:40:14Z")

</div>

You have given me some ideas. The unit test doesn’t actually deal with the encrypted data, I just needed the recipe to converge. I had not considered setting the encrypted\_data\_bag\_secret in the client.rb. I have been using the ServerRunner because I needed to access Ohai variables.
