# Is \[chef-client::task\] recipe supposed to be idempotent?

**URL:** <https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540>\
**Category:** Chef Infra (archive)\
**Created:** [May 23, 2016, 8:51pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540 "2016-05-23T20:51:11Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 23, 2016, 8:51pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/1 "2016-05-23T20:51:11Z")

</div>

Hello,

I run chef-client as windows scheduled task and inclusion of [chef-client::task] in my runlist and I expected it to create scheduled task only on first run and somehow knew not to create a new task each time chef-client runs but I’m seeing behavior where chef-client recreates task on each run. What would be the proper way to handle this.

G

---

<div class="post-metadata">

**Author:** ![chris\_sullivan](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@chris\_sullivan](https://discourse.chef.io/u/chris_sullivan)\
**Post date:** [May 24, 2016, 8:31am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/2 "2016-05-24T08:31:02Z")

</div>

Hi artisticcheese,

My original response did not come through for some reason so here is an abbreviated version.

The task is being created by windows\_task resource which is declared in the windows cookbook.

If the schedule task action is :create there are three ways the resource can be updated

1. Using the force setting of the resource
2. The schedule task user changes
3. The schedule task command changes

Suspect that the resource is not idempotent because of 3. Why?

This is likely to be down to a Ruby/PowerShell issue around quotes and/or backslashes which need to be escaped out.

Your options

1. Log an issue at [https://github.com/chef-cookbooks/windows/issues](https://github.com/chef-cookbooks/windows/issues)
2. Pull the resource from the resource queue and add an only\_if, if the task exists then do not update
3. Monkey patch the provider

---

<div class="post-metadata">

**Author:** ![chris\_sullivan](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@chris\_sullivan](https://discourse.chef.io/u/chris_sullivan)\
**Post date:** [May 24, 2016, 8:48am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/3 "2016-05-24T08:48:44Z")

</div>

I’ve just pushed the chef-client cookbook across to a VM and tested with Chef-Zero just running the task recipe and added a pry breakpoint in the Windows cookbook task provider.

The code that does the idempotency check is

```auto
def task_need_update?
  # gsub needed as schtasks converts single quotes to double quotes on creation
  @current_resource.command != @new_resource.command.tr("'", "\"") ||
    @current_resource.user != @new_resource.user
end

```

The values for user in the current and new resource definitions are the same.

The command being run by the schedule task is

```auto
@current_resource.command=> "cmd /c \" C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 > NUL 2>&1\""
@new_resource.command=> "cmd /c ' C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 > NUL 2>&1'"
@new_resource.command.tr("'", "\"") => "cmd /c \" C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 > NUL 2>&1\""

```

With the default attribute settings I’m not getting any resources updated and it looks idempotent to me. have you overridden any of the attributes below?

```auto
node['chef_client']['ruby_bin']} 
node['chef_client']['bin']
node['chef_client']['log_dir']
node['chef_client']['conf_dir']
node['chef_client']['splay']
node['chef_client']['task']['user']

```

Can you supply an extract of the log (debug mode preferably) to show that the resource is not idempotent, chef-client version, cookbook versions of chef-client and windows.

---

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 24, 2016, 11:46am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/4 "2016-05-24T11:46:42Z")

</div>

I have a environment override for [task][frequency\_modifier]. Would that trigger chef-client to recreate task on each run? If it is then how do modify frequency for different environments?

```
{
  "chef_client": {
    "task": {
      "frequency_modifier": 17
    }
  }
}

```

debug log is below which shows new task is being created

```
[2016-05-24T19:12:56-06:00] INFO: Processing windows_task[chef-client] action create (chef-client::task line 32)
[2016-05-24T19:12:56-06:00] DEBUG: Providers for generic windows_task resource enabled on node include: [LWRP provider windows_task from cookbook windows]
[2016-05-24T19:12:56-06:00] DEBUG: Provider for action create on resource windows_task[chef-client] is LWRP provider windows_task from cookbook windows
[2016-05-24T19:12:56-06:00] DEBUG: Looking for existing tasks
[2016-05-24T19:12:56-06:00] DEBUG: running: 
[2016-05-24T19:12:56-06:00] DEBUG: schtasks /CREATE /TN "chef-client" /F /SC "minute" /MO "27" /ST "19:39" /TR "cmd /c \" C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 > NUL 2>&1\"" /RU "SYSTEM" /RL "HIGHEST" 
[2016-05-24T19:12:56-06:00] INFO: windows_task[chef-client] task created
[2016-05-24T19:12:56-06:00] DEBUG: Saving the current state of node CLDPOCCS0062

```

Chef-client 12.10.24, Windows 2012 R2, windows cookbook 1.41.0, chef-client cookbook 4.5.0

---

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 25, 2016, 2:07pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/5 "2016-05-25T14:07:49Z")

</div>

here is showing that task is being recreate on each run

![](https://sea2.discourse-cdn.com/flex016/images/transparent.png)

---

<div class="post-metadata">

**Author:** ![chris\_sullivan](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@chris\_sullivan](https://discourse.chef.io/u/chris_sullivan)\
**Post date:** [May 26, 2016, 8:34am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/6 "2016-05-26T08:34:03Z")

</div>

Hi artisticcheese,

I’ve had another look just calling chef-client task … sure enough it is not idempotent, perhaps my original tests were using an older version of the cookbook? Using version 4.5.2 of the chef-client cookbook the windows\_task resource in the task recipe is not idempotent. I’d probably log an issue on the Github of the chef-client cookbook.

FYI, the windows\_task resource runs schtasks (although there is a pending pull for using OLE32, personally I think it would be better if a PowerShell provider was written for Windows 2012/8.0). On my test box I get the following

```auto
C:\>schtasks /Query /FO LIST /V /TN "chef-client"

Folder: \
HostName: TEST-WIN20-2
TaskName: \chef-client
Next Run Time: 5/26/2016 8:47:00 AM
Status: Ready
Logon Mode: Interactive/Background
Last Run Time: N/A
Last Result: 1
Author: vagrant
Task To Run: cmd /c " C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 "
Start In: N/A
Comment: N/A
Scheduled Task State: Enabled
Idle Time: Disabled
Power Management: Stop On Battery Mode, No Start On Batteries
Run As User: SYSTEM
Delete Task If Not Rescheduled: Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule: Scheduling data is not available in this format.
Schedule Type: One Time Only, Minute
Start Time: 8:47:00 AM
Start Date: 5/26/2016
End Date: N/A
Days: N/A
Months: N/A
Repeat: Every: 0 Hour(s), 30 Minute(s)
Repeat: Until: Time: None
Repeat: Until: Duration: Disabled
Repeat: Stop If Still Running: Disabled

```

The windows\_task provider checks the current value of the task\_to\_run against the one specified in the new resource.

The new resource looks like this

```auto
windows_task 'chef-client' do
  run_level :highest
  command "cmd /c \\\"#{node['chef_client']['ruby_bin']} #{node['chef_client']['bin']} \
  -L #{File.join(node['chef_client']['log_dir'], 'client.log')} \
  -c #{File.join(node['chef_client']['conf_dir'], 'client.rb')} -s #{node['chef_client']['splay']} > NUL 2>&1\\\""

  user node['chef_client']['task']['user']
  password node['chef_client']['task']['password']
  frequency node['chef_client']['task']['frequency'].to_sym
  frequency_modifier node['chef_client']['task']['frequency_modifier']
  start_time node['chef_client']['task']['start_time'] || start_time
end

```

As you can see the command has a re-direct which is being lost when the schedule tasks is being saved, you can also see this by opening the task scheduler, locating chef-client, double clicking, select actions tab, edit. Sticking a breakpoint on the provider I can see the following

```auto
@current_resource.command => "cmd /c \" C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \""
@new_resource.command => "cmd /c \\\" C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 > NUL 2>&1\\\""

```

---

<div class="post-metadata">

**Author:** ![chris\_sullivan](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@chris\_sullivan](https://discourse.chef.io/u/chris_sullivan)\
**Post date:** [May 26, 2016, 8:51am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/7 "2016-05-26T08:51:57Z")

</div>

The command that is generated by chef-client is pretty complex with regards to backslashes and quotes

```auto
cmd => "schtasks /CREATE /TN \"chef-client\" /F /SC \"minute\" /MO \"30\" /ST \"09:10\" /TR \"cmd /c \\\" C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 > NUL 2>&1\\\"\" /RU \"SYSTEM\" /RL \"HIGHEST\""

```

Started to debug but I suspect this will burn a couple of hours, definitely ping over an issue on the chef-client github, if I get time I’ll have another look myself.

Chris.

---

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 26, 2016, 2:15pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/8 "2016-05-26T14:15:16Z")

</div>

I created issue on github but I’m not sure I did it for correct cookbook.

> <https://github.com/chef-cookbooks/chef-client/issues/397>

---

<div class="post-metadata">

**Author:** ![Matt\_Wrock](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/matt_wrock/32/3394_2.png) [@Matt\_Wrock](https://discourse.chef.io/u/Matt_Wrock)\
**Post date:** [May 27, 2016, 7:17am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/9 "2016-05-27T07:17:53Z")

</div>

This requires fixes in both the windows cookbook as well as chef-client. I have submitted [https://github.com/chef-cookbooks/windows/pull/365](https://github.com/chef-cookbooks/windows/pull/365) and [https://github.com/chef-cookbooks/chef-client/pull/398](https://github.com/chef-cookbooks/chef-client/pull/398) to address this.

---

<div class="post-metadata">

**Author:** ![chris\_sullivan](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@chris\_sullivan](https://discourse.chef.io/u/chris_sullivan)\
**Post date:** [May 27, 2016, 7:34am UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/10 "2016-05-27T07:34:03Z")

</div>

Thank you @Matt_Wrock

---

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 27, 2016, 4:22pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/11 "2016-05-27T16:22:06Z")

</div>

I updated Windows Cookbook to version 1.42.0 and now it still tries to create a new task on each run but fails with error below.

#\<Mixlib::ShellOut::ShellCommandFailed: windows\_task[chef-client] (chef-client::task line 32) had an error: Mixlib::ShellOut::ShellCommandFailed: Expected process to exit with [0], but received ‘-2147467259’ ---- Begin output of schtasks /CREATE /TN “chef-client” /F /SC “minute” /MO “30” /ST “10:48” /TR “cmd /c \” C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \> NUL 2\>&1\"" /RU “SYSTEM” /RL “HIGHEST” ---- STDOUT: STDERR: ---- End output of schtasks /CREATE /TN “chef-client” /F /SC “minute” /MO “30” /ST “10:48” /TR “cmd /c \” C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \> NUL 2\>&1\"" /RU “SYSTEM” /RL “HIGHEST” ---- Ran schtasks /CREATE /TN “chef-client” /F /SC “minute” /MO “30” /ST “10:48” /TR “cmd /c \” C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \> NUL 2\>&1\"" /RU “SYSTEM” /RL “HIGHEST” returned -2147467259\> had an error:  
windows\_task[chef-client] (chef-client::task line 32) had an error: Mixlib::ShellOut::ShellCommandFailed: Expected process to exit with [0], but received ‘-2147467259’ ---- Begin output of schtasks /CREATE /TN “chef-client” /F /SC “minute” /MO “30” /ST “10:48” /TR “cmd /c \” C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \> NUL 2\>&1\"" /RU “SYSTEM” /RL “HIGHEST” ---- STDOUT: STDERR: ---- End output of schtasks /CREATE /TN “chef-client” /F /SC “minute” /MO “30” /ST “10:48” /TR “cmd /c \” C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \> NUL 2\>&1\"" /RU “SYSTEM” /RL “HIGHEST” ---- Ran schtasks /CREATE /TN “chef-client” /F /SC “minute” /MO “30” /ST “10:48” /TR “cmd /c \” C:/opscode/chef/bin/chef-client -L C:/chef/log/client.log -c C:/chef/client.rb -s 300 \> NUL 2\>&1\"" /RU “SYSTEM” /RL “HIGHEST” returned -2147467259

---

<div class="post-metadata">

**Author:** ![Matt\_Wrock](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/matt_wrock/32/3394_2.png) [@Matt\_Wrock](https://discourse.chef.io/u/Matt_Wrock)\
**Post date:** [May 27, 2016, 4:33pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/12 "2016-05-27T16:33:44Z")

</div>

we are in the midst of changing the chef-client cookbook to work with the windows changes. chef-client 4.5.3 has just ben released so please try now with that version.

---

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 27, 2016, 5:06pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/13 "2016-05-27T17:06:07Z")

</div>

Well it fixed issue with idempotency but broke ability to override task attributes. Previously it will recreate task but will honor task attributes overriden but now it does not.  
If I have a task with default attribute of 30 mins and then override default in environment, it will not be recreated with new attribute.

```
{
  "chef_client": {
    "task": {
      "frequency_modifier": 17
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Matt\_Wrock](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/matt_wrock/32/3394_2.png) [@Matt\_Wrock](https://discourse.chef.io/u/Matt_Wrock)\
**Post date:** [May 27, 2016, 5:41pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/14 "2016-05-27T17:41:01Z")

</div>

ugh yes. For some reason the task idempotency (and I don’t think this is new) is based solely on the command and user name and it ignores all other attribute changes. I just created [this issue](https://github.com/chef-cookbooks/windows/issues/366) to track this problem. In the meantime, you could work around the issue by removing the task prior to the chef-client task recipe.

---

<div class="post-metadata">

**Author:** ![artisticcheese](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@artisticcheese](https://discourse.chef.io/u/artisticcheese)\
**Post date:** [May 27, 2016, 6:20pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/15 "2016-05-27T18:20:06Z")

</div>

Well if I delete task then chef-client will not run. So I need to delete task and then manually run chef-client. Chicken and egg scenario.

---

<div class="post-metadata">

**Author:** ![Matt\_Wrock](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/matt_wrock/32/3394_2.png) [@Matt\_Wrock](https://discourse.chef.io/u/Matt_Wrock)\
**Post date:** [May 27, 2016, 6:39pm UTC](https://discourse.chef.io/t/is-chef-client-task-recipe-supposed-to-be-idempotent/8540/16 "2016-05-27T18:39:31Z")

</div>

Sorry for the confusion. What I mean is to delete the task and then run the chef-client recipe in the same run. I think that should effectively put you back in your original position which is not ideal but should “work”.
