# Kitchen-ec2 0.9.0 / iam\_profile\_name Something missing?

**URL:** <https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603>\
**Category:** Chef Infra (archive)\
**Created:** [May 20, 2015, 6:16pm UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603 "2015-05-20T18:16:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luis\_Cosmes](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/luis_cosmes/32/79_2.png) [@Luis\_Cosmes](https://discourse.chef.io/u/Luis_Cosmes)\
**Post date:** [May 20, 2015, 6:16pm UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/1 "2015-05-20T18:16:17Z")

</div>

Hi,

Testing the new iam\_profile\_name, which I understand can be used to set the  
role when creating a new instance via kitchen-ec2 I updated the  
corresponding .kitchen.yml file, but the instance does not get any role  
assigned. Folowing is the config I used and the results from the created  
instance. I am thinking maybe I missed something obvious that I can’t see?

Luis

- .kitchen.yml config \*

## Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ head .kitchen.yml

driver:  
name: ec2  
aws\_ssh\_key\_id: [my\_ssh\_key\_id]  
region: us-east-1  
availability\_zone: us-east-1b  
security\_group\_ids: [“sg-YYYYYY”]  
subnet\_id: "subnet-aaaaaaa"  
instance\_type: t2.small  
iam\_profile\_name: master

- “master” role exists in IAM \*  
Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws iam get-role --role-name  
master --query ‘Role.{RoleName:RoleName,Arn:Arn}’  
{  
“RoleName”: “master”,  
“Arn”: “arn:aws:iam::663255216447:role/master”  
}

- kitchen converge creates the new instance, and doesn’t spit any errors \*

Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ kitchen converge def  
-----\> Starting Kitchen (v1.4.0)  
$$$$$$ WARN: The driver[Kitchen::Driver::Ec2] config key `username` is  
deprecated, please use `transport.username`  
-----\> Creating …  
Creating \<\>…  
If you are not using an account that qualifies under the AWS  
free-tier, you may be charged to run these suites. The charge  
should be minimal, but neither Test Kitchen nor its maintainers  
are responsible for your incurred costs.

```
   Instance <i-b517ad65> requested.
   EC2 instance <i-b517ad65> created.

```

…

- The created instance, however, does not contain a role \*

Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws ec2 describe-instances  
–instance-ids i-b517ad65 --query  
’Reservations[_].Instances[_].IamInstanceProfile’  
[  
[]  
]

–

Are you creating an ERP FrankenCloud? Watch 2:11 video  
[http://erpfrankencloud.com?utm\_medium=email\_footer](http://erpfrankencloud.com?utm_medium=email_footer)

---

<div class="post-metadata">

**Author:** ![coderanger](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/coderanger/32/5_2.png) [@coderanger](https://discourse.chef.io/u/coderanger)\
**Post date:** [May 20, 2015, 6:50pm UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/2 "2015-05-20T18:50:39Z")

</div>

Instance profiles are not the same as IAM roles. While normally there is a one-to-one mapping, I don't see any code in kitchen to automatically create instance profiles for you the way that some other tools do. Create the insp yourself and it should work.

--Noah

On May 20, 2015, at 11:16 AM, Luis Cosmes [lcosmes@financialforce.com](mailto:lcosmes@financialforce.com) wrote:

> Hi,
> 
> Testing the new iam\_profile\_name, which I understand can be used to set the role when creating a new instance via kitchen-ec2 I updated the corresponding .kitchen.yml file, but the instance does not get any role assigned. Folowing is the config I used and the results from the created instance. I am thinking maybe I missed something obvious that I can't see?
> 
> Luis
> 
> - .kitchen.yml config \*
> 
> ## Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ head .kitchen.yml
> 
> driver:  
> name: ec2  
> aws\_ssh\_key\_id: [my\_ssh\_key\_id]  
> region: us-east-1  
> availability\_zone: us-east-1b  
> security\_group\_ids: ["sg-YYYYYY"]  
> subnet\_id: "subnet-aaaaaaa"  
> instance\_type: t2.small  
> iam\_profile\_name: master
> 
> - "master" role exists in IAM \*  
> Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws iam get-role --role-name master --query 'Role.{RoleName:RoleName,Arn:Arn}'  
> {  
> "RoleName": "master",  
> "Arn": "arn:aws:iam::663255216447:role/master"  
> }
> 
> - kitchen converge creates the new instance, and doesn't spit any errors \*
> 
> Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ kitchen converge def  
> -----\> Starting Kitchen (v1.4.0)  
> $$$$$$ WARN: The driver[Kitchen::Driver::Ec2] config key `username` is deprecated, please use `transport.username`  
> -----\> Creating ...  
> Creating \<\>...  
> If you are not using an account that qualifies under the AWS  
> free-tier, you may be charged to run these suites. The charge  
> should be minimal, but neither Test Kitchen nor its maintainers  
> are responsible for your incurred costs.
> 
> ```
> Instance <i-b517ad65> requested.
> EC2 instance <i-b517ad65> created.
> 
> ```
> 
> ...
> 
> - The created instance, however, does not contain a role \*
> 
> Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws ec2 describe-instances --instance-ids i-b517ad65 --query 'Reservations[_].Instances[_].IamInstanceProfile'  
> [  
>   
> ]
> 
> Are you creating an ERP FrankenCloud? Watch 2:11 video

---

<div class="post-metadata">

**Author:** ![Yoshi\_Spendiff](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/yoshi_spendiff/32/13_2.png) [@Yoshi\_Spendiff](https://discourse.chef.io/u/Yoshi_Spendiff)\
**Post date:** [May 20, 2015, 10:38pm UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/3 "2015-05-20T22:38:33Z")

</div>

I'm getting the same with a with an iam role/instance profile with the same  
name. Both of the following commands return correct values

aws iam get-role --role-name webServer  
aws iam get-instance-profile --instance-profile-name webServer

In my .kitchen.yml I have:

driver:  
iam\_profile\_name: webServer

The iam role was created via the AWS console so the name definitely matches  
with the instance profile.

On Wed, May 20, 2015 at 11:50 AM, Noah Kantrowitz [noah@coderanger.net](mailto:noah@coderanger.net)  
wrote:

> Instance profiles are not the same as IAM roles. While normally there is a  
> one-to-one mapping, I don't see any code in kitchen to automatically create  
> instance profiles for you the way that some other tools do. Create the insp  
> yourself and it should work.
> 
> --Noah
> 
> On May 20, 2015, at 11:16 AM, Luis Cosmes [lcosmes@financialforce.com](mailto:lcosmes@financialforce.com)  
> wrote:
> 
> > Hi,
> > 
> > Testing the new iam\_profile\_name, which I understand can be used to set  
> > the role when creating a new instance via kitchen-ec2 I updated the  
> > corresponding .kitchen.yml file, but the instance does not get any role  
> > assigned. Folowing is the config I used and the results from the created  
> > instance. I am thinking maybe I missed something obvious that I can't see?
> > 
> > Luis
> > 
> > - .kitchen.yml config \*
> > 
> > ## Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ head .kitchen.yml
> > 
> > driver:  
> > name: ec2  
> > aws\_ssh\_key\_id: [my\_ssh\_key\_id]  
> > region: us-east-1  
> > availability\_zone: us-east-1b  
> > security\_group\_ids: ["sg-YYYYYY"]  
> > subnet\_id: "subnet-aaaaaaa"  
> > instance\_type: t2.small  
> > iam\_profile\_name: master
> > 
> > - "master" role exists in IAM \*  
> > Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws iam get-role  
> > --role-name master --query 'Role.{RoleName:RoleName,Arn:Arn}'  
> > {  
> > "RoleName": "master",  
> > "Arn": "arn:aws:iam::663255216447:role/master"  
> > }
> > 
> > - kitchen converge creates the new instance, and doesn't spit any errors
> 
> - 
> 
> > Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ kitchen converge def  
> > -----\> Starting Kitchen (v1.4.0)  
> > $$$$$$ WARN: The driver[Kitchen::Driver::Ec2] config key `username` is  
> > deprecated, please use `transport.username`  
> > -----\> Creating ...  
> > Creating \<\>...  
> > If you are not using an account that qualifies under the AWS  
> > free-tier, you may be charged to run these suites. The charge  
> > should be minimal, but neither Test Kitchen nor its maintainers  
> > are responsible for your incurred costs.
> > 
> > ```
> > Instance <i-b517ad65> requested.
> > EC2 instance <i-b517ad65> created.
> > 
> > ```
> > 
> > ...
> > 
> > - The created instance, however, does not contain a role \*
> > 
> > Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws ec2 describe-instances  
> > --instance-ids i-b517ad65 --query  
> > 'Reservations[_].Instances[_].IamInstanceProfile'  
> > [  
> >   
> > ]
> > 
> > Are you creating an ERP FrankenCloud? Watch 2:11 video

--  
Yoshi Spendiff  
Ops Engineer  
Indochino  
Mobile: +1 778 952 2025  
Email: [yoshi.spendiff@indochino.com](mailto:yoshi.spendiff@indochino.com)

---

<div class="post-metadata">

**Author:** ![Stuart\_Cracraft](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/stuart_cracraft/32/64_2.png) [@Stuart\_Cracraft](https://discourse.chef.io/u/Stuart_Cracraft)\
**Post date:** [May 21, 2015, 5:00am UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/4 "2015-05-21T05:00:31Z")

</div>

This is the result of trying to get the chef-server to consider itself a chef client.

root@chef-server:/etc/chef-server# chef-client  
[2015-05-20T21:58:42-07:00] INFO: Forking chef instance to converge…  
Starting Chef Client, version 12.3.0  
[2015-05-20T21:58:42-07:00] INFO: \*\*\* Chef 12.3.0 \*\*\*  
[2015-05-20T21:58:42-07:00] INFO: Chef-client pid: 6470  
[2015-05-20T21:58:45-07:00] ERROR: SSL Validation failure connecting to host: chef-server - SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed

# ================================================================================ Chef encountered an error attempting to load the node data for “chef-server”

## Unexpected Error:

OpenSSL::SSL::SSLError: SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed

[2015-05-20T21:58:45-07:00] FATAL: Stacktrace dumped to /var/chef/cache/chef-stacktrace.out  
Chef Client failed. 0 resources updated in 2.552439872 seconds  
[2015-05-20T21:58:45-07:00] ERROR: SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed  
[2015-05-20T21:58:45-07:00] FATAL: Chef::Exceptions::ChildConvergeError: Chef run process exited unsuccessfully (exit code 1)  
root@chef-server:/etc/chef-server#

Unsure as to how to proceed.

---

<div class="post-metadata">

**Author:** ![Stuart\_Cracraft](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/stuart_cracraft/32/64_2.png) [@Stuart\_Cracraft](https://discourse.chef.io/u/Stuart_Cracraft)\
**Post date:** [May 21, 2015, 5:16am UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/5 "2015-05-21T05:16:45Z")

</div>

What file is this reading localhost from when it should be chef-server?

I.e. where is the chef\_server-url defined?

What configuration file? What path?

root@chef-server:/etc/chef# knife ssl check  
WARNING: No knife configuration file found  
Connecting to host localhost:443  
ERROR: The SSL cert is signed by a trusted authority but is not valid for the given hostname  
ERROR: You are attempting to connect to: 'localhost’  
ERROR: The server’s certificate belongs to ‘chef-server’

TO FIX THIS ERROR:

The solution for this issue depends on your networking configuration. If you  
are able to connect to this server using the hostname chef-server  
instead of localhost, then you can resolve this issue by updating chef\_server\_url  
in your configuration file.

If you are not able to connect to the server using the hostname chef-server  
you will have to update the certificate on the server to use the correct hostname.  
root@chef-server:/etc/chef#

---

<div class="post-metadata">

**Author:** ![Stuart\_Cracraft](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/stuart_cracraft/32/64_2.png) [@Stuart\_Cracraft](https://discourse.chef.io/u/Stuart_Cracraft)\
**Post date:** [May 21, 2015, 5:17am UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/6 "2015-05-21T05:17:42Z")

</div>

By the way, the chef-client host from last night is fine. It was a knife.rb which needed  
to be generated from the Chef GUI and a validation pem regenerated.

---

<div class="post-metadata">

**Author:** ![Tyler\_Ball](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/tyler_ball/32/14_2.png) [@Tyler\_Ball](https://discourse.chef.io/u/Tyler_Ball)\
**Post date:** [May 21, 2015, 4:26pm UTC](https://discourse.chef.io/t/kitchen-ec2-0-9-0-iam-profile-name-something-missing/6603/7 "2015-05-21T16:26:35Z")

</div>

This is a regression I introduced in 0.9.0 - I accidentally renamed the key `iam_profile_name` to `iam_instance_profile`. I’ve fixed the issue in PR #125 [https://github.com/test-kitchen/kitchen-ec2/pull/125](https://github.com/test-kitchen/kitchen-ec2/pull/125) and will be releasing a patch fix as soon as I get it merged. Thanks for the report, and sorry for the regression! I added test coverage for this as well.

-T

> On May 20, 2015, at 3:38 PM, Yoshi Spendiff [yoshi.spendiff@indochino.com](mailto:yoshi.spendiff@indochino.com) wrote:
> 
> I'm getting the same with a with an iam role/instance profile with the same name. Both of the following commands return correct values
> 
> aws iam get-role --role-name webServer  
> aws iam get-instance-profile --instance-profile-name webServer
> 
> In my .kitchen.yml I have:
> 
> driver:  
> iam\_profile\_name: webServer
> 
> The iam role was created via the AWS console so the name definitely matches with the instance profile.
> 
> On Wed, May 20, 2015 at 11:50 AM, Noah Kantrowitz \<[noah@coderanger.net](mailto:noah@coderanger.net) [mailto:noah@coderanger.net](mailto:noah@coderanger.net)\> wrote:  
> Instance profiles are not the same as IAM roles. While normally there is a one-to-one mapping, I don't see any code in kitchen to automatically create instance profiles for you the way that some other tools do. Create the insp yourself and it should work.
> 
> --Noah
> 
> On May 20, 2015, at 11:16 AM, Luis Cosmes \<[lcosmes@financialforce.com](mailto:lcosmes@financialforce.com) [mailto:lcosmes@financialforce.com](mailto:lcosmes@financialforce.com)\> wrote:
> 
> > Hi,
> > 
> > Testing the new iam\_profile\_name, which I understand can be used to set the role when creating a new instance via kitchen-ec2 I updated the corresponding .kitchen.yml file, but the instance does not get any role assigned. Folowing is the config I used and the results from the created instance. I am thinking maybe I missed something obvious that I can't see?
> > 
> > Luis
> > 
> > - .kitchen.yml config \*
> > 
> > ## Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ head .kitchen.yml
> > 
> > driver:  
> > name: ec2  
> > aws\_ssh\_key\_id: [my\_ssh\_key\_id]  
> > region: us-east-1  
> > availability\_zone: us-east-1b  
> > security\_group\_ids: ["sg-YYYYYY"]  
> > subnet\_id: "subnet-aaaaaaa"  
> > instance\_type: t2.small  
> > iam\_profile\_name: master
> > 
> > - "master" role exists in IAM \*  
> > Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws iam get-role --role-name master --query 'Role.{RoleName:RoleName,Arn:Arn}'  
> > {  
> > "RoleName": "master",  
> > "Arn": "arn:aws:iam::663255216447:role/master"  
> > }
> > 
> > - kitchen converge creates the new instance, and doesn't spit any errors \*
> > 
> > Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ kitchen converge def  
> > -----\> Starting Kitchen (v1.4.0)  
> > $$$$$$ WARN: The driver[Kitchen::Driver::Ec2] config key `username` is deprecated, please use `transport.username`  
> > -----\> Creating ...  
> > Creating \<\>...  
> > If you are not using an account that qualifies under the AWS  
> > free-tier, you may be charged to run these suites. The charge  
> > should be minimal, but neither Test Kitchen nor its maintainers  
> > are responsible for your incurred costs.
> > 
> > ```
> > Instance <i-b517ad65> requested.
> > EC2 instance <i-b517ad65> created.
> > 
> > ```
> > 
> > ...
> > 
> > - The created instance, however, does not contain a role \*
> > 
> > Luis-Cosmes-MacBook-Pro:ffdc-common lcosmes$ aws ec2 describe-instances --instance-ids i-b517ad65 --query 'Reservations[_].Instances[_].IamInstanceProfile'  
> > [  
> >   
> > ]
> > 
> > Are you creating an ERP FrankenCloud? Watch 2:11 video
> 
> --  
> Yoshi Spendiff  
> Ops Engineer  
> Indochino  
> Mobile: +1 778 952 2025  
> Email: [yoshi.spendiff@indochino.com](mailto:yoshi.spendiff@indochino.com) [mailto:yoshi.spendiff@indochino.com](mailto:yoshi.spendiff@indochino.com)
