# Knife + ec2

**URL:** <https://discourse.chef.io/t/knife-ec2/2526>\
**Category:** Chef Infra (archive)\
**Created:** [February 9, 2012, 1:50pm UTC](https://discourse.chef.io/t/knife-ec2/2526 "2012-02-09T13:50:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mark\_bradley](https://avatars.discourse-cdn.com/v4/letter/m/a87d85/32.png) [@mark\_bradley](https://discourse.chef.io/u/mark_bradley)\
**Post date:** [February 9, 2012, 1:50pm UTC](https://discourse.chef.io/t/knife-ec2/2526/1 "2012-02-09T13:50:48Z")

</div>

Hi,

I’m trying to bootstrap nodes in EC2 using knife as follows:

# knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S

DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V

but it hangs with the following output:

DEBUG: Using configuration from /root/.chef/knife.rb  
Instance ID: i-638eea06  
Flavor: m1.large  
Image: ami-1b814f72  
Region: us-east-1  
Availability Zone: us-east-1b  
Security Groups: DevOps  
SSH Key: DevOps

Waiting for server…  
Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
Public IP Address: 50.19.18.3  
Private DNS Name: ip-10-87-1-167.ec2.internal  
Private IP Address: 10.87.1.167

Waiting for sshd.

If, however, I manually log in to the instance everything seems available:

$ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
The authenticity of host  
’[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)(50.19.18.3)’ can’t be  
established.  
RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
Are you sure you want to continue connecting (yes/no)? yes  
Warning: Permanently added ‘[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3’  
(RSA) to the list of known hosts.

```
   __|__ |_ )
   _| ( / Amazon Linux AMI
  ___|\___ |___|

```

See /usr/share/doc/system-release/ for latest release notes.  
There are 23 security update(s) out of 32 total update(s) available  
[ec2-user@ip-10-87-1-167 ~]$

Is there any way to get more debugging information from knife? Does anyone  
know what could be going wrong?

Thanks,  
Mark

---

<div class="post-metadata">

**Author:** ![James](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/james/32/232_2.png) [@James](https://discourse.chef.io/u/James)\
**Post date:** [February 9, 2012, 7:35pm UTC](https://discourse.chef.io/t/knife-ec2/2526/2 "2012-02-09T19:35:06Z")

</div>

I think this can also be caused by the sshd daemon taking longer to start  
than the timeout allows. I see it in roughly 1/20 ec2 nodes. You could  
bootstrap the instance, but I just delete them and re-create.  
On Feb 9, 2012 5:51 AM, "mark bradley" [gopearls42@gmail.com](mailto:gopearls42@gmail.com) wrote:

> Hi,
> 
> I'm trying to bootstrap nodes in EC2 using knife as follows:
> 
> # knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S
> 
> DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V
> 
> but it hangs with the following output:
> 
> DEBUG: Using configuration from /root/.chef/knife.rb  
> Instance ID: i-638eea06  
> Flavor: m1.large  
> Image: ami-1b814f72  
> Region: us-east-1  
> Availability Zone: us-east-1b  
> Security Groups: DevOps  
> SSH Key: DevOps
> 
> Waiting for server.......................  
> Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
> Public IP Address: 50.19.18.3  
> Private DNS Name: ip-10-87-1-167.ec2.internal  
> Private IP Address: 10.87.1.167
> 
> Waiting for sshd.
> 
> If, however, I manually log in to the instance everything seems available:
> 
> $ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
> The authenticity of host '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)(50.19.18.3)' can't be established.  
> RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
> Are you sure you want to continue connecting (yes/no)? yes  
> Warning: Permanently added '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3'  
> (RSA) to the list of known hosts.
> 
> ```
> __|__ |_ )
> _| ( / Amazon Linux AMI
> ___|\___ |___|
> 
> ```
> 
> See /usr/share/doc/system-release/ for latest release notes.  
> There are 23 security update(s) out of 32 total update(s) available  
> [ec2-user@ip-10-87-1-167 ~]$
> 
> Is there any way to get more debugging information from knife? Does anyone  
> know what could be going wrong?
> 
> Thanks,  
> Mark

---

<div class="post-metadata">

**Author:** ![Kevin\_Harvey](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/kevin_harvey/32/755_2.png) [@Kevin\_Harvey](https://discourse.chef.io/u/Kevin_Harvey)\
**Post date:** [February 9, 2012, 1:53pm UTC](https://discourse.chef.io/t/knife-ec2/2526/3 "2012-02-09T13:53:58Z")

</div>

## How long are you waiting for sshd to come up there? It can take a minute or more.

Kevin Harvey  
Web Developer  
[kcharvey@gmail.com](mailto:kcharvey@gmail.com)

On Thu, Feb 9, 2012 at 8:50 AM, mark bradley [gopearls42@gmail.com](mailto:gopearls42@gmail.com) wrote:

> Hi,
> 
> I'm trying to bootstrap nodes in EC2 using knife as follows:
> 
> # knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S
> 
> DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V
> 
> but it hangs with the following output:
> 
> DEBUG: Using configuration from /root/.chef/knife.rb  
> Instance ID: i-638eea06  
> Flavor: m1.large  
> Image: ami-1b814f72  
> Region: us-east-1  
> Availability Zone: us-east-1b  
> Security Groups: DevOps  
> SSH Key: DevOps
> 
> Waiting for server.......................  
> Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
> Public IP Address: 50.19.18.3  
> Private DNS Name: ip-10-87-1-167.ec2.internal  
> Private IP Address: 10.87.1.167
> 
> Waiting for sshd.
> 
> If, however, I manually log in to the instance everything seems available:
> 
> $ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
> The authenticity of host '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)(50.19.18.3)' can't be established.  
> RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
> Are you sure you want to continue connecting (yes/no)? yes  
> Warning: Permanently added '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3'  
> (RSA) to the list of known hosts.
> 
> ```
> __|__ |_ )
> _| ( / Amazon Linux AMI
> ___|\___ |___|
> 
> ```
> 
> See /usr/share/doc/system-release/ for latest release notes.  
> There are 23 security update(s) out of 32 total update(s) available  
> [ec2-user@ip-10-87-1-167 ~]$
> 
> Is there any way to get more debugging information from knife? Does anyone  
> know what could be going wrong?
> 
> Thanks,  
> Mark

---

<div class="post-metadata">

**Author:** ![Bryan\_Stenson](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/bryan_stenson/32/420_2.png) [@Bryan\_Stenson](https://discourse.chef.io/u/Bryan_Stenson)\
**Post date:** [February 9, 2012, 1:57pm UTC](https://discourse.chef.io/t/knife-ec2/2526/4 "2012-02-09T13:57:19Z")

</div>

Total guess: knife blocked on unknown host SSL key?  
On Feb 9, 2012 5:54 AM, "Kevin Harvey" [kcharvey@gmail.com](mailto:kcharvey@gmail.com) wrote:

> ## How long are you waiting for sshd to come up there? It can take a minute or more.
> 
> Kevin Harvey  
> Web Developer  
> [kcharvey@gmail.com](mailto:kcharvey@gmail.com)
> 
> On Thu, Feb 9, 2012 at 8:50 AM, mark bradley [gopearls42@gmail.com](mailto:gopearls42@gmail.com) wrote:
> 
> > Hi,
> > 
> > I'm trying to bootstrap nodes in EC2 using knife as follows:
> > 
> > # knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S
> > 
> > DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V
> > 
> > but it hangs with the following output:
> > 
> > DEBUG: Using configuration from /root/.chef/knife.rb  
> > Instance ID: i-638eea06  
> > Flavor: m1.large  
> > Image: ami-1b814f72  
> > Region: us-east-1  
> > Availability Zone: us-east-1b  
> > Security Groups: DevOps  
> > SSH Key: DevOps
> > 
> > Waiting for server.......................  
> > Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
> > Public IP Address: 50.19.18.3  
> > Private DNS Name: ip-10-87-1-167.ec2.internal  
> > Private IP Address: 10.87.1.167
> > 
> > Waiting for sshd.
> > 
> > If, however, I manually log in to the instance everything seems available:
> > 
> > $ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
> > The authenticity of host '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)(50.19.18.3)' can't be established.  
> > RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
> > Are you sure you want to continue connecting (yes/no)? yes  
> > Warning: Permanently added '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3'  
> > (RSA) to the list of known hosts.
> > 
> > ```
> > __|__ |_ )
> > _| ( / Amazon Linux AMI
> > ___|\___ |___|
> > 
> > ```
> > 
> > See /usr/share/doc/system-release/ for latest release notes.  
> > There are 23 security update(s) out of 32 total update(s) available  
> > [ec2-user@ip-10-87-1-167 ~]$
> > 
> > Is there any way to get more debugging information from knife? Does  
> > anyone know what could be going wrong?
> > 
> > Thanks,  
> > Mark

---

<div class="post-metadata">

**Author:** ![Charles\_Sullivan](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/charles_sullivan/32/483_2.png) [@Charles\_Sullivan](https://discourse.chef.io/u/Charles_Sullivan)\
**Post date:** [February 9, 2012, 2:10pm UTC](https://discourse.chef.io/t/knife-ec2/2526/5 "2012-02-09T14:10:24Z")

</div>

I suggest adding an entry to your ~/.ssh/config file. Something similar to  
the following.

Host _compute_.amazonaws.com  
ForwardAgent yes  
User csullivan-emr  
CheckHostIP no  
StrictHostKeyChecking no  
UserKnownHostsFile /dev/null  
KeepAlive yes  
IdentityFile=~/.ssh/id\_rsa

Also, look into this project to ease your SSH key usage.

[http://www.funtoo.org/wiki/Keychain](http://www.funtoo.org/wiki/Keychain)

On Thu, Feb 9, 2012 at 7:57 AM, Bryan Stenson [bryan.stenson@gmail.com](mailto:bryan.stenson@gmail.com)wrote:

> Total guess: knife blocked on unknown host SSL key?  
> On Feb 9, 2012 5:54 AM, "Kevin Harvey" [kcharvey@gmail.com](mailto:kcharvey@gmail.com) wrote:
> 
> > ## How long are you waiting for sshd to come up there? It can take a minute or more.
> > 
> > Kevin Harvey  
> > Web Developer  
> > [kcharvey@gmail.com](mailto:kcharvey@gmail.com)
> > 
> > On Thu, Feb 9, 2012 at 8:50 AM, mark bradley [gopearls42@gmail.com](mailto:gopearls42@gmail.com)wrote:
> > 
> > > Hi,
> > > 
> > > I'm trying to bootstrap nodes in EC2 using knife as follows:
> > > 
> > > # knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S
> > > 
> > > DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V
> > > 
> > > but it hangs with the following output:
> > > 
> > > DEBUG: Using configuration from /root/.chef/knife.rb  
> > > Instance ID: i-638eea06  
> > > Flavor: m1.large  
> > > Image: ami-1b814f72  
> > > Region: us-east-1  
> > > Availability Zone: us-east-1b  
> > > Security Groups: DevOps  
> > > SSH Key: DevOps
> > > 
> > > Waiting for server.......................  
> > > Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
> > > Public IP Address: 50.19.18.3  
> > > Private DNS Name: ip-10-87-1-167.ec2.internal  
> > > Private IP Address: 10.87.1.167
> > > 
> > > Waiting for sshd.
> > > 
> > > If, however, I manually log in to the instance everything seems  
> > > available:
> > > 
> > > $ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
> > > The authenticity of host '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)(50.19.18.3)' can't be established.  
> > > RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
> > > Are you sure you want to continue connecting (yes/no)? yes  
> > > Warning: Permanently added '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3'  
> > > (RSA) to the list of known hosts.
> > > 
> > > ```
> > > __|__ |_ )
> > > _| ( / Amazon Linux AMI
> > > ___|\___ |___|
> > > 
> > > ```
> > > 
> > > See /usr/share/doc/system-release/ for latest release notes.  
> > > There are 23 security update(s) out of 32 total update(s) available  
> > > [ec2-user@ip-10-87-1-167 ~]$
> > > 
> > > Is there any way to get more debugging information from knife? Does  
> > > anyone know what could be going wrong?
> > > 
> > > Thanks,  
> > > Mark

--  
Charles Sullivan  
[charlie.sullivan@gmail.com](mailto:charlie.sullivan@gmail.com)

---

<div class="post-metadata">

**Author:** ![mark\_bradley](https://avatars.discourse-cdn.com/v4/letter/m/a87d85/32.png) [@mark\_bradley](https://discourse.chef.io/u/mark_bradley)\
**Post date:** [February 9, 2012, 2:39pm UTC](https://discourse.chef.io/t/knife-ec2/2526/6 "2012-02-09T14:39:05Z")

</div>

Well, my accident I left it waiting overnight ☹

Mark

On Thu, Feb 9, 2012 at 8:53 AM, Kevin Harvey [kcharvey@gmail.com](mailto:kcharvey@gmail.com) wrote:

> ## How long are you waiting for sshd to come up there? It can take a minute or more.
> 
> Kevin Harvey  
> Web Developer  
> [kcharvey@gmail.com](mailto:kcharvey@gmail.com)
> 
> On Thu, Feb 9, 2012 at 8:50 AM, mark bradley [gopearls42@gmail.com](mailto:gopearls42@gmail.com) wrote:
> 
> > Hi,
> > 
> > I'm trying to bootstrap nodes in EC2 using knife as follows:
> > 
> > # knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S
> > 
> > DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V
> > 
> > but it hangs with the following output:
> > 
> > DEBUG: Using configuration from /root/.chef/knife.rb  
> > Instance ID: i-638eea06  
> > Flavor: m1.large  
> > Image: ami-1b814f72  
> > Region: us-east-1  
> > Availability Zone: us-east-1b  
> > Security Groups: DevOps  
> > SSH Key: DevOps
> > 
> > Waiting for server.......................  
> > Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
> > Public IP Address: 50.19.18.3  
> > Private DNS Name: ip-10-87-1-167.ec2.internal  
> > Private IP Address: 10.87.1.167
> > 
> > Waiting for sshd.
> > 
> > If, however, I manually log in to the instance everything seems available:
> > 
> > $ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
> > The authenticity of host '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)(50.19.18.3)' can't be established.  
> > RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
> > Are you sure you want to continue connecting (yes/no)? yes  
> > Warning: Permanently added '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3'  
> > (RSA) to the list of known hosts.
> > 
> > ```
> > __|__ |_ )
> > _| ( / Amazon Linux AMI
> > ___|\___ |___|
> > 
> > ```
> > 
> > See /usr/share/doc/system-release/ for latest release notes.  
> > There are 23 security update(s) out of 32 total update(s) available  
> > [ec2-user@ip-10-87-1-167 ~]$
> > 
> > Is there any way to get more debugging information from knife? Does  
> > anyone know what could be going wrong?
> > 
> > Thanks,  
> > Mark

---

<div class="post-metadata">

**Author:** ![Aaron\_Abramson](https://avatars.discourse-cdn.com/v4/letter/a/71e660/32.png) [@Aaron\_Abramson](https://discourse.chef.io/u/Aaron_Abramson)\
**Post date:** [February 9, 2012, 3:55pm UTC](https://discourse.chef.io/t/knife-ec2/2526/7 "2012-02-09T15:55:21Z")

</div>

Doublecheck that your DevOps security group has your IP authorized for SSH.

I ran "knife ec2 server create -f m1.large -I ami-1b814f72 -G default -S mykey -N foobar -x ec2-user -V -V" and it hung on SSH, then I remembered that my default group only allows inter-ec2 communication.

This worked for me "knife ec2 server create -f m1.large -I ami-1b814f72 -G default,management -S mykey -N foobar -x ec2-user -V -V"

I use ssh-add to store my ssh key for ease of use.

On Feb 9, 2012, at 8:39 AM, mark bradley wrote:

> Well, my accident I left it waiting overnight ☹
> 
> Mark
> 
> ## On Thu, Feb 9, 2012 at 8:53 AM, Kevin Harvey [kcharvey@gmail.com](mailto:kcharvey@gmail.com) wrote: How long are you waiting for sshd to come up there? It can take a minute or more.
> 
> Kevin Harvey  
> Web Developer  
> [kcharvey@gmail.com](mailto:kcharvey@gmail.com)
> 
> On Thu, Feb 9, 2012 at 8:50 AM, mark bradley [gopearls42@gmail.com](mailto:gopearls42@gmail.com) wrote:  
> Hi,
> 
> I'm trying to bootstrap nodes in EC2 using knife as follows:
> 
> # knife ec2 server create --flavor m1.large -I ami-1b814f72 -G DevOps -S DevOps -N foobar -x ec2-user -i /tmp/DevOps.pem -V -V
> 
> but it hangs with the following output:
> 
> DEBUG: Using configuration from /root/.chef/knife.rb  
> Instance ID: i-638eea06  
> Flavor: m1.large  
> Image: ami-1b814f72  
> Region: us-east-1  
> Availability Zone: us-east-1b  
> Security Groups: DevOps  
> SSH Key: DevOps
> 
> Waiting for server.......................  
> Public DNS Name: [ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com)  
> Public IP Address: 50.19.18.3  
> Private DNS Name: ip-10-87-1-167.ec2.internal  
> Private IP Address: 10.87.1.167
> 
> Waiting for sshd.
> 
> If, however, I manually log in to the instance everything seems available:
> 
> $ ssh -i DevOps.pem [ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com](mailto:ec2-user@ec2-50-19-18-3.compute-1.amazonaws.com)  
> The authenticity of host '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com) (50.19.18.3)' can't be established.  
> RSA key fingerprint is 0e:da:5e:4b:8d:80:7f:ba:63:89:25:ad:dd:b4:ba:a0.  
> Are you sure you want to continue connecting (yes/no)? yes  
> Warning: Permanently added '[ec2-50-19-18-3.compute-1.amazonaws.com](http://ec2-50-19-18-3.compute-1.amazonaws.com),50.19.18.3' (RSA) to the list of known hosts.
> 
> ```
> __|__ |_ )
> _| ( / Amazon Linux AMI
> ___|\___ |___|
> 
> ```
> 
> See /usr/share/doc/system-release/ for latest release notes.  
> There are 23 security update(s) out of 32 total update(s) available  
> [ec2-user@ip-10-87-1-167 ~]$
> 
> Is there any way to get more debugging information from knife? Does anyone know what could be going wrong?
> 
> Thanks,  
> Mark
