# Ohai timeouts inside VPC

**URL:** <https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241>\
**Category:** Chef Infra (archive)\
**Created:** [January 30, 2015, 5:47pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241 "2015-01-30T17:47:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Douglas\_Garstang](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@Douglas\_Garstang](https://discourse.chef.io/u/Douglas_Garstang)\
**Post date:** [January 30, 2015, 5:47pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241/1 "2015-01-30T17:47:31Z")

</div>

I'm running chef and using ohai plugins inside EC2 instances running in a  
VPC. Aside from creating the hints file, it seems that any ohai reloads are  
horribly slow.

It looks like someone has created a cookbook as a workaround for a issue  
with similar symptons. Is this a known issue?

> **[marcelom/ohai\_ec2\_hack](https://github.com/marcelom/ohai_ec2_hack)**
>
> Fixed Ohai EC2 bug (OHAI-310) detecting EC2 instance inside VPC. - marcelom/ohai\_ec2\_hack

Doug

---

<div class="post-metadata">

**Author:** ![ssd](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@ssd](https://discourse.chef.io/u/ssd)\
**Post date:** [January 30, 2015, 7:20pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241/2 "2015-01-30T19:20:05Z")

</div>

Hi Douglas,

Unfortunately, reliably detecting VPC nodes is difficult. If you are  
only seeing slowness without the ohai hint in place, then my guess is  
that it is a result of the fact that we detect being on ec2 by making  
a network call to the metadata API:

> <https://github.com/chef/ohai/blob/main/lib/ohai/plugins/ec2.rb#L45>

If you are seeing the reload slowness even with the hint enabled, then  
I would recommend running chef-client with debug logging turned on.  
The timestamps in the log can often help find which plugins are slow  
to load.

> It looks like someone has created a cookbook as a workaround for a issue with similar symptons. Is this a known issue?

The difficulty and slowness of detecting EC2 nodes is known and was  
one of the primary motivators for Ohai's hint system. Currently,  
using an ohai hint when you know you are on EC2 and disabling the  
plugin when you know you are not on EC2 is the best method to avoid  
the speed penalty (and unreliability) of the ec2 detection methods we  
have.

The ec2 hint can be put on disk by the knife-ec2 plugin at the time of  
provisioning or by the ohai cookbook's ohai\_hint LWRP on the first  
chef-client run. (The ohai cookbook is also capable of disabling  
plugins).

Hope this helps.

Cheers,

Steven

On Fri, Jan 30, 2015 at 5:47 PM, Douglas Garstang  
[doug.garstang@gmail.com](mailto:doug.garstang@gmail.com) wrote:

> I'm running chef and using ohai plugins inside EC2 instances running in a  
> VPC. Aside from creating the hints file, it seems that any ohai reloads are  
> horribly slow.
> 
> It looks like someone has created a cookbook as a workaround for a issue  
> with similar symptons. Is this a known issue?
> 
> [GitHub - marcelom/ohai\_ec2\_hack: Fixed Ohai EC2 bug (OHAI-310) detecting EC2 instance inside VPC.](https://github.com/marcelom/ohai_ec2_hack)
> 
> Doug

---

<div class="post-metadata">

**Author:** ![ssd](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@ssd](https://discourse.chef.io/u/ssd)\
**Post date:** [January 30, 2015, 7:24pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241/3 "2015-01-30T19:24:43Z")

</div>

Hi,

A quick follow up. I just saw your other thread about writing a VPC  
plugin. It looks like my knowledge about it being difficult to detect  
VPC might be out of date? If so, improvements to the ec2 plugin  
itself are also welcome.

Cheers,

Steven

On Fri, Jan 30, 2015 at 7:20 PM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:

> Hi Douglas,
> 
> Unfortunately, reliably detecting VPC nodes is difficult. If you are  
> only seeing slowness without the ohai hint in place, then my guess is  
> that it is a result of the fact that we detect being on ec2 by making  
> a network call to the metadata API:
> 
> [https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45](https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45)
> 
> If you are seeing the reload slowness even with the hint enabled, then  
> I would recommend running chef-client with debug logging turned on.  
> The timestamps in the log can often help find which plugins are slow  
> to load.
> 
> > It looks like someone has created a cookbook as a workaround for a issue with similar symptons. Is this a known issue?
> 
> The difficulty and slowness of detecting EC2 nodes is known and was  
> one of the primary motivators for Ohai's hint system. Currently,  
> using an ohai hint when you know you are on EC2 and disabling the  
> plugin when you know you are not on EC2 is the best method to avoid  
> the speed penalty (and unreliability) of the ec2 detection methods we  
> have.
> 
> The ec2 hint can be put on disk by the knife-ec2 plugin at the time of  
> provisioning or by the ohai cookbook's ohai\_hint LWRP on the first  
> chef-client run. (The ohai cookbook is also capable of disabling  
> plugins).
> 
> Hope this helps.
> 
> Cheers,
> 
> Steven
> 
> On Fri, Jan 30, 2015 at 5:47 PM, Douglas Garstang  
> [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com) wrote:
> 
> > I'm running chef and using ohai plugins inside EC2 instances running in a  
> > VPC. Aside from creating the hints file, it seems that any ohai reloads are  
> > horribly slow.
> > 
> > It looks like someone has created a cookbook as a workaround for a issue  
> > with similar symptons. Is this a known issue?
> > 
> > [GitHub - marcelom/ohai\_ec2\_hack: Fixed Ohai EC2 bug (OHAI-310) detecting EC2 instance inside VPC.](https://github.com/marcelom/ohai_ec2_hack)
> > 
> > Doug

---

<div class="post-metadata">

**Author:** ![Douglas\_Garstang](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@Douglas\_Garstang](https://discourse.chef.io/u/Douglas_Garstang)\
**Post date:** [January 30, 2015, 7:28pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241/4 "2015-01-30T19:28:38Z")

</div>

Steven,

I actually wrote a new plugin. Can't use it tho. Looks like the data  
returned by custom plugins is not available in attributes/default.rb (data  
in core ohai seems to be though). Since I imagine this is the most likely  
place you would want to check (I'm using it to check if it's a VPC and set  
attributes used by an upstream cookbook), then, well, it's kinda pointless.  
Actually, this would make most ohai plugins pointless. ☹

Doug.

On Fri, Jan 30, 2015 at 11:24 AM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:

> Hi,
> 
> A quick follow up. I just saw your other thread about writing a VPC  
> plugin. It looks like my knowledge about it being difficult to detect  
> VPC might be out of date? If so, improvements to the ec2 plugin  
> itself are also welcome.
> 
> Cheers,
> 
> Steven
> 
> On Fri, Jan 30, 2015 at 7:20 PM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:
> 
> > Hi Douglas,
> > 
> > Unfortunately, reliably detecting VPC nodes is difficult. If you are  
> > only seeing slowness without the ohai hint in place, then my guess is  
> > that it is a result of the fact that we detect being on ec2 by making  
> > a network call to the metadata API:
> > 
> > [https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45](https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45)
> > 
> > If you are seeing the reload slowness even with the hint enabled, then  
> > I would recommend running chef-client with debug logging turned on.  
> > The timestamps in the log can often help find which plugins are slow  
> > to load.
> > 
> > > It looks like someone has created a cookbook as a workaround for a  
> > > issue with similar symptons. Is this a known issue?
> > 
> > The difficulty and slowness of detecting EC2 nodes is known and was  
> > one of the primary motivators for Ohai's hint system. Currently,  
> > using an ohai hint when you know you are on EC2 and disabling the  
> > plugin when you know you are not on EC2 is the best method to avoid  
> > the speed penalty (and unreliability) of the ec2 detection methods we  
> > have.
> > 
> > The ec2 hint can be put on disk by the knife-ec2 plugin at the time of  
> > provisioning or by the ohai cookbook's ohai\_hint LWRP on the first  
> > chef-client run. (The ohai cookbook is also capable of disabling  
> > plugins).
> > 
> > Hope this helps.
> > 
> > Cheers,
> > 
> > Steven
> > 
> > On Fri, Jan 30, 2015 at 5:47 PM, Douglas Garstang  
> > [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com) wrote:
> > 
> > > I'm running chef and using ohai plugins inside EC2 instances running in  
> > > a  
> > > VPC. Aside from creating the hints file, it seems that any ohai reloads  
> > > are  
> > > horribly slow.
> > > 
> > > It looks like someone has created a cookbook as a workaround for a issue  
> > > with similar symptons. Is this a known issue?
> > > 
> > > [GitHub - marcelom/ohai\_ec2\_hack: Fixed Ohai EC2 bug (OHAI-310) detecting EC2 instance inside VPC.](https://github.com/marcelom/ohai_ec2_hack)
> > > 
> > > Doug

--  
Regards,

Douglas Garstang  
[http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
Cell: +1-805-340-5627

---

<div class="post-metadata">

**Author:** ![Douglas\_Garstang](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@Douglas\_Garstang](https://discourse.chef.io/u/Douglas_Garstang)\
**Post date:** [January 30, 2015, 7:30pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241/5 "2015-01-30T19:30:30Z")

</div>

This is what I've ended up with in attributes/default.rb. Not very pretty  
but seems to work.

vpc\_id = nil  
node['ec2']['network\_interfaces\_macs'].each\_pair do |iface, data|  
vpc\_id = data['vpc\_id'] if data.key?('vpc\_id')  
end

case vpc\_id  
when nil  
default['openldap']['server'] = node['slice-ldap']['ldap\_server\_url']  
else  
default['openldap']['server'] =  
node['slice-ldap']['ldap\_server\_url\_vpc']  
end

Is there a better way?

Doug.

On Fri, Jan 30, 2015 at 11:28 AM, Douglas Garstang [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
wrote:

> Steven,
> 
> I actually wrote a new plugin. Can't use it tho. Looks like the data  
> returned by custom plugins is not available in attributes/default.rb (data  
> in core ohai seems to be though). Since I imagine this is the most likely  
> place you would want to check (I'm using it to check if it's a VPC and set  
> attributes used by an upstream cookbook), then, well, it's kinda pointless.  
> Actually, this would make most ohai plugins pointless. ☹
> 
> Doug.
> 
> On Fri, Jan 30, 2015 at 11:24 AM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:
> 
> > Hi,
> > 
> > A quick follow up. I just saw your other thread about writing a VPC  
> > plugin. It looks like my knowledge about it being difficult to detect  
> > VPC might be out of date? If so, improvements to the ec2 plugin  
> > itself are also welcome.
> > 
> > Cheers,
> > 
> > Steven
> > 
> > On Fri, Jan 30, 2015 at 7:20 PM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:
> > 
> > > Hi Douglas,
> > > 
> > > Unfortunately, reliably detecting VPC nodes is difficult. If you are  
> > > only seeing slowness without the ohai hint in place, then my guess is  
> > > that it is a result of the fact that we detect being on ec2 by making  
> > > a network call to the metadata API:
> > > 
> > > [https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45](https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45)
> > > 
> > > If you are seeing the reload slowness even with the hint enabled, then  
> > > I would recommend running chef-client with debug logging turned on.  
> > > The timestamps in the log can often help find which plugins are slow  
> > > to load.
> > > 
> > > > It looks like someone has created a cookbook as a workaround for a  
> > > > issue with similar symptons. Is this a known issue?
> > > 
> > > The difficulty and slowness of detecting EC2 nodes is known and was  
> > > one of the primary motivators for Ohai's hint system. Currently,  
> > > using an ohai hint when you know you are on EC2 and disabling the  
> > > plugin when you know you are not on EC2 is the best method to avoid  
> > > the speed penalty (and unreliability) of the ec2 detection methods we  
> > > have.
> > > 
> > > The ec2 hint can be put on disk by the knife-ec2 plugin at the time of  
> > > provisioning or by the ohai cookbook's ohai\_hint LWRP on the first  
> > > chef-client run. (The ohai cookbook is also capable of disabling  
> > > plugins).
> > > 
> > > Hope this helps.
> > > 
> > > Cheers,
> > > 
> > > Steven
> > > 
> > > On Fri, Jan 30, 2015 at 5:47 PM, Douglas Garstang  
> > > [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com) wrote:
> > > 
> > > > I'm running chef and using ohai plugins inside EC2 instances running  
> > > > in a  
> > > > VPC. Aside from creating the hints file, it seems that any ohai  
> > > > reloads are  
> > > > horribly slow.
> > > > 
> > > > It looks like someone has created a cookbook as a workaround for a  
> > > > issue  
> > > > with similar symptons. Is this a known issue?
> > > > 
> > > > [GitHub - marcelom/ohai\_ec2\_hack: Fixed Ohai EC2 bug (OHAI-310) detecting EC2 instance inside VPC.](https://github.com/marcelom/ohai_ec2_hack)
> > > > 
> > > > Doug
> 
> --  
> Regards,
> 
> Douglas Garstang  
> [http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
> Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
> Cell: +1-805-340-5627

--  
Regards,

Douglas Garstang  
[http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
Cell: +1-805-340-5627

---

<div class="post-metadata">

**Author:** ![Douglas\_Garstang](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@Douglas\_Garstang](https://discourse.chef.io/u/Douglas_Garstang)\
**Post date:** [January 30, 2015, 7:51pm UTC](https://discourse.chef.io/t/ohai-timeouts-inside-vpc/6241/6 "2015-01-30T19:51:25Z")

</div>

Actually, I had to use this, even uglier. Without the has\_key checks, this  
will fail on non ec2 including vagrant.

vpc\_id = nil  
if node.has\_key?('ec2')  
if node[:ec2].has\_key?('network\_interfaces\_macs')  
node['ec2']['network\_interfaces\_macs'].each\_pair do |iface, data|  
vpc\_id = data['vpc\_id'] if data.key?('vpc\_id')  
end  
end  
end  
case vpc\_id  
when nil  
default['openldap']['server'] = node['slice-ldap']['ldap\_server\_url']  
else  
default['openldap']['server'] =  
node['slice-ldap']['ldap\_server\_url\_vpc']  
end

Seems ridiculous that we can't use custom ohai plugins in this situation.

Doug.

On Fri, Jan 30, 2015 at 11:30 AM, Douglas Garstang [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
wrote:

> This is what I've ended up with in attributes/default.rb. Not very pretty  
> but seems to work.
> 
> vpc\_id = nil  
> node['ec2']['network\_interfaces\_macs'].each\_pair do |iface, data|  
> vpc\_id = data['vpc\_id'] if data.key?('vpc\_id')  
> end
> 
> case vpc\_id  
> when nil  
> default['openldap']['server'] = node['slice-ldap']['ldap\_server\_url']  
> else  
> default['openldap']['server'] =  
> node['slice-ldap']['ldap\_server\_url\_vpc']  
> end
> 
> Is there a better way?
> 
> Doug.
> 
> On Fri, Jan 30, 2015 at 11:28 AM, Douglas Garstang \<  
> [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)\> wrote:
> 
> > Steven,
> > 
> > I actually wrote a new plugin. Can't use it tho. Looks like the data  
> > returned by custom plugins is not available in attributes/default.rb (data  
> > in core ohai seems to be though). Since I imagine this is the most likely  
> > place you would want to check (I'm using it to check if it's a VPC and set  
> > attributes used by an upstream cookbook), then, well, it's kinda pointless.  
> > Actually, this would make most ohai plugins pointless. ☹
> > 
> > Doug.
> > 
> > On Fri, Jan 30, 2015 at 11:24 AM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:
> > 
> > > Hi,
> > > 
> > > A quick follow up. I just saw your other thread about writing a VPC  
> > > plugin. It looks like my knowledge about it being difficult to detect  
> > > VPC might be out of date? If so, improvements to the ec2 plugin  
> > > itself are also welcome.
> > > 
> > > Cheers,
> > > 
> > > Steven
> > > 
> > > On Fri, Jan 30, 2015 at 7:20 PM, Steven Danna [steve@chef.io](mailto:steve@chef.io) wrote:
> > > 
> > > > Hi Douglas,
> > > > 
> > > > Unfortunately, reliably detecting VPC nodes is difficult. If you are  
> > > > only seeing slowness without the ohai hint in place, then my guess is  
> > > > that it is a result of the fact that we detect being on ec2 by making  
> > > > a network call to the metadata API:
> > > > 
> > > > [https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45](https://github.com/chef/ohai/blob/master/lib/ohai/plugins/ec2.rb#L45)
> > > > 
> > > > If you are seeing the reload slowness even with the hint enabled, then  
> > > > I would recommend running chef-client with debug logging turned on.  
> > > > The timestamps in the log can often help find which plugins are slow  
> > > > to load.
> > > > 
> > > > > It looks like someone has created a cookbook as a workaround for a  
> > > > > issue with similar symptons. Is this a known issue?
> > > > 
> > > > The difficulty and slowness of detecting EC2 nodes is known and was  
> > > > one of the primary motivators for Ohai's hint system. Currently,  
> > > > using an ohai hint when you know you are on EC2 and disabling the  
> > > > plugin when you know you are not on EC2 is the best method to avoid  
> > > > the speed penalty (and unreliability) of the ec2 detection methods we  
> > > > have.
> > > > 
> > > > The ec2 hint can be put on disk by the knife-ec2 plugin at the time of  
> > > > provisioning or by the ohai cookbook's ohai\_hint LWRP on the first  
> > > > chef-client run. (The ohai cookbook is also capable of disabling  
> > > > plugins).
> > > > 
> > > > Hope this helps.
> > > > 
> > > > Cheers,
> > > > 
> > > > Steven
> > > > 
> > > > On Fri, Jan 30, 2015 at 5:47 PM, Douglas Garstang  
> > > > [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com) wrote:
> > > > 
> > > > > I'm running chef and using ohai plugins inside EC2 instances running  
> > > > > in a  
> > > > > VPC. Aside from creating the hints file, it seems that any ohai  
> > > > > reloads are  
> > > > > horribly slow.
> > > > > 
> > > > > It looks like someone has created a cookbook as a workaround for a  
> > > > > issue  
> > > > > with similar symptons. Is this a known issue?
> > > > > 
> > > > > [GitHub - marcelom/ohai\_ec2\_hack: Fixed Ohai EC2 bug (OHAI-310) detecting EC2 instance inside VPC.](https://github.com/marcelom/ohai_ec2_hack)
> > > > > 
> > > > > Doug
> > 
> > --  
> > Regards,
> > 
> > Douglas Garstang  
> > [http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
> > Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
> > Cell: +1-805-340-5627
> 
> --  
> Regards,
> 
> Douglas Garstang  
> [http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
> Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
> Cell: +1-805-340-5627

--  
Regards,

Douglas Garstang  
[http://www.linkedin.com/in/garstang](http://www.linkedin.com/in/garstang)  
Email: [doug.garstang@gmail.com](mailto:doug.garstang@gmail.com)  
Cell: +1-805-340-5627
