# Using kitchen-ssh driver to run Inspec tests on remote node

**URL:** <https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035>\
**Category:** Chef Infra (archive)\
**Created:** [July 27, 2016, 9:11pm UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035 "2016-07-27T21:11:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![etg7125](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@etg7125](https://discourse.chef.io/u/etg7125)\
**Post date:** [July 27, 2016, 9:11pm UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035/1 "2016-07-27T21:11:40Z")

</div>

**The problem:**  
I am trying to use the kitchen-ssh driver in the .kitchen.yml file to run test kitchen on a remote node, but running kitchen commands simply uses the SSH connection to spin up a VM on that node’s ipaddress.

Rather than spinning up a new VM with every kitchen command, I want to make kitchen run the Inspec tests on the actual node itself, then withdraw from the SSH, returning the pass/fail log of the tests.

  
\*\*My questions:\*\* Am I misusing kitchen-ssh here, or missing the point of test kitchen's create/test/destroy methodology? Or am I just combining the wrong tools to try to accomplish what I need?

When I run kitchen test or kitchen create/converge with the below .yml file everything runs perfectly fine, and I get no failures, but I don’t actually understand what’s going on with the SSH connection - I haven’t found much documentation on how kitchen-ssh works and what it does other than the following github link:

> **[neillturner/kitchen-ssh](https://github.com/neillturner/kitchen-ssh)**
>
> kitchen-ssh - ssh and ssh\_gzip driver for test-kitchen for any running server with an ip address

## Thanks for your help. **My .kitchen.yml file:**

driver:  
name: ssh  
hostname: 10.204.81.250  
port: 22  
username: egiese  
ssh\_key: /Users/egiese/.ssh/id\_rsa

provisioner:  
name: chef\_zero

platforms:

- name: rhel-6.7

suites:

- name: default  
run\_list:
  - recipe[httpdtest::default]  
attributes:

---

<div class="post-metadata">

**Author:** ![Matt\_Wrock](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/matt_wrock/32/3394_2.png) [@Matt\_Wrock](https://discourse.chef.io/u/Matt_Wrock)\
**Post date:** [July 28, 2016, 1:27am UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035/2 "2016-07-28T01:27:40Z")

</div>

I think you want to use the built in `proxy` driver instead of the ssh driver. That will not try to create a vm but simmply connects to a running instance. So your yaml would look like:

```auto
driver:
  name: proxy
  host: <ip or host name of server>
  reset_command: "exit 0"
  port: 22
  username: <ssh user>
  password: <ssh password>

```

You can use the `reset_command` to reset any state if necessary. `exit 0` is a good no op command to use.

---

<div class="post-metadata">

**Author:** ![coderanger](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/coderanger/32/5_2.png) [@coderanger](https://discourse.chef.io/u/coderanger)\
**Post date:** [July 28, 2016, 1:29am UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035/3 "2016-07-28T01:29:43Z")

</div>

InSpec (or rather `kitchen-inspec`) doesn’t use Kitchen’s communication abstraction at all so which driver you use is moot. That said, if you don’t want the VM management features, you might just want to use InSpec on its own.

---

<div class="post-metadata">

**Author:** ![etg7125](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@etg7125](https://discourse.chef.io/u/etg7125)\
**Post date:** [July 28, 2016, 2:23pm UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035/4 "2016-07-28T14:23:36Z")

</div>

Oh wow, this is awesome! Just tried it and had great results! Thank you so much for your help!!!

I have another question as well about the reset\_command functionality. Is there a way to use this to create a ‘snapshot’ of the server before the cookbook is fully converged (but after kitchen has proxied in), and then ‘reset’ the node back to the snapshot state. Essentially, a way to reset the node to what it was before the cookbooks and testing were run, but without destroying it, like kitchen normally does.

I was thinking of having some kind of system backup/restore command inside a recipe, but if the reset\_command can do this that’d be even better.

---

<div class="post-metadata">

**Author:** ![Matt\_Wrock](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/matt_wrock/32/3394_2.png) [@Matt\_Wrock](https://discourse.chef.io/u/Matt_Wrock)\
**Post date:** [July 28, 2016, 2:32pm UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035/5 "2016-07-28T14:32:08Z")

</div>

Glad this worked for you!

The proxy driver is super minimal and does not really have any kind of snapshotting capability built in. You could have it run a shell script that has awareness of your convergence scenario and set everything back, but its really on you to do that work.

---

<div class="post-metadata">

**Author:** ![etg7125](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@etg7125](https://discourse.chef.io/u/etg7125)\
**Post date:** [July 29, 2016, 12:44pm UTC](https://discourse.chef.io/t/using-kitchen-ssh-driver-to-run-inspec-tests-on-remote-node/9035/6 "2016-07-29T12:44:09Z")

</div>

Hi Matt,

I know this is completely unrelated to this thread, but I have noticed a bug on this site that I wanted to point out. While at the top of the screen, 'Chef Mailing List' and the thread topic appear just fine, but as soon as you scroll down to view posts, the thread title, the Chef logo, and the forum tag (chef, chef-dev, etc) all merge on top of each other. Please see the screenshot below:

![](https://sea2.discourse-cdn.com/flex016/images/transparent.png)
