执行chef-client时返回HTTP 404错误,请求排查原因
Troubleshooting the Chef Client HTTP 404 Error
Let's walk through fixing that HTTP 404 error you're seeing when running:
chef-client -S https://ip-172-31-87-170.ec2.internal -K /etc/chef/4thcoffee-validator.pem
First, let's spot the obvious typo in your client.rb—this is likely causing configuration parsing issues that could throw off your chef_server_url handling:
- You have
log__location STDOUT(double underscore) but the correct setting islog_location STDOUT(single underscore). Fix that first, as invalid config settings can prevent the client from loading proper server connection details.
Next, let's dig into other common causes of this 404:
1. Verify the Chef Server URL is reachable and correct
- Test if the server URL responds at all by running:
If you get a 404 here, confirm:curl -v https://ip-172-31-87-170.ec2.internal- The EC2 instance
ip-172-31-87-170.ec2.internalis actually running the Chef Server service. - The Chef Server is using the default port 443—if it's configured to use a different port (like 8443), you need to add it to the URL, e.g.,
https://ip-172-31-87-170.ec2.internal:8443. - The server's DNS/hostname resolves correctly from your client node (try pinging the hostname to check).
- The EC2 instance
2. Validate the validator certificate
- Ensure the
/etc/chef/4thcoffee-validator.pemfile:- Exists and has proper permissions (set to
600so only the root user can read it:chmod 600 /etc/chef/4thcoffee-validator.pem). - Matches the validator key stored on your Chef Server. If this key was deleted or revoked on the server, the client will fail to authenticate, which can sometimes manifest as a 404.
- Exists and has proper permissions (set to
3. Check trusted certificates configuration
- Your
trusted_certs_diris set to/root/.chef/trusted_certs—make sure this directory contains the Chef Server's SSL certificate. Without it, the client can't establish a secure connection, which might lead to unexpected 404 errors.- You can fetch the server's cert using:
knife ssl fetch https://ip-172-31-87-170.ec2.internal
/var/opt/opscode/nginx/ca/directory to your client's trusted certs folder. - You can fetch the server's cert using:
After fixing the typo and verifying these points, re-run the chef-client command and see if the error resolves. If you're still hitting issues, check the Chef Client logs (since you set log_location STDOUT, the logs will print directly to your terminal) for more specific error details.
内容的提问来源于stack exchange,提问作者user2159389
相关产品推荐
相关产品推荐

