3 ms·
I am a co-founder of a small SaaS company. We recently decided to make the investment of upgrading our infrastructure setup process from "Hey David go do that"
by apinstein 15y ago
I am a co-founder of a small SaaS company. We recently decided to make the investment of upgrading our infrastructure setup process from "Hey David go do that" to being 100% chef-based.
I managed the process, and consider it a success. However, here are some points I would make:
1. It took a long time. Let's be generous and say it took 2-3 man-months of time to set up 4-5 different projects and roles. This was probably 10-20x what it would've taken to set up the servers directly. Why? Learning curve with chef for both our programmer and sysadmin. Figuring out how to make config changes automatable and idempotent.
2. The scale you get from chef is bigger than managing production infrastructure. We now use chef for not only production deployment, but also dev. Once paired with Vagrant, we are able to get new devs up with a complete stack in about 10m of keyboard time. If we need to upgrade to some new version of something, only one person has to deal with the sysadmin; everyone else can just update their box.
3. I think it will save money in the long-term. A good sysadmin is $100/hr+. Unfortunately you have to pay that rate whether they're doing architecture, security review, or just editing text files. With chef, a non-sysadmin resource can generate recipes with just architectural advice and review from a sysadmin. This is much more efficient, especially for small shops where a sysadmin is an expensive and not immediately available resource.
- bryanwb 15y agoawesome comments, apinstein btw, I am copying your method of managing dotfiles with a Rakefile as we speak. I counter that while it takes a while to learn chef, it also takes many times more effort to maintain a custom set of shell scripts over the long term
- devmach 15y agoIs there a something like Foreman[1] for Chef ? Something able to create and spin up new VM and execute receipts after install ( by using just a "web browser" ). [1]: http://theforeman.org/projects/foreman/wiki/Screencasts http://theforeman.org/projects/foreman/wiki/Screencasts
- apinstein 15y agoOh nice I hadn't seen Foreman before. Looks like EC2 console but for your own stack. We use XEN, that might be nice. I don't know what you mean by "execute receipts" however in the video they kick off a puppet run, which makes me think you could similarly kick off a chef run instead.
- manvsmachine 15y agoI'm guessing that 'receipts' was meant to be 'recipes'.
- devmach 15y agoSorry, my bad. I meant to say "recipes".
- tptacek 15y agoA good sysadmin costs $200k/year? Or do you have a contract sysadmin? Because that number sounds way, way, way high. (We recently hired a sysadmin "+").
- apinstein 15y agoWe've been in business for about 8 years and use about ~100 sysadmin hours a year. I interviewed several sysadmins over the years and no one that I deemed competent charged less than $100/hour. I did find people charging as low as $50/hour but they didn't seem that great, or that reliable, or that available. For me as well, you pretty much need to trust your sysadmin more than almost anyone else in your company (except people that can sign checks). Trust comes at a premium. I will yield that I don't like working with substandard people. I hate having to manage people and am willing to pay a premium for people I trust to work on the right things with the right skills in a timely manner. Besides, it doesn't scale. One of my business goals is to never have middle management.
- tptacek 15y agoYou'd be more convincing if you didn't imply that anyone who worked for less than $100/hr was "substandard". For full-time salaried, I assure you, $200k/yr is not the going rate for sysadmin.
- nestlequ1k 15y agoYou cant directly equate contract hourly rate with yearly salary. If you don't have the budget to hire a 100k a yr salary, you'll have to pay contract rates which could be over 100/hr
- tptacek 15y agoI buy that the valley is so hot right now that a sysadmin commands $100k/yr there, but they don't in Chicago, Seattle, or New York. I'm not looking to argue so much as to inject some more data into the price point that was casually dropped on this thread earlier. I do not think the other guy overpaid for sysadmin; if he's got an amazing admin, great! I can see paying a premium for that. Another point I'd like to raise is, if you're paying $100k/hr for sysadmin, and using them frequently, contracting instead of fulltiming sysadmin might be penny-wise-pound-foolish. But maybe not, if you're only paying $10,000/yr in sysadmin. We've used over 100 hours of admin in just the last couple weeks. A great hire; one we made "37signals-style", after realizing that doing all the sysadmin chores ourselves was subtly making us all miserable and ineffective. Believe me, I know the difference between contracting rates and salary. ;)
- sjwright 15y agoI learned a new word today: Idempotence. Thank you.
- Dalves 15y agoYou've just echoed my experience with chef but I'm still on the fence as to whether I think it was a success or not and whether I'd use it again. We were able to achieve everything we wanted but to say it took a metric fuckton of time would be a grave understatement. Even what are ordinarily trivial things took a lot longer than I expected. Some things I just found to be oddly designed and surprisingly inflexible, especially the recipe construct. I still to this day see no point of having a folder with 2 subfolders with 3 files combined for what amounts to "apt get install somepackage". And having to learn a DSL to replace the already very effective bash is in my opinion not a very enticing trade. Although it's very new, I think I'll try out juju.ubuntu.com for my next large deployment instead of sticking with chef or puppet, if only for the flexibility of the hooks-in-any-language thing and a chance to feed my bash fetish.
- lkanies 15y ago(disclaimer - Puppet Labs employee) 2-3 months is a long time. We consistently hear 2-6 weeks to get to full production, with 30-120 minutes for some proof of concept work. And one of the great things about Puppet is you can start very small - automate the parts that are hardest, most critical, etc., and do bits manually as it makes sense for your problem set. And yeah, managing dev and prod the same way is absolutely critical for clean deployments.