Use the env resource to manage environment keys in Microsoft Windows. After an environment key is set, Microsoft Windows must be restarted before the environment key will be available to the Task Scheduler.


On UNIX-based systems, the best way to manipulate environment keys is with the ENV variable in Ruby; however, this approach does not have the same permanent effect as using the env resource.


A env resource block manages environment keys in Microsoft Windows:

env 'ComSpec' do
  value 'C:\\Windows\\system32\\cmd.exe'

The full syntax for all of the properties that are available to the env resource is:

env 'name' do
  delim                      String
  key_name                   String # defaults to 'name' if not specified
  notifies                   # see description
  provider                   Chef::Provider::Env
  subscribes                 # see description
  value                      String
  action                     Symbol # defaults to :create if not specified


  • env is the resource
  • name is the name of the resource block
  • :action identifies the steps the chef-client will take to bring the node into the desired state
  • delim, key_name, provider, and value are properties of this resource, with the Ruby type shown. See “Properties” section below for more information about all of the properties that may be used with this resource.


This resource has the following actions:

Default. Create an environment variable. If an environment variable already exists (but does not match), update that environment variable to match.
Delete an environment variable.
Modify an existing environment variable. This prepends the new value to the existing value, using the delimiter specified by the delim property.
Define this resource block to do nothing until notified by another resource to take action. When this resource is notified, this resource block is either run immediately or it is queued up to be run at the end of the chef-client run.


This resource has the following properties:


Ruby Type: String

The delimiter that is used to separate multiple values for a single key.


Ruby Types: TrueClass, FalseClass

Continue running a recipe if a resource fails for any reason. Default value: false.


Ruby Type: String

The name of the key that is to be created, deleted, or modified. Default value: the name of the resource block. See “Syntax” section above for more information.


Ruby Type: Symbol, ‘Chef::Resource[String]’

Which resource takes action when this resource’s state changes. A resource may notify more than one resource; use a notifies statement for each resource to be notified.

Specify the :action, 'resource[name]', and timer (:delayed or :immediately). Use multiple notifies statements to notify more than one resource.

resource 'name' do
  notifies :action, 'resource[name]', :timer

Use the following timers to specify when a notification is triggered:

Use to specify that a notification should be queued up, and then executed at the very end of a chef-client run.
Use to specify that a notification should be run immediately, per resource notified.

Ruby Type: Chef Class

Optional. Explicitly specify a provider.


Ruby Type: Integer

The number of times to catch exceptions and retry the resource. Default value: 0.


Ruby Type: Integer

The retry delay (in seconds). Default value: 2.


Ruby Type: Symbol, ‘Chef::Resource[String]’

Specify that this resource is to listen to another resource, and then take action when that resource’s state changes.

Specify the :action, 'resource[name]', and timer (:delayed or :immediately). Use multiple subscribes statements to listen to more than one resource.

resource 'name' do
  subscribes :action, 'resource[name]', :timer

The subscribes property uses the same timers as the notifies property.


Ruby Type: String

The value with which key_name is set.


A guard property can be used to evaluate the state of a node during the execution phase of the chef-client run. Based on the results of this evaluation, a guard property is then used to tell the chef-client if it should continue executing a resource. A guard property accepts either a string value or a Ruby block value:

  • A string is executed as a shell command. If the command returns 0, the guard is applied. If the command returns any other value, then the guard property is not applied. String guards in a powershell_script run Windows PowerShell commands and may return true in addition to 0.
  • A block is executed as Ruby code that must return either true or false. If the block returns true, the guard property is applied. If the block returns false, the guard property is not applied.

A guard property is useful for ensuring that a resource is idempotent by allowing that resource to test for the desired state as it is being executed, and then if the desired state is present, for the chef-client to do nothing.


The following properties can be used to define a guard that is evaluated during the execution phase of the chef-client run:

Prevent a resource from executing when the condition returns true.
Allow a resource to execute only if the condition returns true.


The following arguments can be used with the not_if or only_if guard properties:


Specify the user that a command will run as. For example:

not_if 'grep adam /etc/passwd', :user => 'adam'

Specify the group that a command will run as. For example:

not_if 'grep adam /etc/passwd', :group => 'adam'

Specify a Hash of environment variables to be set. For example:

not_if 'grep adam /etc/passwd', :environment => {
  'HOME' => '/home/adam'

Set the current working directory before running a command. For example:

not_if 'grep adam passwd', :cwd => '/etc'

Set a timeout for a command. For example:

not_if 'sleep 10000', :timeout => 10


The following examples demonstrate various approaches for using resources in recipes. If you want to see examples of how Chef uses resources in recipes, take a closer look at the cookbooks that Chef authors and maintains: https://github.com/chef-cookbooks.

Set an environment variable

env 'ComSpec' do
  value "C:\\Windows\\system32\\cmd.exe"