# Shell access timeout after 60secs

**URL:** <https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825>\
**Category:** Get Help\
**Created:** [October 21, 2024, 4:17pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825 "2024-10-21T16:17:21Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![samagids](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/samagids/32/2445_2.png) [@samagids](https://discourse.openondemand.org/u/samagids)\
**Post date:** [October 21, 2024, 4:17pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/1 "2024-10-21T16:17:21Z")

</div>

Upgraded to 3.1.9 and now the shell timeout less than a minute.

Set passenger pool timeout to 300 and 900 with no success

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 21, 2024, 4:23pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/2 "2024-10-21T16:23:33Z")

</div>

3.1.9 announcement should have said something about the shell app utilizing ping pongs to keep the connection alive.

Here are the docs for the same:

[https://osc.github.io/ood-documentation/latest/customizations.html#enable-and-configure-shell-ping-pong](https://osc.github.io/ood-documentation/latest/customizations.html#enable-and-configure-shell-ping-pong)

---

<div class="post-metadata">

**Author:** ![kenny.hanson](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@kenny.hanson](https://discourse.openondemand.org/u/kenny.hanson)\
**Post date:** [October 24, 2024, 2:56pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/3 "2024-10-24T14:56:03Z")

</div>

I set the inactivity timeout to 1 hour and max terminal life to 24 hours. I also enabled ping pongs to keep it alive. The terminal started at 8:48am and disconnected at 8:54am.

OOD\_SHELL\_INACTIVE\_TIMEOUT\_MS=36000000  
OOD\_SHELL\_MAX\_DURATION\_MS=8640000000  
OOD\_SHELL\_PING\_PONG=true

Is there any way to completely disable this behavior and return to the old style that didn’t disconnect?

Kenny

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 3:03pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/4 "2024-10-24T15:03:11Z")

</div>

Did you restart your webserver to pick up the new configs?

---

<div class="post-metadata">

**Author:** ![kenny.hanson](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@kenny.hanson](https://discourse.openondemand.org/u/kenny.hanson)\
**Post date:** [October 24, 2024, 3:06pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/5 "2024-10-24T15:06:00Z")

</div>

Hi Jeff 🙂 Thanks for the quick reply.

Restart as in systemctl restart httpd? Or restart as in Developer menu Restart Webserver?

We first set ping pong = true and figured that disables the timers, update\_ood\_portal, then I logged out and logged back in. I was disconnected fairly quickly. I then added my long default timers and restarted webserver using the developer menu and I was disconnected as described earlier.

I’m trying one more time.

K

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 3:07pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/6 "2024-10-24T15:07:53Z")

</div>

Yea restart the webserver in the help menu to pick up new application configurations.

---

<div class="post-metadata">

**Author:** ![emily.dragowsky](https://avatars.discourse-cdn.com/v4/letter/e/c68b51/32.png) [@emily.dragowsky](https://discourse.openondemand.org/u/emily.dragowsky)\
**Post date:** [October 24, 2024, 3:10pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/7 "2024-10-24T15:10:40Z")

</div>

> [@Jeff Ohrstrom](#):
>
> 3.1.9 announcement should have said something about the shell app utilizing ping pongs to keep the connection alive. Here are the docs for the same: [Customizations — Open OnDemand 3.1.0 documentation](https://osc.github.io/ood-documentation/latest/customizations.html#enable-and-configure-shell-ping-pong)

Our situation isn’t quite so drastic. We’ve not implemented a config for the shell app previously. Obviously, now it is necessary. We had server maintenance Monday this week, and our ondemand was updated to 3.1.9.

Our shells have tended to last up to 30 mins or so, although some account holders report that for them the shells don’t last more than 5 mins.

Thanks to samagids and kenny for driving the discussion. And thanks Jeff for providing the doc to resolve the situation.

~ Em

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 3:20pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/8 "2024-10-24T15:20:29Z")

</div>

Not sure what to say about folks getting kicked after 5 minutes. My only guess is their PUN didn’t bounce to pick up the new configurations.

I’m trying to replicate right now. I started this at ~11:06 EST and continue to get and send ping/pongs past 5 minutes (up to 11:19 in the screenshot).

 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/6/6264a5f47a979128d227853d9afaa3e9b704cac9.png)

So I can get past 5 minutes and will hold it there and update the thread later.

> [@kenny.hanson](#):
>
> Is there any way to completely disable this behavior and return to the old style that didn’t disconnect?

No, and you can blame me personally for this if you like. I made the decision to disable it by default because I figured we (the developers/maintainers) need to be conservative in the defaults we provide here. I (the developer) need to distribute secure defaults so that someone’s not surprised when a shell session can last much longer (forever actually) than their authentication system would allow.

---

<div class="post-metadata">

**Author:** ![kenny.hanson](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@kenny.hanson](https://discourse.openondemand.org/u/kenny.hanson)\
**Post date:** [October 24, 2024, 3:26pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/9 "2024-10-24T15:26:23Z")

</div>

I’ve got a test running too, an idle inactive background tab has been going for 15 minutes now.

I believe in security defaults so no worries as I can think of situations where the timers can be helpful. I’ll be editing my defaults to more reasonable times when I’ve got this stable.

How did you get your network inspector to show that? Mine just sits with nothing reporting.

K

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 3:28pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/10 "2024-10-24T15:28:59Z")

</div>

> [@kenny.hanson](#):
>
> How did you get your network inspector to show that? Mine just sits with nothing reporting.

Yea it’s a bit funny. Once you have the tab open - hard refresh the page and _then_ you should start seeing them. It’s like if the connection has already been made (or in the process of being made) when the developer tools is open it won’t report anything.

---

<div class="post-metadata">

**Author:** ![kenny.hanson](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@kenny.hanson](https://discourse.openondemand.org/u/kenny.hanson)\
**Post date:** [October 24, 2024, 3:30pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/11 "2024-10-24T15:30:24Z")

</div>

Ahh there we go. Does that reset the timers too?

K

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 3:31pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/12 "2024-10-24T15:31:29Z")

</div>

Yea because it’s a new connection at that point.

---

<div class="post-metadata">

**Author:** ![emily.dragowsky](https://avatars.discourse-cdn.com/v4/letter/e/c68b51/32.png) [@emily.dragowsky](https://discourse.openondemand.org/u/emily.dragowsky)\
**Post date:** [October 24, 2024, 3:41pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/13 "2024-10-24T15:41:11Z")

</div>

Sorry, battling a cold this morning, so all is fuzzier than usual.

Is it adequate to implement the changes in a running ood session via the 'restart web server" from help menu? or is a httpd service restart necessary after all?

Also, I’ve implemented …/shell/env file, with the two setting, but without enabling ping pongs. I’ve had two sessions fail under these conditions.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 3:46pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/14 "2024-10-24T15:46:03Z")

</div>

> [@emily.dragowsky](#):
>
> Is it adequate to implement the changes in a running ood session via the 'restart web server" from help menu? or is a httpd service restart necessary after all?

No you shouldn’t need to restart httpd for any application configs (shell, dashboard or otherwise). The link to restart your webserver will restart _your_ webserver, but if you need to bounce them all you need to issue the `nginx_stage` command.

> [@emily.dragowsky](#):
>
> Also, I’ve implemented …/shell/env file, with the two setting, but without enabling ping pongs. I’ve had two sessions fail under these conditions.

You need to enable ping pongs to keep the connection alive. Otherwise you’d need some trick like backgrounding something that prints stuff at regular intervals or similar. apache’s going to disconnect the connection after 60 seconds if there’s no traffic (pings and pongs are the traffic that will keep the connection alive).

---

<div class="post-metadata">

**Author:** ![kenny.hanson](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@kenny.hanson](https://discourse.openondemand.org/u/kenny.hanson)\
**Post date:** [October 24, 2024, 4:09pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/15 "2024-10-24T16:09:07Z")

</div>

> [@jeff.ohrstrom](#):
>
> No you shouldn’t need to restart httpd for any application configs (shell, dashboard or otherwise). The link to restart your webserver will restart _your_ webserver, but if you need to bounce them all you need to issue the `nginx_stage` command.

Jeff you caught my attention with `nginx_stage` command. How exactly do I do that and where is the documentation that describes how to affect all active site logins?

---

<div class="post-metadata">

**Author:** ![emily.dragowsky](https://avatars.discourse-cdn.com/v4/letter/e/c68b51/32.png) [@emily.dragowsky](https://discourse.openondemand.org/u/emily.dragowsky)\
**Post date:** [October 24, 2024, 4:15pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/16 "2024-10-24T16:15:36Z")

</div>

Thanks, Jeff – I’m testing on backup/dev server, and enabling the pong was an additional necessary step, as you report.

Nice that for the apps it’s not system-level invasive to reset.

Appreciate you!

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 24, 2024, 4:17pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/17 "2024-10-24T16:17:35Z")

</div>

The documentation for this is here, though I admit, I see how it’s buried and not super discoverable.

IIRC the executable is at `/opt/ood/nginx_stage/sbin/nginx_stage`. That may not be 100% correct, but it’s definitely in `/opt/ood`.

[https://osc.github.io/ood-documentation/latest/reference/commands/nginx-stage/commands/nginx-clean.html#nginx-stage-nginx-clean](https://osc.github.io/ood-documentation/latest/reference/commands/nginx-stage/commands/nginx-clean.html#nginx-stage-nginx-clean)

---

<div class="post-metadata">

**Author:** ![kenny.hanson](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@kenny.hanson](https://discourse.openondemand.org/u/kenny.hanson)\
**Post date:** [October 24, 2024, 4:45pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/18 "2024-10-24T16:45:02Z")

</div>

Thanks, Jeff. I do believe the timers are working fine now. Thanks for the help.

Kenny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [April 22, 2025, 4:45pm UTC](https://discourse.openondemand.org/t/shell-access-timeout-after-60secs/3825/19 "2025-04-22T16:45:33Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
