Both are feasible.
Your options you mentioned were:
1)
turn the script into a
template, the recipe would simply
render the template to a given path
and then register a cronjob
This is easy to get started (no real change to your script, it just ensures it's there)
Remember that chef runs every recipe, every time.... As jtimberman said: "it only modifies resources if they do not match the recipe". So your recipe should just overwrite new template when it changes.
OR 2)
Break the script into resources,
providers, etc., and have Chef run it
every hour.
This option is more chef-like, and probably more reliable and scalable -- especially as you put more infrastructure under chef management.
It'll work great if your chef client is daemonized, or chef-solo is run on cron.
In this case you could setup a recipe using resources like the 'user', 'group' and 'file' (to copy ssh keys). See here for details: http://wiki.opscode.com/display/chef/Resources#Resources-File
Then, you're best bet is to use a 'data-bag' (json data) to store user details, and install your users based on that. It's exactly what opscode have done in this recipe (look in ./recipe/sysadmins.rb for inspiration):
https://github.com/opscode/cookbooks/tree/master/users
Just be aware they are using chef-server (or opscode platform). If you're using chef-solo you'll need to replace 'search(:users, 'groups:sysadmin')' with your own data-bag file found somewhere chef-solo can get at it (downloadable, or within your chef-repo).