Move runbooks into domain directories

od-db-backup.md becomes od/db-backup.md -- the hyphen becomes a slash, so
the fetch command is exactly as long to type as before. That mattered: the
length of a hand-typed command is the constraint this repo is organized
around, and a reorganization that lengthened it would have been a net loss.

Scripts deliberately stay flat in scripts/ with their domain prefix.
Everything executable in one directory is the set worth reading before it
runs, and nesting five files by domain would add characters without adding
clarity.

Updates every reference: README Contents (now grouped by directory), the
layout section, both fetch examples, inter-runbook links, and the .NOTES
headers in all five scripts. Verified every markdown link resolves on disk
and that Contents and the filesystem agree in both directions.

Records the naming rule in CONTRIBUTING so the next file lands correctly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwcG1jLs1T425QRMxtjxP7
This commit is contained in:
2026-09-02 23:15:48 -07:00
parent f2a979f047
commit cb0c5b4614
14 changed files with 91 additions and 48 deletions
+51 -23
View File
@@ -20,13 +20,13 @@ client workstations during on-site work with short, hand-typeable commands.
Fetch and read on the target workstation:
```powershell
irm rb.godwinsystems.com/<file> | more
irm rb.godwinsystems.com/od/db-backup.md | more
```
Run an executable runbook script directly (scripts live under `scripts/`):
```powershell
irm rb.godwinsystems.com/scripts/<file>.ps1 | iex
irm rb.godwinsystems.com/scripts/od-db-backup.ps1 | iex
```
Scripts prompt for anything client-specific via `Read-Host` — nothing to edit
@@ -44,7 +44,7 @@ mid-incident — the canonical URL is 63 characters before the filename. The
canonical form still works and is what the redirect targets:
```
https://gitea.ivangodwin.com/godwinsystems/rb/raw/branch/main/<file>
https://gitea.ivangodwin.com/godwinsystems/rb/raw/branch/main/<dir>/<file>.md
```
The redirect is a backendless Gateway API `HTTPRoute` defined in
@@ -55,21 +55,37 @@ runbook here documents a dead URL.
## Layout & naming
- **Runbooks** (`.md`) live flat at the repo root with short, hand-typeable
filenames and light category prefixes.
- **Scripts** (`.ps1`) live under [`scripts/`](scripts/). `_template.ps1`
sorts first and is the convention reference, not a runnable runbook.
- **Meta** (`README.md`, `CONTRIBUTING.md`) stays at the root.
```
od/ Open Dental
sec/ Security / incident response
scripts/ Executable .ps1 — one flat namespace, prefixed by domain
```
Runbook prefixes:
- **Runbooks** (`.md`) live in a domain directory, named without a prefix —
the directory is the prefix. `od/db-backup.md`, not `od-db-backup.md`.
- **Scripts** (`.ps1`) stay flat in [`scripts/`](scripts/) and keep their
domain prefix. One directory holds everything executable, which is the set
worth auditing before a change; `_template.ps1` sorts first as the
convention reference, not a runnable runbook.
- **Meta** (`README.md`, `CONTRIBUTING.md`, `LICENSE`) stays at the root.
| Prefix | Domain |
The split is deliberate: the fetch command's length is the constraint this
repo is organized around, and `od/db-backup.md` is exactly as long to type as
`od-db-backup.md` was — the hyphen became a slash. Nesting scripts by domain
too would add characters without adding clarity to a five-file directory.
Domain directories, as they are needed:
| Directory | Domain |
|---|---|
| `win-` | Windows workstation / server |
| `m365-` | Microsoft 365 / Entra |
| `od-` | Open Dental |
| `net-` | Networking |
| `sec-` | Security / incident response |
| `win/` | Windows workstation / server |
| `m365/` | Microsoft 365 / Entra |
| `od/` | Open Dental |
| `net/` | Networking |
| `sec/` | Security / incident response |
Non-interactive scripts (Intune remediations) get their own sibling directory
when they arrive — not `scripts/`, which is for `iex`-safe interactive ones.
## Placeholder conventions
@@ -87,16 +103,28 @@ run time — never commit filled-in values.
## Contents
### Open Dental — `od/`
| File | Purpose |
|---|---|
| [`od/smb-cred.md`](od/smb-cred.md) | Open Dental SMB share — stored-credential fix |
| [`od/cfg-persist.md`](od/cfg-persist.md) | Open Dental — persist "Do not show this window on startup" (writable FreeDentalConfig.xml) |
| [`od/scan-duplex.md`](od/scan-duplex.md) | Open Dental — duplex ADF scanner captures only one side (TWAIN, Show TWAIN UI branches) |
| [`od/db-backup.md`](od/db-backup.md) | Open Dental — rock-solid cold backup of the database + images (stop/copy/start MySQL/MariaDB) |
| [`od/backup-verify.md`](od/backup-verify.md) | Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist) |
| [`od/backup-schedule.md`](od/backup-schedule.md) | Open Dental — schedule the backup + off-site upload and monitor it (dead-man's-switch heartbeat) |
### Security / incident response — `sec/`
| File | Purpose |
|---|---|
| [`sec/google-compromise.md`](sec/google-compromise.md) | Incident response — suspected compromise of a **consumer** Google/Gmail account (AiTM session theft; no Workspace admin console) |
| [`sec/google-evidence.md`](sec/google-evidence.md) | Google/Gmail account — evidence capture before changes + re-entry check after a password reset (numbered, field-usable) |
### Scripts — `scripts/`
| File | Purpose |
|---|---|
| [`od-smb-cred.md`](od-smb-cred.md) | Open Dental SMB share — stored-credential fix |
| [`od-cfg-persist.md`](od-cfg-persist.md) | Open Dental — persist "Do not show this window on startup" (writable FreeDentalConfig.xml) |
| [`od-scan-duplex.md`](od-scan-duplex.md) | Open Dental — duplex ADF scanner captures only one side (TWAIN, Show TWAIN UI branches) |
| [`od-db-backup.md`](od-db-backup.md) | Open Dental — rock-solid cold backup of the database + images (stop/copy/start MySQL/MariaDB) |
| [`od-backup-verify.md`](od-backup-verify.md) | Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist) |
| [`od-backup-schedule.md`](od-backup-schedule.md) | Open Dental — schedule the backup + off-site upload and monitor it (dead-man's-switch heartbeat) |
| [`sec-google-compromise.md`](sec-google-compromise.md) | Incident response — suspected compromise of a **consumer** Google/Gmail account (AiTM session theft; no Workspace admin console) |
| [`sec-google-evidence.md`](sec-google-evidence.md) | Google/Gmail account — evidence capture before changes + re-entry check after a password reset (numbered, field-usable) |
| [`scripts/cg-disable.ps1`](scripts/cg-disable.ps1) | Disable Credential Guard, then reboot (prompts to confirm) |
| [`scripts/od-cfg-acl.ps1`](scripts/od-cfg-acl.ps1) | Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist) |
| [`scripts/od-db-backup.ps1`](scripts/od-db-backup.ps1) | Cold backup: stop MySQL/MariaDB, copy whole data dir + OpenDentImages, always restart (od-db-backup) |