The repo is public and files are fetched by raw URL, so a reader who lands
on one runbook never sees the README -- the repo's context does not travel
with the file. Each .md now carries two lines under the title, each .ps1 the
equivalent at the end of its .NOTES block.
Deliberately two lines, not a paragraph. These files are read through `| more`
on a client console mid-incident, and the top of the file is where the
procedure-specific warnings live -- never a live chart, stop the service
before copying, confirm authorization before acting. A legal preamble above
those competes with them and trains people to skip past.
Wording aims at a stranger who found the repo, not at the quality of the
procedure: these double as documented-procedure evidence for E&O, and
language implying the content is unreliable works against that.
MIT rather than no license: the warranty and liability disclaimer is the part
that does the work, and leaving it unlicensed makes reuse ambiguous rather
than disclaimed.
Also fixes 5 stale ops/rb URLs in scripts/*.ps1 that the previous commit
missed -- it only swept the .md files.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwcG1jLs1T425QRMxtjxP7
The ops -> godwinsystems org move would have made every hand-typed onsite
command 10 characters longer, against the whole reason filenames here are
short. A redirect host makes them shorter than they ever were:
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/od-smb-cred.md
irm rb.godwinsystems.com/od-smb-cred.md
Flips all 6 hardcoded URLs and documents what the hostname is, where the
route is defined, and that removing it means updating these commands in
the same change.
Verified before committing: the short and canonical URLs return
byte-identical content for 5 files, the scheme-less http:// form resolves
through 301 -> 302 -> 200, bare / lands on the repo page, and a missing
file still 404s at the right path.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwcG1jLs1T425QRMxtjxP7
Automate the nightly cold backup (Task Scheduler, filled-in local copy in
private tier), stagger the off-site upload, and MONITOR with three layers:
Task Scheduler last-run, a read-only health check (freshness/completeness/
size), and a dead-man's-switch heartbeat that pings an external monitor only
on success so silent failures and offline servers get caught. od-backup-check.ps1
is read-only (no DB/service), iex-safe, and pings <HEARTBEAT_URL> on PASS.
Cross-linked with od-db-backup.md and od-backup-verify.md; README updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Verify an od-db-backup cold backup by restoring it into a throwaway,
network-isolated Hyper-V VM (revert to checkpoint after), never over live
prod. Covers matching versions from MANIFEST, whole-datadir restore for
InnoDB, re-pointing the image path, and a pass/fail health checklist
(connects, Help>About version, Database Maintenance Check, recent data,
images open, no missing tables, optional mysqlcheck). Cites Open Dental
Backups / Manual Backups / Database Maintenance. Cross-linked with
od-db-backup.md; README updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Off-site replication (Duplicati->B2, rclone, Veeam, etc.) should back up the
cold-copy output under <DEST>, not re-crawl C:\mysql\data. The od-backup-*
folders are already consistent; a naive hot copy of a live InnoDB datadir is
corrupt. Adds sequencing guidance (run off-site job after the cold backup;
stagger schedules) and layered off-site encryption/immutability.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Per Open Dental docs a complete backup is the database + A-to-Z images; the
program itself is not backed up but reinstalled at the matching version on
restore. Extend the script to capture two recovery aids best-effort (outside
the downtime window): a copy of FreeDentalConfig.xml and the exact Open Dental
+ MySQL/MariaDB versions, recorded in MANIFEST.txt. Runbook now spells out
what is/isn't backed up and notes the config file holds the obfuscated DB
password on direct-connect setups.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Rock-solid two-part backup (data directory + OpenDentImages) using the
cold-copy method: stop the DB service, verify it stopped, copy the whole
data dir (incl InnoDB ibdata1/ib_logfile*), then always restart the
service via a finally block. Covers mysqldump supplement, scheduling,
test-restore verification, and 3-2-1 retention.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>