Initial runbook repo: Open Dental SMB credential fix + conventions
- README: purpose, hand-typeable fetch usage, naming + placeholder conventions - CONTRIBUTING: public-repo sanitization rule (procedures only, no particulars) - _template.ps1: iex-safe script convention (Read-Host, no param, admin check) - od-smb-cred.md: Open Dental SMB stored-credential fix - cg-disable.ps1: standalone Credential Guard disable + reboot Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,70 @@
|
||||
# rb — runbooks
|
||||
|
||||
Generic, reusable IT procedures and scripts for MSP field work. Fetched onto
|
||||
client workstations during on-site work with short, hand-typeable commands.
|
||||
|
||||
> [!WARNING]
|
||||
> **This repository is PUBLIC-READ.** It must never contain client-identifying
|
||||
> information — no client names, hostnames, IPs, usernames, credentials, or
|
||||
> screenshots. Procedures with placeholders **only**. See
|
||||
> [CONTRIBUTING.md](CONTRIBUTING.md) for the sanitization rule.
|
||||
|
||||
## Using a runbook
|
||||
|
||||
Fetch and read on the target workstation:
|
||||
|
||||
```powershell
|
||||
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file> | more
|
||||
```
|
||||
|
||||
Run an executable runbook script directly:
|
||||
|
||||
```powershell
|
||||
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file>.ps1 | iex
|
||||
```
|
||||
|
||||
Scripts prompt for anything client-specific via `Read-Host` — nothing to edit
|
||||
before running. See [`_template.ps1`](_template.ps1) for the convention.
|
||||
|
||||
## Naming
|
||||
|
||||
Flat repo, short filenames, light category prefixes so URLs stay
|
||||
hand-typeable:
|
||||
|
||||
| Prefix | Domain |
|
||||
|---|---|
|
||||
| `win-` | Windows workstation / server |
|
||||
| `m365-` | Microsoft 365 / Entra |
|
||||
| `od-` | Open Dental |
|
||||
| `net-` | Networking |
|
||||
| `_` | Meta / templates (not a runbook) |
|
||||
|
||||
## Placeholder conventions
|
||||
|
||||
Fill these from the private tier (private repo or Bitwarden secure note) at
|
||||
run time — never commit filled-in values.
|
||||
|
||||
| Placeholder | Meaning |
|
||||
|---|---|
|
||||
| `<CLIENT>` | Client / site identifier |
|
||||
| `<SERVER>` | Server hostname |
|
||||
| `<SHARE>` | Share name |
|
||||
| `<SHARE_USER>` | Local account used for share access |
|
||||
| `<USER>` | End-user account |
|
||||
| `<PASSWORD>` | From password manager — never written to a file |
|
||||
|
||||
## Contents
|
||||
|
||||
| File | Purpose |
|
||||
|---|---|
|
||||
| [`od-smb-cred.md`](od-smb-cred.md) | Open Dental SMB share — stored-credential fix |
|
||||
| [`cg-disable.ps1`](cg-disable.ps1) | Disable Credential Guard, then reboot (prompts to confirm) |
|
||||
|
||||
## Tiers
|
||||
|
||||
- **This repo (public):** generic procedures, placeholders only.
|
||||
- **Private tier:** filled-in, client-specific versions — private repo or
|
||||
Bitwarden secure notes. Never here.
|
||||
|
||||
This repo also serves as the raw source for Intune remediation scripts and as
|
||||
documented-procedures evidence for E&O / cyber insurance.
|
||||
Reference in New Issue
Block a user