# rb — runbooks Generic, reusable IT procedures and scripts for MSP field work. Fetched onto client workstations during on-site work with short, hand-typeable commands. > [!WARNING] > **This repository is PUBLIC-READ.** It must never contain client-identifying > information — no client names, hostnames, IPs, usernames, credentials, or > screenshots. Procedures with placeholders **only**. See > [CONTRIBUTING.md](CONTRIBUTING.md) for the sanitization rule. > Provided as-is, no warranty. Running any script is at your own risk. Contains > no client-identifying data by policy. ## Using a runbook Fetch and read on the target workstation: ```powershell irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/ | more ``` Run an executable runbook script directly (scripts live under `scripts/`): ```powershell irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/scripts/.ps1 | iex ``` Scripts prompt for anything client-specific via `Read-Host` — nothing to edit before running. See [`scripts/_template.ps1`](scripts/_template.ps1) for the convention. ## Layout & naming - **Runbooks** (`.md`) live flat at the repo root with short, hand-typeable filenames and light category prefixes. - **Scripts** (`.ps1`) live under [`scripts/`](scripts/). `_template.ps1` sorts first and is the convention reference, not a runnable runbook. - **Meta** (`README.md`, `CONTRIBUTING.md`) stays at the root. Runbook prefixes: | Prefix | Domain | |---|---| | `win-` | Windows workstation / server | | `m365-` | Microsoft 365 / Entra | | `od-` | Open Dental | | `net-` | Networking | ## Placeholder conventions Fill these from the private tier (private repo or Bitwarden secure note) at run time — never commit filled-in values. | Placeholder | Meaning | |---|---| | `` | Client / site identifier | | `` | Server hostname | | `` | Share name | | `` | Local account used for share access | | `` | End-user account | | `` | From password manager — never written to a file | ## Contents | File | Purpose | |---|---| | [`od-smb-cred.md`](od-smb-cred.md) | Open Dental SMB share — stored-credential fix | | [`od-cfg-persist.md`](od-cfg-persist.md) | Open Dental — persist "Do not show this window on startup" (writable FreeDentalConfig.xml) | | [`od-scan-duplex.md`](od-scan-duplex.md) | Open Dental — duplex ADF scanner captures only one side (TWAIN, Show TWAIN UI branches) | | [`od-db-backup.md`](od-db-backup.md) | Open Dental — rock-solid cold backup of the database + images (stop/copy/start MySQL/MariaDB) | | [`od-backup-verify.md`](od-backup-verify.md) | Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist) | | [`scripts/cg-disable.ps1`](scripts/cg-disable.ps1) | Disable Credential Guard, then reboot (prompts to confirm) | | [`scripts/od-cfg-acl.ps1`](scripts/od-cfg-acl.ps1) | Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist) | | [`scripts/od-db-backup.ps1`](scripts/od-db-backup.ps1) | Cold backup: stop MySQL/MariaDB, copy whole data dir + OpenDentImages, always restart (od-db-backup) | ## Tiers - **This repo (public):** generic procedures, placeholders only. - **Private tier:** filled-in, client-specific versions — private repo or Bitwarden secure notes. Never here. This repo also serves as the raw source for Intune remediation scripts and as documented-procedures evidence for E&O / cyber insurance.