igodwin dfe37d3e4a Add od-backup-schedule runbook + od-backup-check script: schedule & monitor backups
Automate the nightly cold backup (Task Scheduler, filled-in local copy in
private tier), stagger the off-site upload, and MONITOR with three layers:
Task Scheduler last-run, a read-only health check (freshness/completeness/
size), and a dead-man's-switch heartbeat that pings an external monitor only
on success so silent failures and offline servers get caught. od-backup-check.ps1
is read-only (no DB/service), iex-safe, and pings <HEARTBEAT_URL> on PASS.
Cross-linked with od-db-backup.md and od-backup-verify.md; README updated.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 01:07:47 -07:00

rb — runbooks

Generic, reusable IT procedures and scripts for MSP field work. Fetched onto client workstations during on-site work with short, hand-typeable commands.

Warning

This repository is PUBLIC-READ. It must never contain client-identifying information — no client names, hostnames, IPs, usernames, credentials, or screenshots. Procedures with placeholders only. See CONTRIBUTING.md for the sanitization rule.

Provided as-is, no warranty. Running any script is at your own risk. Contains no client-identifying data by policy.

Using a runbook

Fetch and read on the target workstation:

irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file> | more

Run an executable runbook script directly (scripts live under scripts/):

irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/scripts/<file>.ps1 | iex

Scripts prompt for anything client-specific via Read-Host — nothing to edit before running. See scripts/_template.ps1 for the convention.

Layout & naming

  • Runbooks (.md) live flat at the repo root with short, hand-typeable filenames and light category prefixes.
  • Scripts (.ps1) live under scripts/. _template.ps1 sorts first and is the convention reference, not a runnable runbook.
  • Meta (README.md, CONTRIBUTING.md) stays at the root.

Runbook prefixes:

Prefix Domain
win- Windows workstation / server
m365- Microsoft 365 / Entra
od- Open Dental
net- Networking

Placeholder conventions

Fill these from the private tier (private repo or Bitwarden secure note) at run time — never commit filled-in values.

Placeholder Meaning
<CLIENT> Client / site identifier
<SERVER> Server hostname
<SHARE> Share name
<SHARE_USER> Local account used for share access
<USER> End-user account
<PASSWORD> From password manager — never written to a file

Contents

File Purpose
od-smb-cred.md Open Dental SMB share — stored-credential fix
od-cfg-persist.md Open Dental — persist "Do not show this window on startup" (writable FreeDentalConfig.xml)
od-scan-duplex.md Open Dental — duplex ADF scanner captures only one side (TWAIN, Show TWAIN UI branches)
od-db-backup.md Open Dental — rock-solid cold backup of the database + images (stop/copy/start MySQL/MariaDB)
od-backup-verify.md Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist)
od-backup-schedule.md Open Dental — schedule the backup + off-site upload and monitor it (dead-man's-switch heartbeat)
scripts/cg-disable.ps1 Disable Credential Guard, then reboot (prompts to confirm)
scripts/od-cfg-acl.ps1 Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist)
scripts/od-db-backup.ps1 Cold backup: stop MySQL/MariaDB, copy whole data dir + OpenDentImages, always restart (od-db-backup)
scripts/od-backup-check.ps1 Read-only backup health check: freshness/completeness/size + heartbeat ping (od-backup-schedule)

Tiers

  • This repo (public): generic procedures, placeholders only.
  • Private tier: filled-in, client-specific versions — private repo or Bitwarden secure notes. Never here.

This repo also serves as the raw source for Intune remediation scripts and as documented-procedures evidence for E&O / cyber insurance.

S
Description
No description provided
Readme 105 KiB
Languages
PowerShell 100%