- README: purpose, hand-typeable fetch usage, naming + placeholder conventions - CONTRIBUTING: public-repo sanitization rule (procedures only, no particulars) - _template.ps1: iex-safe script convention (Read-Host, no param, admin check) - od-smb-cred.md: Open Dental SMB stored-credential fix - cg-disable.ps1: standalone Credential Guard disable + reboot Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.2 KiB
rb — runbooks
Generic, reusable IT procedures and scripts for MSP field work. Fetched onto client workstations during on-site work with short, hand-typeable commands.
Warning
This repository is PUBLIC-READ. It must never contain client-identifying information — no client names, hostnames, IPs, usernames, credentials, or screenshots. Procedures with placeholders only. See CONTRIBUTING.md for the sanitization rule.
Using a runbook
Fetch and read on the target workstation:
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file> | more
Run an executable runbook script directly:
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file>.ps1 | iex
Scripts prompt for anything client-specific via Read-Host — nothing to edit
before running. See _template.ps1 for the convention.
Naming
Flat repo, short filenames, light category prefixes so URLs stay hand-typeable:
| Prefix | Domain |
|---|---|
win- |
Windows workstation / server |
m365- |
Microsoft 365 / Entra |
od- |
Open Dental |
net- |
Networking |
_ |
Meta / templates (not a runbook) |
Placeholder conventions
Fill these from the private tier (private repo or Bitwarden secure note) at run time — never commit filled-in values.
| Placeholder | Meaning |
|---|---|
<CLIENT> |
Client / site identifier |
<SERVER> |
Server hostname |
<SHARE> |
Share name |
<SHARE_USER> |
Local account used for share access |
<USER> |
End-user account |
<PASSWORD> |
From password manager — never written to a file |
Contents
| File | Purpose |
|---|---|
od-smb-cred.md |
Open Dental SMB share — stored-credential fix |
cg-disable.ps1 |
Disable Credential Guard, then reboot (prompts to confirm) |
Tiers
- This repo (public): generic procedures, placeholders only.
- Private tier: filled-in, client-specific versions — private repo or Bitwarden secure notes. Never here.
This repo also serves as the raw source for Intune remediation scripts and as documented-procedures evidence for E&O / cyber insurance.