Files
rb/CONTRIBUTING.md
T
igodwin 6df8a53196 Reorganize: scripts under scripts/, add README disclaimer
- Move _template.ps1 and cg-disable.ps1 into scripts/
- Update all fetch/run URLs and doc links to scripts/ paths
- Rework README layout/naming section; add as-is/no-warranty disclaimer

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 15:56:02 -07:00

54 lines
1.9 KiB
Markdown

# Contributing (note-to-self)
Solo-maintained. This file exists to keep future-me honest.
## The rule
**Procedures only. No particulars.**
This repo is public-read. Anything that identifies a client or would let a
reader act against a client environment goes to the private tier — **no
exceptions.**
Never commit:
- Client / business names, site identifiers
- Hostnames, IPs, subnets, SSIDs, MAC addresses
- Usernames, account names, email addresses
- Passwords, keys, tokens, connection strings, license keys
- Screenshots, exports, logs, or config dumps containing any of the above
Instead use placeholders: `<CLIENT>`, `<SERVER>`, `<SHARE>`, `<SHARE_USER>`,
`<USER>`, `<PASSWORD>`. Filled-in versions live in the **private tier**
(private repo or Bitwarden secure note).
## Where things go
| Content | Home |
|---|---|
| Generic procedure with placeholders | **This repo** |
| Anything needing a credential | Private tier |
| Client-specific config / values | Private tier |
| Any identifying detail | Private tier |
If a step can't be written without a real particular, it doesn't belong here —
split the particular out to the private tier and reference it as a placeholder.
## Before every commit
1. Re-read the diff. Would a stranger learn *who* the client is, or *how to
reach* their systems? If yes, stop.
2. No real hostnames/IPs/users/passwords — placeholders only.
3. No screenshots or pasted output with real data.
4. Scripts prompt for client-specifics at run time; they don't hard-code them.
## Scripts
Scripts live under `scripts/`. Follow [`scripts/_template.ps1`](scripts/_template.ps1):
- Prompt for placeholders with `Read-Host` — no editing before running, no
`param()` (can't pass args through `irm | iex`).
- Safe to run via `irm <url> | iex` from our own server.
- Confirm before anything destructive or that reboots.
- Check for admin explicitly (`#Requires` is not enforced under `iex`).