Capabilities
Active Directory
| Feature | Playbook / Role | Type | Status | Notes |
|---|---|---|---|---|
| Create AD Users and Groups | playbooks/provision_ad.yml | build | dev | |
| Create AD GMSA | playbooks/create-gmsa.yml | build | dev | |
| Remove computer from AD | playbooks/remove-computer-ad.yml | build | dev |
Windows
| feature | playbook | type | status | notes |
|---|---|---|---|---|
| Provision AWS storage | aws_windows_storage | build | prod | |
| Provision Azure storage | azure_windows_storage | build | prod | |
| Install Microsoft SQL | microsoft_sql | build | prod | |
| Install Kuiper | kuiper | build | prod | |
| Install System Pulse | system_pulse | build | prod | |
| Install Cogito and Caboodle | cogito | build | prod | |
| Install windows_exporter | windows_exporter | build | prod | Used with Prometheus monitoring |
| CIS Hardening | trippsc2.cis.windows2022 | build | dev | See playbooks/apply-windows-server-2022-cis-hardening.yml for recommended exclusions |
| Domain join | playbooks/join-domain.yml | build | dev | |
| Log off disconnected sessions | playbooks/logoff-disconnected-sessions.yml | maintenance | prod | Useful for account lockouts after a password change |
Linux
| feature | playbook | type | status | notes |
|---|---|---|---|---|
| Provision AWS storage | aws_linux_storage | build | prod | |
| Provision Azure storage | azure_linux_storage | build | prod |