Preface
Who This Book Is For
How to Use This Book
- Part I: The Case for Deterministic Orchestration
Chapter 1: The Problem with Procedural Scripts
- 1.1 The Script That Worked, Until It Didn’t
- 1.2 Four Symptoms of Procedural Rot
- 1.3 Why This Matters at Fleet Scale
- 1.4 Introducing Ashfield College
- 1.5 What Solving This Properly Requires
- Chapter Summary
Chapter 2: The Four-Phase Contract
- 2.1 Four Questions, Not Four Steps
- 2.2 The Central Rule
- 2.3 One-Way Data Flow
- 2.4 Why Four, and Not Three or Five
- 2.5 Resolving Chapter 1, Symptom by Symptom
- 2.6 The Shape in
4-phase.ps1 - Chapter Summary
Chapter 3: The Atomic Instrument
- 3.1 The Instrument, Not the Orchestrator
- 3.2 The Discovery Contract
- 3.3 The Execution Contract
- 3.4 Execution Instruments Are Dumb On Purpose
- 3.5 Why Scalar, Not Iterative
- 3.6 The Naming Convention Is Part of the Contract
- Chapter Summary
- Part II: The Framework Chassis
Chapter 4: The Parameter Gate and the Metadata Block
- 4.1 A Parser-Level Guarantee, Not a Style Convention
- 4.2 Why This Bites Hardest at the Worst Possible Time
- 4.3 No CmdletBinding at the Top: A Deliberate Absence
- 4.4 The Metadata Block: Identity as a First-Class Citizen
- 4.5 Why Metadata Is Not a Parameter
- Chapter Summary
Chapter 5: Transcription as a Forensic Requirement
- 5.1 Two Kinds of Audit Trail
- 5.2 The IntuneManagementExtension\Logs Convention
- 5.3 The %TEMP% Fallback, and What It Actually Costs
- 5.4 Defensive by Necessity: Stop-Transcript Before Start-Transcript
- 5.5 Stop-fpTranscript and the Discipline of a finally Block
- 5.6 $CurrentLogFile: Why a Side Channel Was Never Necessary
- Chapter Summary
Chapter 6: Two Data Contracts, Config and Pipeline
- 6.1 Generated Output, Authored Input
- 6.2 New-fpPipelineObject: A Fixed Skeleton, Not a Growing Object
- 6.3 Get-fpStaticPipeline: Solving a Problem That No Longer Exists
- 6.4 $config: Desired State, Authored by a Human
- 6.5 A First Pass at the Ashfield $config
- Chapter Summary
Chapter 7: The Visual Grammar of the Console
- 7.1 Why Console Output Deserves Its Own Contract
- 7.2 Write-fpConsoleLog: Seven Types, One Grammar
- 7.3 What Actually Survives Into the Transcript
- 7.4 Write-fpObjectToLog: Deconstruction as a Console Convenience
- 7.5 Two Header Functions, Two Jobs
- Chapter Summary
- Part III: Phase 1, Discovery
Chapter 8: The Principle of Passive Interrogation
- 8.1 Read-Only Is Necessary. Passive Is the Actual Standard.
- 8.2 The Temptation to Test by Doing
- 8.3 Facts, Not Opinions: The Boundary Discovery Must Not Cross
- 8.4 Test-Path: An Audit of Every Call Site
- 8.5 What This Buys You When the System Is Actually on Fire
- Chapter Summary
Chapter 9: The Discovery Library, Read One Instrument at a Time
- 9.1 Get-fpService: The Simplest Case
- 9.2 Get-fpRegistryValue: The One That Nearly Broke the Contract
- 9.3 Get-fpFile: The Reference Pattern
- 9.4 Get-fpFileEncoding: Reading Bytes Without Reading the File
- 9.5 Get-fpShortcut: COM in Discovery, and Why That’s Fine Here
- 9.6 Test-fpPathExists: One Instrument, Two Providers
- Chapter Summary
Chapter 10: The Conductor and the Predicate
- 10.1 What a Conductor Actually Does
- 10.2 Which Facts Earn Their Own Instrument
- 10.3 Test-fpIsAdmin: Discovery’s Interrogation, Not Validation’s Verdict
- 10.4 Which Direction Elevation Actually Needs to Run
- 10.5 What Happens When Composition Itself Fails
- 10.6 An Aggregation Idiom Worth Retiring
- Chapter Summary
- Part IV: Phase 2, Validation
Chapter 11: Hard Stops vs Soft Exits
- 11.1 Two Ways For a Run To Stop
- 11.2 Why Elevation Never Gets to Be a Soft Exit
- 11.3 The General Principle, For Checks This Book Has Not Written Yet
- Chapter Summary
Chapter 12: Building Get-fpValidation
- 12.1 What Runs Before Any Check Does
- 12.2 Why a Check Cannot Be Anything but a Predicate
- 12.3 Why the Function Returns a Dictionary, Not Just a Verdict
- Chapter Summary
- Part V: Phase 3, Logic
Chapter 13: The Brain of the Orchestrator
- 13.1 A Different Shape of Comparison
- 13.2 Reading Discovery, Never Re-Asking It
- 13.3 What Logic Decides, and What It Refuses to Touch
- 13.4 An Empty List Is Still a Complete Answer
- 13.5 Why Execution Never Has to Ask
- Chapter Summary
Chapter 14: Constructing the Work Order
- 14.1 The Initialisation That Isn’t Optional
- 14.2 Returning Without Losing the Shape
- 14.3 A Second Guard at the Call Site, and Why It Isn’t the Same Mistake
- 14.4 Reason Exists for a Reader, Not for the Machine
- Chapter Summary
Chapter 15: Case Study, the Ashfield Work Order Matrix
- 15.1 What Discovery Has to Have Gathered First
- 15.2 Extending Ashfield’s Config
- 15.3 Six Requirements, Seven Comparisons, Two Prerequisites
- 15.4 Three Machines, One Function, Zero Code Changes
- Chapter Summary
- Part VI: Phase 4, Execution
Chapter 16: The Task Dispatcher Pattern
- 16.1 The One Loop in the Whole Framework
- 16.2 Why the Switch Lives in the Dispatcher, Not the Instruments
- 16.3 The Default Case Is Not Decoration
- 16.4 The Same Lesson, a Second Time
- 16.5 WhatIf Passes Through, It Doesn’t Originate Here
- Chapter Summary
Chapter 17: Building the Execution Library
- 17.1 The Shape Every Instrument Shares
- 17.2 The Refactor: Start-fpService and Set-fpService
- 17.3 Set-fpRegistryValue: No Exception Needed Anymore
- 17.4 Set-fpIniValue: The Same Simplification, Applied to a File
- 17.5 New-fpRegistryKey and New-fpFileStructure: Where the Exception Went
- 17.6 Remove-fpIniValue: Removal Is Mechanical, Not Judgment
- 17.7 Set-fpShortcut and Set-fpFileEncoding
- Chapter Summary
Chapter 18: WhatIf as a First-Class Citizen
- 18.1 The Automatic Way and the Manual Way
- 18.2 The Automatic Message Doesn’t Speak This Transcript’s Language
- 18.3 Every Instrument Has to Return a Real Result Object, Even in Simulation
- 18.4 Determinism Over Convention
- 18.5 What This Trade Gives Up
- Chapter Summary
Chapter 19: The Result Object and Forensic Capture
- 19.1 Four Fields, Every Time
- 19.2 Why the Contract Doesn’t Need to Say What Was Attempted
- 19.3 Turning a List of Results Into One Verdict
- 19.4 A Gap in the Contract’s Own Enforcement
- 19.5 One Assignment, One Exit
- Chapter Summary
- Part VII: The Ashfield College Scenario, End to End
Chapter 20: Defining the Scenario
- 20.1 A Requirements Document Is Not a Config File
- 20.2 Why Now
- 20.3 The Ashfield Classroom PC: Six Requirements
- 20.4 What This Document Doesn’t Decide
- 20.5 The Complete Config
- Chapter Summary
Chapter 21: Discovery Implementation
- 21.1 Filling the Extension Point
- 21.2 Two Facts, One Node: What IniPolicy Reports
- 21.3 Assembling the Extended Host Object
- 21.4 Extending MAIN’s Reporting Block
- Chapter Summary
Chapter 22: Validation Implementation
- 22.1 Why This Phase Needed No Extension Point
- 22.2 PRE-1: Administrative Context
- 22.3 PRE-2: Available Disk Space
- 22.4 What the Transcript Actually Shows
- Chapter Summary
Chapter 23: Execution and Dispatch
- 23.1 Wiring Logic Into the Template
- 23.2 The Dispatcher Learns Nine New Words
- 23.3 Why Service State No Longer Composes Two Calls Into One
- 23.4 A Dry Run for the Whole Estate
- Chapter Summary
Chapter 24: Reading the Forensics
- 24.1 Two Artifacts, One Underlying Object
- 24.2 A Coarse Status Hides a Story Worth Reading Further
- 24.3 Matching a Result Back to the Item That Staged It
- 24.4 Reading a Run That Never Reached Execution
- Chapter Summary
- Part VIII: Hardening the Framework
Chapter 25: Unit Testing the Framework with Pester
- 25.1 The Tests Appendix E Already Asked For
- 25.2 Mocking
Get-Service: What Discovery Needs That Logic Didn’t - 25.3 Testing the Post-Flight Check: Proving a Lying Cmdlet Gets Caught
- 25.4 What Mocking Can’t Give You
- Chapter Summary
Chapter 26: Extending the Instrument Library
- 26.1 Get-fpFirewallRule: Filling In the Discovery Template
- 26.2 Set-fpFirewallRule: Filling In the Execution Template, and Earning Its Post-Flight Check
- 26.3 A Short Note on Where Discovery Is Allowed to Look
- 26.4 Closing the Loop: What Comes After Writing the Pair
- 26.5 Looking Up What Already Exists
- 26.6 One Dependency Worth Knowing About Before You Test in Isolation
- Chapter Summary
Chapter 27: Anti-Patterns and Common Failures
- 27.1 A Discovery Instrument That Mutates “Just This Once”
- 27.2 A Logic Comparison That Calls
Get-ServiceDirectly - 27.3 An Execution Instrument That Re-Implements Discovery’s Own Check
- 27.4 An Execution Instrument Whose
-WhatIfCheck Arrives Too Late - 27.5 A Pipeline Object Serialised Before
EndTimeIs Set - Chapter Summary
Appendix A: Full Annotated Listing
Appendix B: Atomic Instrument Library Reference
- Discovery Instruments
- Execution Instruments
- The Template’s Own Placeholder
Appendix C: Troubleshooting Guide
- The Transcript Won’t Start
- JSON Serialisation: Slow, Truncated, or Silently Wrong, Not Actually Hanging
- COM Object Leak:
Get-fpShortcut, NotSet-fpShortcut
Appendix D: Pester Test Suite for the Ashfield Scenario
- Logic: All Nine Comparisons
- Discovery: Confirming the $null-on-Absence Contract
- Execution: Happy Path and the WhatIf Short-Circuit
- What This Suite Does and Doesn’t Prove