Skip to content

Document unguaranteed platform assumptions - #19

Merged
vartaxe merged 1 commit into
mainfrom
docs-platform-assumptions
Oct 6, 2026
Merged

vartaxe merged 1 commit into
mainfrom
docs-platform-assumptions

Conversation

@vartaxe

@vartaxe vartaxe commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Summary

Two platform behaviors the script relies on are conventional and widely observed, but are not stated as guarantees in Microsoft's published documentation. They were previously implicit:

  1. A System.DirectoryServices.Protocols Kerberos bind uses the supplied NetworkCredential (derived from -Credential) rather than the calling thread identity. Under OSD the thread identity is Local System, so if this did not hold, results would be attributable to the computer account instead of the supplied account.
  2. System.DirectoryServices.ActiveDirectory.DirectoryServer.Name returns a fully qualified name. The LDAP/<fqdn> service principal name and LDAPS certificate matching both depend on this.

Changes (documentation only):

  • docs/compatibility.md — new ## Environment-validated assumptions section describing both assumptions, why each matters, and how to confirm them in your own environment, with a cross-link to the validation checklist.
  • docs/validation.md — two rows appended to the ## Required live tests table, both with status Not executed.
  • CHECKSUMS.txt — regenerated using the snippet in docs/release-process.md (two hash lines updated).

No change to Scripts/Add-ComputerToADGroup.ps1, workflows, manifests, or version. Published v1.0.0 release assets remain byte-identical.

Validation

  • build\Invoke-Validation.ps1 passes on Windows PowerShell 5.1
  • PSScriptAnalyzer returns no findings
  • Pester 5.7.1 discovery and tests pass
  • Full validation runs without -SkipChecksums; manifest matches worktree and candidate git archive
  • Live results are recorded separately, with untested scenarios explicitly pending
  • Documentation updated if behavior changed
  • No credentials, internal values, or sensitive logs included

Command run on Windows PowerShell 5.1 after the edits:

.\build\Invoke-Validation.ps1

Result: Tests Passed: 227, Failed: 0, Skipped: 0, Inconclusive: 0, NotRun: 0 — SHA-256 manifest verified against exact source bytes. — Validation passed. (exit code 0, 359.86s).

The same gate was also run against the published v1.0.0 release ZIP after verifying its SHA-256 against both the .sha256 sidecar and GitHub's published asset digest: 227/227 passed.

No live Active Directory or ConfigMgr task sequence testing was executed. Both new assumptions are recorded in docs/validation.md as Not executed, consistent with the rest of that checklist.

Two behaviors the script depends on are conventional and widely observed
but are not stated as guarantees in Microsoft published documentation:

- A System.DirectoryServices.Protocols Kerberos bind uses the supplied
  NetworkCredential derived from -Credential rather than the calling
  thread identity.
- System.DirectoryServices.ActiveDirectory.DirectoryServer.Name returns a
  fully qualified name, which the LDAP SPN and LDAPS certificate matching
  rely on.

Add an Environment-validated assumptions section to docs/compatibility.md
explaining both and how to confirm them, and add matching Not executed
rows to the required live tests table in docs/validation.md. Regenerate
CHECKSUMS.txt. Documentation only; no script or workflow changes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 19:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@vartaxe
vartaxe merged commit 035ce5e into main Oct 6, 2026
5 checks passed
@vartaxe
vartaxe deleted the docs-platform-assumptions branch October 6, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants