/os-platform
Define and execute operating system baseline, hardening, and patching workflows with verif.
Define and execute operating system baseline, hardening, and patching workflows with verifiable platform health controls.
Category
Infrastructure
Execution
7 steps, sequential + gated
Goal
Define and execute operating system baseline, hardening, and patching workflows with verifiable platform health controls.
Scope
Applies to
- +Run OS hardening workflow
- +Plan server patching and validation
- +Audit platform baseline
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Run OS hardening workflow""Plan server patching and validation""Audit platform baseline""Create OS operations contract"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Baseline and target state must be explicit before changes.
- 02Patching and hardening changes require service impact assessment.
- 03Verification must include service status, resource health, and security posture checks.
- 04Recovery path must be defined for failed patch or hardening step.
Procedure
- Step 1Step 1 — Capture current baseline (packages, kernel/OS version, services, security controls).
- Step 2Step 2 — Define hardening or patch set with expected service impact.
- Step 3Step 3 — Run pre-change checks (service health, disk/memory headroom, backup/recovery readiness).
- Step 4Step 4 — Apply patching/hardening actions in controlled steps.
- Step 5Step 5 — Run post-change checks (service status, boot/runtime health, security scan delta).
- Step 6Step 6 — Trigger recovery/rollback path if verification fails.
- Step 7Step 7 — Publish platform handoff report with residual risk and follow-up actions.
Outputs
- ▸OS baseline delta report.
- ▸Patching/hardening execution log.
- ▸Post-change service and security verification evidence.
- ▸Recovery/rollback status note.
Review Gate
- [ ]Baseline and target state are documented.
- [ ]Service impact and maintenance window are explicit.
- [ ]Post-change health and security checks pass.
- [ ]Recovery/rollback instructions are actionable.