Public/Install-ADCSGoat.ps1

function Install-ADCSGoat {
    <#
    .SYNOPSIS
        Deploys the full ADCSGoat lab by running the four scenario deploys.

    .DESCRIPTION
        Orchestrates the four-scenario design settled in ADCSGoat issue #19 and
        completed in issue #30. Each scenario clones a built-in template,
        applies its recipe and rights, publishes (or deliberately withholds)
        per its design, and records state for teardown:

        - ESC1 Deploy-AGEsc1 — "Copy of Web Server" (Web Server +
                                            Client Auth), Domain Users enroll,
                                            published.
        - ESC4 Deploy-AGEsc4 — "Test SSL" (verbatim Web Server),
                                            Domain Users Full Control,
                                            published.
        - ESC2+SchemaV1 Deploy-AGEsc3Chain — "VMware 6.x" (SubCA clone) +
                                            built-in User published,
                                            Authenticated Users enroll.
        - ESC4+ESC5 Deploy-AGEsc5Chain — "Copy of Workstation" (Workstation
                                            clone), Domain Users Full Control,
                                            NOT published; Authenticated Users
                                            Full Control on the CA object.

        All scenarios target a single selected enterprise CA and write a state
        file used by Uninstall-ADCSGoat for byte-exact teardown.

    .PARAMETER CAName
        The cn of the enterprise CA to target. Optional; autodetected when the
        forest has exactly one enterprise CA.

    .PARAMETER StatePath
        Where the deploy state file lives. Defaults to ADCSGoat.State.xml next
        to the module root.

    .PARAMETER Server
        The domain controller to write to. Defaults to the logon server.

    .PARAMETER Force
        Replaces ADCSGoat-owned existing clones without prompting. Required for
        non-interactive redeploy.

    .EXAMPLE
        Install-ADCSGoat

        Deploys all four scenarios against the forest's single CA.

    .EXAMPLE
        Install-ADCSGoat -CAName 'LabRootCA1' -Force

        Redeploys all four scenarios against the named CA.
    #>

    [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSUseShouldProcessForStateChangingFunctions', '',
        Justification = 'AD writes gated by the per-scenario collision prompt / -Force contract per module precedent.')]
    [CmdletBinding()]
    param (
        [Parameter()]
        [ValidateNotNullOrEmpty()]
        [string]$CAName,

        [Parameter()]
        [ValidateNotNullOrEmpty()]
        [string]$StatePath,

        [Parameter()]
        [ValidateNotNullOrEmpty()]
        [string]$Server,

        [Parameter()]
        [switch]$Force
    )

    begin {
        if ([string]::IsNullOrEmpty($StatePath)) {
            $StatePath = Join-Path -Path $PSScriptRoot -ChildPath '..\ADCSGoat.State.xml'
        }
        $scenarioParams = @{ StatePath = $StatePath }
        if ($PSBoundParameters.ContainsKey('CAName')) { $scenarioParams['CAName'] = $CAName }
        if ($PSBoundParameters.ContainsKey('Server')) { $scenarioParams['Server'] = $Server }
        if ($Force.IsPresent) { $scenarioParams['Force'] = $true }
    }

    process {
        Deploy-AGEsc1 @scenarioParams
        Deploy-AGEsc4 @scenarioParams
        Deploy-AGEsc3Chain @scenarioParams
        Deploy-AGEsc5Chain @scenarioParams
    }
}