wiki: sync 2026-07-30 13:16 UTC — 5 file(s) updated

This commit is contained in:
2026-07-30 13:16:58 +00:00
parent 5a5ca7f137
commit c9e3c5d5fd
5 changed files with 69 additions and 16 deletions
+36 -9
View File
@@ -1,7 +1,7 @@
# Channel Wiki: #atea-storm
_Channel ID: 1531661088209371198_
_Created: 2026-07-29 12:40 UTC_
_Last updated: 2026-07-30 09:10 UTC_
_Last updated: 2026-07-30 13:14 UTC_
## Purpose
@@ -11,9 +11,9 @@ When new information arrives, update each workstream with: stage/status, owner(s
## Executive Summary
Atea cooperation currently spans four workstreams. The **VSSA AWS contract** and **Lietuvos Geležinkeliai RFP** are known active topics, but their scope, owners, dates, and source documents have not yet been captured. The **VSSA DPVP** area includes an identified Phase 2 opportunity across an operator/client portal, migration of backend execution away from GitLab pipelines, VSSA on-premises data-centre onboarding, and complex hybrid services; these are discussion capabilities rather than approved commitments. The **Valstybės duomenų agentūra AWS portal audit** is an active opportunity whose authorization, assets, and formal scope remain unconfirmed. No active security testing may begin without explicit written authorization and agreed scope.
Atea cooperation currently spans four established workstreams plus two newly named, early Atea & IBM items. The **VSSA AWS contract** is a known active topic with a proposed AWS Well-Architected Framework review, while the **Lietuvos Geležinkeliai RFP** is also active; both still lack complete scope, owners, dates, and source documents. The **VSSA DPVP** area includes an identified Phase 2 opportunity across an operator/client portal, migration of backend execution away from GitLab pipelines, VSSA on-premises data-centre onboarding, complex hybrid services, and multi-cloud organization scanning across AWS, Azure, and GCP; these are discussion capabilities rather than approved commitments. A separate DPVP follow-up is to check with Atea about role assumption for TFE OIDC setup. The **Valstybės duomenų agentūra AWS portal audit** is an active opportunity whose authorization, assets, and formal scope remain unconfirmed. The new **Atea & IBM** items are currently known only by the user-provided titles “Let's go to institutions” and **Government Developer Portal**; customer, scope, owners, dates, and relationship to existing workstreams are not yet confirmed. No active security testing may begin without explicit written authorization and agreed scope.
Immediate priorities are to identify owners and contacts, collect the contract/RFP/audit source documents and deadlines, qualify and estimate DPVP Phase 2, and establish written audit authorization and boundaries.
Immediate priorities are to identify owners and contacts, collect the contract/RFP/audit source documents and deadlines, qualify and estimate DPVP Phase 2, clarify the TFE OIDC role-assumption requirement, qualify the two Atea & IBM items, and establish written audit authorization and boundaries.
A consolidated executive summary was first requested on 2026-07-29 and requested again with a direct Hermes mention on 2026-07-30. The standalone Markdown file `atea-storm-overall-executive-summary.md` was generated and delivered in `#atea-storm` on 2026-07-30 at 07:09 UTC; the shorter living summary remains maintained in the **Executive Summary** section of this ledger.
@@ -22,8 +22,11 @@ A consolidated executive summary was first requested on 2026-07-29 and requested
### 1. VSSA — AWS contract
- **Status:** 🔲 Active topic; details not yet captured.
- **Known:** Contract/workstream involves VSSA, AWS, and Atea.
- **Need to capture:** scope, contracting parties, procurement stage, value/term, owners, contacts, deadlines, blockers, and documents.
- **Next action:** Ask for or extract the latest status and source documents when discussed.
- **Proposed audit action:** Run a review of the VSSA AWS workload using the **AWS Well-Architected Framework**, covering Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability.
- **Decision status:** Proposal only; approval, authorization, workload/account scope, access, participants, schedule, evidence, reporting, and remediation ownership are not yet confirmed.
- **Need to capture:** scope, contracting parties, procurement stage, value/term, owners, contacts, deadlines, blockers, documents, and whether findings will be recorded through the AWS Well-Architected Tool.
- **Next action:** Obtain the latest contract/status documents and agree the sponsor, authorization, and scope for the proposed AWS Well-Architected Review.
- **Framework reference:** https://docs.aws.amazon.com/wellarchitected/latest/framework/the-pillars-of-the-framework.html
### 2. VSSA — DPVP contract and Phase 2 opportunity
- **Status:** ⚠️ Active opportunity; Phase 2 capabilities have been identified for discussion, but scope, delivery model, owners, commercial structure, and dates are not yet agreed.
@@ -31,7 +34,7 @@ A consolidated executive summary was first requested on 2026-07-29 and requested
#### DPVP Platform — Phase 2 opportunity
DPVP Phase 2 is an opportunity to expand the platform across four areas: the operator portal, backend execution, VSSA on-premises onboarding, and complex hybrid services. The scope below contains only the capabilities currently identified for discussion.
DPVP Phase 2 is an opportunity to expand the platform across five areas: the operator portal, backend execution, VSSA on-premises onboarding, complex hybrid services, and multi-cloud organization scanning. The scope below contains only the capabilities currently identified for discussion.
##### 2.1 DPVP Portal
@@ -75,8 +78,19 @@ Introduce complex DPVP services covering:
- cloud-based disaster recovery; and
- a cloud observability toolkit connected to on-premises environments.
##### 2.5 Multi-Cloud Organization Scanning Service
Introduce a DPVP scanning service for organizations operating across:
- Amazon Web Services (AWS);
- Microsoft Azure; and
- Google Cloud Platform (GCP).
The scan types, security and compliance baselines, access model, reporting, remediation workflow, execution frequency, and acceptance criteria remain to be defined.
**Need to capture next:** opportunity owner, Atea role, customer sponsor, prioritisation, discovery/estimation plan, dependencies, acceptance criteria, commercial/procurement route, target dates, and supporting documents.
**Additional DPVP/Atea follow-up (2026-07-30):** Check with Atea about role assumption for the TFE OIDC setup. The intended identity/role, account/environment, owner, exact configuration task, deadline, and dependencies are not yet recorded.
### 3. Valstybės duomenų agentūra — existing AWS portal audit
- **Status:** ⚠️ Active audit opportunity; authorization, portal identity, and formal scope are not yet recorded.
- **Background from channel (2026-07-28):** the agency has, or will soon have, a public portal hosted on AWS infrastructure obtained through VSSA. The channel raised whether an audit should be performed; the audit is now listed as an active topic.
@@ -95,6 +109,12 @@ Introduce complex DPVP services covering:
- **Need to capture:** official procurement/RFP title and link, contracting entity, scope/lots, submission deadline, clarification deadline, response owner, Atea role, partners, qualification requirements, evaluation criteria, risks, and bid/no-bid decision.
- **Next action:** Add the RFP document or procurement link as soon as available.
### 5. Atea & IBM — early opportunity items
- **Status:** 🔲 Two newly named backlog/opportunity items; details not yet captured.
- **User-provided titles:** “Let's go to institutions” and **Government Developer Portal**.
- **Evidence boundary:** The messages establish only the titles and Atea/IBM association. They do not yet establish a customer, sponsor, scope, procurement route, commitment, owner, deadline, or relationship to the existing VSSA Government Developers Platform idea.
- **Next action:** Qualify each item separately and capture objective, target institutions/customer, owner, contacts, scope, stage, next milestone, dates, blockers, and source documents.
## Atea — Verified Context
- **Atea, UAB** belongs to the **Atea Baltic** group, managed by **Atea Baltic, UAB**. Atea describes its Lithuanian delivery coverage as end-to-end: needs analysis, solution design, implementation, and ongoing maintenance.
@@ -116,7 +136,7 @@ Introduce complex DPVP services covering:
## Decisions and Guardrails
- ✅ This channel is the continuity hub for ongoing Atea-related topics.
- ✅ Keep all four workstreams visible even when details are incomplete.
- ✅ Keep all established and newly named workstreams/items visible even when details are incomplete.
- ✅ Preserve user-provided terminology while recording likely corrections separately.
- ✅ Separate verified facts, internal statements, and assumptions.
- ✅ Never perform active security testing without explicit written authorization and agreed scope.
@@ -128,17 +148,24 @@ Introduce complex DPVP services covering:
## Open Action Items
- [ ] Capture owner, Atea contact, customer contact, stage, next milestone, and deadlines for each of the four workstreams.
- [ ] Capture owner, Atea contact, customer contact, stage, next milestone, and deadlines for each tracked workstream/item.
- [x] Confirm acronym: **VSSA DPVP** — confirmed by RootAtSkic on 2026-07-29.
- [ ] Define owners, priorities, discovery/estimation plan, dependencies, and commercial route for DPVP Phase 2.
- [ ] Obtain the Valstybės duomenų agentūra portal URL and written authorization before any active testing.
- [ ] Obtain the Lietuvos Geležinkeliai RFP/procurement link and deadlines.
- [ ] Verify Atea's current AWS partner tier/competencies from an authoritative AWS source if required for contracting or the RFP.
- [ ] Check with Atea about role assumption for the TFE OIDC setup; capture the intended role/account, owner, scope, and deadline.
- [ ] Qualify the Atea & IBM “Let's go to institutions” and Government Developer Portal items without assuming scope or customer.
- [x] Provide an overall executive summary in Markdown — standalone file `atea-storm-overall-executive-summary.md` delivered in `#atea-storm` on 2026-07-30 at 07:09 UTC after the request was reiterated; the **Executive Summary** section above remains the living summary.
## Channel History Anchor
- Latest processed human message: `1532283616321863771` — 2026-07-30 07:08:02 UTC (reiterated the request for an overall executive summary in Markdown as a file, directly mentioning Hermes).
- Latest processed human message: `1532359647435165829` — 2026-07-30 12:10:09 UTC (proposed a VSSA AWS audit action using the AWS Well-Architected Framework).
- Earlier relevant human message: `1532359246316834896` — 2026-07-30 12:08:34 UTC (added AWS/Azure/GCP organization scanning service to DPVP Phase 2).
- Cross-channel source: `#lego-planner-v1` message at 2026-07-30 12:53:52 UTC — Atea & IBM Government Developer Portal item.
- Cross-channel source: `#lego-planner-v1` message at 2026-07-30 12:23:09 UTC — Atea & IBM “Let's go to institutions” item.
- Cross-channel source: `#lego-planner-v1` message at 2026-07-30 09:52:57 UTC — check with Atea about role assumption for TFE OIDC setup.
- Earlier relevant human message: `1532283616321863771` — 2026-07-30 07:08:02 UTC (reiterated the request for an overall executive summary in Markdown as a file, directly mentioning Hermes).
- Earlier relevant human message: `1532005971805868103` — 2026-07-29 12:44:46 UTC (first requested an overall executive summary in Markdown as a file).
- Earlier relevant human message: `1532005549879726090` — 2026-07-29 12:43:06 UTC (DPVP Phase 2 opportunity scope).
- Earlier relevant human message: `1531661589214793738` — 2026-07-28 13:56:19 UTC (Valstybės duomenų agentūra AWS portal audit option).