# VSSA — DPVP Action Plan 🔵 Workstream: Digital Platform Value Proposition ## Active Items | ID | Item | Status | Added | |----|------|--------|-------| | ACT-05 | Introduce new groups/roles for financial monitoring (VSSA + non-VSSA) | 🔵 Active | 2026-07-14 | | ACT-06 | Monitoring & pushing of Azure costs data export | 🔵 Active | 2026-07-14 | | ACT-09 | Versioning strategy | 🔵 Active | 2026-07-14 | | ACT-10 | Julius: locate the documentation for the nightly scheduled job that enables AWS cost allocation tags | 🔵 Active | 2026-07-14 | | ACT-11 | Custom domain creation on Azure tenants | 🔵 Active | 2026-07-15 | | ACT-12 | AWS Identity architecture: all VSSA users needing AWS Orgs access → records in main VSSA tenant IDC + federation to member accounts | 🔵 Active | 2026-07-15 | | ACT-13 | Release 0.1.0.0 → testing results — GCP start feeling | 🔵 Active | 2026-07-24 | | ACT-14 | Organize scanning of AWS organization — spun up using DPVP, then scanned by Atea | 🔵 Active | 2026-07-27 | | ACT-15 | DPVP Platform Phase 2 opportunity — scope, prioritise, estimate, and define delivery/commercial approach | 🟡 Opportunity | 2026-07-29 | | ACT-16 | Make merge-request approvals mandatory in the staging environment | 🔵 Active | 2026-07-29 | | ACT-18 | Review and update DPVP documentation together with VSSA stakeholders | 🔵 Active | 2026-08-19 | | ACT-19 | Security: define how to remove or limit cloud access for existing users | 🔵 Active | 2026-08-19 | | ACT-20 | Define how DPVP user access is monitored and audited | 🔵 Active | 2026-08-19 | | ACT-21 | Define DPVP roles and permissions, with Jira as the target for granting and revoking access | 🔵 Active | 2026-08-19 | | ACT-24 | Document the approach for onboarding Azure cost data into Apptio | 🔵 Active | 2026-08-25 | | ACT-25 | Evaluate unit testing options | 🔵 Active | 2026-08-26 | | ACT-26 | Review cloud roles during the VSSA DPVP Architects call discussion | 🔵 Active | 2026-09-03 | ## DPVP Platform — Phase 2 Opportunity ### Executive Summary DPVP Phase 2 is an opportunity to expand the platform across five areas: the operator portal, backend execution, VSSA on-premises onboarding, complex hybrid services, and multi-cloud organization scanning. The proposed scope below contains only the capabilities currently identified for discussion. ### 1. DPVP Portal Provide a workspace through which VSSA operators and clients can access and use DPVP services. #### Operator-guided services - Guided organisation creation, update, and deletion. - Guided project creation, update, and deletion. #### Service-request processing - Combine multiple Jira requests into a single DPVP service for processing. #### Cloud estate visibility - Provide a close-to-real-time view of the organisation farm within the cloud. #### Global configuration - Manage configuration across organisations. - Manage Terraform template versions. - Manage default tags. #### Client access and workspace - Allow VSSA clients to self-register or use their own login method. - Provide each client with a workspace. - Allow clients to receive cloud-service credentials through HashiCorp tooling. ### 2. DPVP Backend Move the execution currently implemented in GitLab pipelines to another technology, with the target approach to be evaluated between: - a web server; or - cloud functions. ### 3. VSSA On-Premises Data-Centre Onboarding Introduce DPVP support for onboarding a VSSA on-premises data centre. ### 4. Complex Services Introduce complex DPVP services covering: - backup for on-premises workloads and systems; - web-application deployment on Kubernetes; - cloud-based disaster recovery; and - a cloud observability toolkit connected to on-premises environments. ### 5. Multi-Cloud Organization Scanning Service Introduce an organization scanning service covering: - Amazon Web Services (AWS); - Microsoft Azure; and - Google Cloud Platform (GCP). The scan types, security/compliance baselines, authorization and access model, reporting, remediation workflow, execution frequency, and acceptance criteria remain to be defined. This is proposed Phase 2 scope, not an approved testing authorization. ### Opportunity Qualification — Open - [ ] Confirm opportunity owner and Atea/VSSA stakeholders. - [ ] Prioritise capabilities and define Phase 2 boundaries. - [ ] Run technical discovery and produce estimates. - [ ] Define dependencies, acceptance criteria, and target dates. - [ ] Select/evaluate backend execution approach: web server or cloud functions. - [ ] Define the delivery and commercial/procurement approach. - [ ] Define authorized assets, scan types/baselines, access, reporting, remediation workflow, frequency, and acceptance criteria for the AWS/Azure/GCP organization scanning service. ## Completed | ID | Item | Completed | |----|------|-----------| | DONE-01 | Deploy env variables to production | 2026-07-15 | | DONE-02 | Apptio: investigate why AWS account connection was lost | 2026-08-25 | | DONE-03 | Apptio: onboard Azure costs data | 2026-08-25 | ## Notes - Julius Sulcas was on time off — follow up when back