10 KiB
Channel Wiki: #atea-storm
Channel ID: 1531661088209371198 Created: 2026-07-29 12:40 UTC Last updated: 2026-07-30 09:10 UTC
Purpose
Maintain continuity and an actionable status ledger for all ongoing cooperation, contracts, opportunities, audits, and RFPs involving Atea in Lithuania.
When new information arrives, update each workstream with: stage/status, owner(s), Atea contact, customer contact, next action, due date, latest decision, blockers, and source links/files. Do not invent missing details.
Executive Summary
Atea cooperation currently spans four workstreams. The VSSA AWS contract and Lietuvos Geležinkeliai RFP are known active topics, but their scope, owners, dates, and source documents have not yet been captured. The VSSA DPVP area includes an identified Phase 2 opportunity across an operator/client portal, migration of backend execution away from GitLab pipelines, VSSA on-premises data-centre onboarding, and complex hybrid services; these are discussion capabilities rather than approved commitments. The Valstybės duomenų agentūra AWS portal audit is an active opportunity whose authorization, assets, and formal scope remain unconfirmed. No active security testing may begin without explicit written authorization and agreed scope.
Immediate priorities are to identify owners and contacts, collect the contract/RFP/audit source documents and deadlines, qualify and estimate DPVP Phase 2, and establish written audit authorization and boundaries.
A consolidated executive summary was first requested on 2026-07-29 and requested again with a direct Hermes mention on 2026-07-30. The standalone Markdown file atea-storm-overall-executive-summary.md was generated and delivered in #atea-storm on 2026-07-30 at 07:09 UTC; the shorter living summary remains maintained in the Executive Summary section of this ledger.
Active Topics
1. VSSA — AWS contract
- Status: 🔲 Active topic; details not yet captured.
- Known: Contract/workstream involves VSSA, AWS, and Atea.
- Need to capture: scope, contracting parties, procurement stage, value/term, owners, contacts, deadlines, blockers, and documents.
- Next action: Ask for or extract the latest status and source documents when discussed.
2. VSSA — DPVP contract and Phase 2 opportunity
- Status: ⚠️ Active opportunity; Phase 2 capabilities have been identified for discussion, but scope, delivery model, owners, commercial structure, and dates are not yet agreed.
- Acronym: ✅ Confirmed by RootAtSkic on 2026-07-29 as DPVP.
DPVP Platform — Phase 2 opportunity
DPVP Phase 2 is an opportunity to expand the platform across four areas: the operator portal, backend execution, VSSA on-premises onboarding, and complex hybrid services. The scope below contains only the capabilities currently identified for discussion.
2.1 DPVP Portal
Provide a workspace through which VSSA operators and clients can access and use DPVP services.
Operator-guided services
- Guided organisation creation, update, and deletion.
- Guided project creation, update, and deletion.
Service-request processing
- Combine multiple Jira requests into a single DPVP service for processing.
Cloud estate visibility
- Provide a close-to-real-time view of the organisation farm within the cloud.
Global configuration
- Manage configuration across organisations.
- Manage Terraform template versions.
- Manage default tags.
Client access and workspace
- Allow VSSA clients to self-register or use their own login method.
- Provide each client with a workspace.
- Allow clients to receive cloud-service credentials through HashiCorp tooling.
2.2 DPVP Backend
Move the execution currently implemented in GitLab pipelines to another technology. Evaluate:
- a web server; or
- cloud functions.
2.3 VSSA On-Premises Data-Centre Onboarding
- Introduce DPVP support for onboarding a VSSA on-premises data centre.
2.4 Complex Services
Introduce complex DPVP services covering:
- backup for on-premises workloads and systems;
- web-application deployment on Kubernetes;
- cloud-based disaster recovery; and
- a cloud observability toolkit connected to on-premises environments.
Need to capture next: opportunity owner, Atea role, customer sponsor, prioritisation, discovery/estimation plan, dependencies, acceptance criteria, commercial/procurement route, target dates, and supporting documents.
3. Valstybės duomenų agentūra — existing AWS portal audit
- Status: ⚠️ Active audit opportunity; authorization, portal identity, and formal scope are not yet recorded.
- Background from channel (2026-07-28): the agency has, or will soon have, a public portal hosted on AWS infrastructure obtained through VSSA. The channel raised whether an audit should be performed; the audit is now listed as an active topic.
- Proposed audit areas (not yet approved scope):
- architecture and AWS configuration review;
- IAM, machine identities, and access paths;
- public attack surface, DNS, TLS, HTTP security headers, and dependencies;
- data protection, logging, backup/recovery, and incident management;
- automated passive scanning.
- Safety boundary: active vulnerability testing or penetration testing requires explicit written authorization and an agreed scope before execution.
- Need to capture: exact portal URL/name, AWS account/landing-zone ownership, audit sponsor, technical contact, written authorization, in/out-of-scope assets, standards/control baseline, evidence access, timeline, and deliverables.
4. Lietuvos Geležinkeliai — RFP
- Status: 🔲 Active topic; no RFP details captured yet.
- Known: An RFP involving Lietuvos Geležinkeliai and Atea is being tracked.
- Need to capture: official procurement/RFP title and link, contracting entity, scope/lots, submission deadline, clarification deadline, response owner, Atea role, partners, qualification requirements, evaluation criteria, risks, and bid/no-bid decision.
- Next action: Add the RFP document or procurement link as soon as available.
Atea — Verified Context
- Atea, UAB belongs to the Atea Baltic group, managed by Atea Baltic, UAB. Atea describes its Lithuanian delivery coverage as end-to-end: needs analysis, solution design, implementation, and ongoing maintenance.
- Atea says it is the largest IT solutions and services provider in the Baltic states and has more than 700 employees across the Baltics.
- At group level, Atea describes itself as the Nordic and Baltic market leader in IT infrastructure and related services for businesses and public-sector organizations, with more than 8,000 employees in 88 cities across seven countries, including Lithuania.
- Public-sector relevance is explicit: Atea Lithuania runs the recurring Atea Public IT conference for state-sector leaders. The 2026 event covered public-sector IT effectiveness, security, NIS2, and AI regulation; AWS appeared among the event partners.
- Atea Lithuania publishes guidance on public cloud for government organizations and explicitly discusses Amazon/AWS alongside Google and Microsoft, shared responsibility, resilience, security, backup, cost, and sustainability.
- Atea Lithuania states that management systems include ISO 9001, ISO 14001, ISO/IEC 27001, ISO/IEC 20000-1, ISO 37001, and ISO 45001. Exact certificate scope/validity should be checked from certificates before using these as procurement evidence.
- Important evidence boundary: AWS appearing as an Atea event partner and Atea discussing Amazon cloud establish public AWS engagement, but do not by themselves prove a specific current AWS Partner Network tier, competency, or certification. Verify any such claim from AWS Partner Finder or formal Atea evidence before using it in a bid.
Sources
- https://www.atea.lt/apie-atea/
- https://www.atea.lt/apie-atea/atea-grupes-imones-lietuvoje/
- https://www.atea.com/who-we-are/
- https://www.atea.lt/blogas/kuo-viesoji-debesija-svarbi-valstybes-organizacijoms/
- https://www.atea.lt/renginiai/2026/atea-public-it-kaip-technologijos-tampa-efektyvumo-varikliu/
- https://www.atea.lt/apie-atea/vadybos-sistemos/
Decisions and Guardrails
- ✅ This channel is the continuity hub for ongoing Atea-related topics.
- ✅ Keep all four workstreams visible even when details are incomplete.
- ✅ Preserve user-provided terminology while recording likely corrections separately.
- ✅ Separate verified facts, internal statements, and assumptions.
- ✅ Never perform active security testing without explicit written authorization and agreed scope.
People & Roles
- RootAtSkic — initiated the channel tracking request and supplied the current topic list.
- Atea/customer owners and contacts — 🔲 not yet recorded.
Open Action Items
- Capture owner, Atea contact, customer contact, stage, next milestone, and deadlines for each of the four workstreams.
- Confirm acronym: VSSA DPVP — confirmed by RootAtSkic on 2026-07-29.
- Define owners, priorities, discovery/estimation plan, dependencies, and commercial route for DPVP Phase 2.
- Obtain the Valstybės duomenų agentūra portal URL and written authorization before any active testing.
- Obtain the Lietuvos Geležinkeliai RFP/procurement link and deadlines.
- Verify Atea's current AWS partner tier/competencies from an authoritative AWS source if required for contracting or the RFP.
- Provide an overall executive summary in Markdown — standalone file
atea-storm-overall-executive-summary.mddelivered in#atea-stormon 2026-07-30 at 07:09 UTC after the request was reiterated; the Executive Summary section above remains the living summary.
Channel History Anchor
- Latest processed human message:
1532283616321863771— 2026-07-30 07:08:02 UTC (reiterated the request for an overall executive summary in Markdown as a file, directly mentioning Hermes). - Earlier relevant human message:
1532005971805868103— 2026-07-29 12:44:46 UTC (first requested an overall executive summary in Markdown as a file). - Earlier relevant human message:
1532005549879726090— 2026-07-29 12:43:06 UTC (DPVP Phase 2 opportunity scope). - Earlier relevant human message:
1531661589214793738— 2026-07-28 13:56:19 UTC (Valstybės duomenų agentūra AWS portal audit option).