145 lines
10 KiB
Markdown
145 lines
10 KiB
Markdown
# Channel Wiki: #atea-storm
|
|
_Channel ID: 1531661088209371198_
|
|
_Created: 2026-07-29 12:40 UTC_
|
|
_Last updated: 2026-07-30 09:10 UTC_
|
|
|
|
## Purpose
|
|
|
|
Maintain continuity and an actionable status ledger for all ongoing cooperation, contracts, opportunities, audits, and RFPs involving Atea in Lithuania.
|
|
|
|
When new information arrives, update each workstream with: stage/status, owner(s), Atea contact, customer contact, next action, due date, latest decision, blockers, and source links/files. Do not invent missing details.
|
|
|
|
## Executive Summary
|
|
|
|
Atea cooperation currently spans four workstreams. The **VSSA AWS contract** and **Lietuvos Geležinkeliai RFP** are known active topics, but their scope, owners, dates, and source documents have not yet been captured. The **VSSA DPVP** area includes an identified Phase 2 opportunity across an operator/client portal, migration of backend execution away from GitLab pipelines, VSSA on-premises data-centre onboarding, and complex hybrid services; these are discussion capabilities rather than approved commitments. The **Valstybės duomenų agentūra AWS portal audit** is an active opportunity whose authorization, assets, and formal scope remain unconfirmed. No active security testing may begin without explicit written authorization and agreed scope.
|
|
|
|
Immediate priorities are to identify owners and contacts, collect the contract/RFP/audit source documents and deadlines, qualify and estimate DPVP Phase 2, and establish written audit authorization and boundaries.
|
|
|
|
A consolidated executive summary was first requested on 2026-07-29 and requested again with a direct Hermes mention on 2026-07-30. The standalone Markdown file `atea-storm-overall-executive-summary.md` was generated and delivered in `#atea-storm` on 2026-07-30 at 07:09 UTC; the shorter living summary remains maintained in the **Executive Summary** section of this ledger.
|
|
|
|
## Active Topics
|
|
|
|
### 1. VSSA — AWS contract
|
|
- **Status:** 🔲 Active topic; details not yet captured.
|
|
- **Known:** Contract/workstream involves VSSA, AWS, and Atea.
|
|
- **Need to capture:** scope, contracting parties, procurement stage, value/term, owners, contacts, deadlines, blockers, and documents.
|
|
- **Next action:** Ask for or extract the latest status and source documents when discussed.
|
|
|
|
### 2. VSSA — DPVP contract and Phase 2 opportunity
|
|
- **Status:** ⚠️ Active opportunity; Phase 2 capabilities have been identified for discussion, but scope, delivery model, owners, commercial structure, and dates are not yet agreed.
|
|
- **Acronym:** ✅ Confirmed by RootAtSkic on 2026-07-29 as **DPVP**.
|
|
|
|
#### DPVP Platform — Phase 2 opportunity
|
|
|
|
DPVP Phase 2 is an opportunity to expand the platform across four areas: the operator portal, backend execution, VSSA on-premises onboarding, and complex hybrid services. The scope below contains only the capabilities currently identified for discussion.
|
|
|
|
##### 2.1 DPVP Portal
|
|
|
|
Provide a workspace through which VSSA operators and clients can access and use DPVP services.
|
|
|
|
**Operator-guided services**
|
|
- Guided organisation creation, update, and deletion.
|
|
- Guided project creation, update, and deletion.
|
|
|
|
**Service-request processing**
|
|
- Combine multiple Jira requests into a single DPVP service for processing.
|
|
|
|
**Cloud estate visibility**
|
|
- Provide a close-to-real-time view of the organisation farm within the cloud.
|
|
|
|
**Global configuration**
|
|
- Manage configuration across organisations.
|
|
- Manage Terraform template versions.
|
|
- Manage default tags.
|
|
|
|
**Client access and workspace**
|
|
- Allow VSSA clients to self-register or use their own login method.
|
|
- Provide each client with a workspace.
|
|
- Allow clients to receive cloud-service credentials through HashiCorp tooling.
|
|
|
|
##### 2.2 DPVP Backend
|
|
|
|
Move the execution currently implemented in GitLab pipelines to another technology. Evaluate:
|
|
- a web server; or
|
|
- cloud functions.
|
|
|
|
##### 2.3 VSSA On-Premises Data-Centre Onboarding
|
|
|
|
- Introduce DPVP support for onboarding a VSSA on-premises data centre.
|
|
|
|
##### 2.4 Complex Services
|
|
|
|
Introduce complex DPVP services covering:
|
|
- backup for on-premises workloads and systems;
|
|
- web-application deployment on Kubernetes;
|
|
- cloud-based disaster recovery; and
|
|
- a cloud observability toolkit connected to on-premises environments.
|
|
|
|
**Need to capture next:** opportunity owner, Atea role, customer sponsor, prioritisation, discovery/estimation plan, dependencies, acceptance criteria, commercial/procurement route, target dates, and supporting documents.
|
|
|
|
### 3. Valstybės duomenų agentūra — existing AWS portal audit
|
|
- **Status:** ⚠️ Active audit opportunity; authorization, portal identity, and formal scope are not yet recorded.
|
|
- **Background from channel (2026-07-28):** the agency has, or will soon have, a public portal hosted on AWS infrastructure obtained through VSSA. The channel raised whether an audit should be performed; the audit is now listed as an active topic.
|
|
- **Proposed audit areas (not yet approved scope):**
|
|
- architecture and AWS configuration review;
|
|
- IAM, machine identities, and access paths;
|
|
- public attack surface, DNS, TLS, HTTP security headers, and dependencies;
|
|
- data protection, logging, backup/recovery, and incident management;
|
|
- automated passive scanning.
|
|
- **Safety boundary:** active vulnerability testing or penetration testing requires explicit written authorization and an agreed scope before execution.
|
|
- **Need to capture:** exact portal URL/name, AWS account/landing-zone ownership, audit sponsor, technical contact, written authorization, in/out-of-scope assets, standards/control baseline, evidence access, timeline, and deliverables.
|
|
|
|
### 4. Lietuvos Geležinkeliai — RFP
|
|
- **Status:** 🔲 Active topic; no RFP details captured yet.
|
|
- **Known:** An RFP involving Lietuvos Geležinkeliai and Atea is being tracked.
|
|
- **Need to capture:** official procurement/RFP title and link, contracting entity, scope/lots, submission deadline, clarification deadline, response owner, Atea role, partners, qualification requirements, evaluation criteria, risks, and bid/no-bid decision.
|
|
- **Next action:** Add the RFP document or procurement link as soon as available.
|
|
|
|
## Atea — Verified Context
|
|
|
|
- **Atea, UAB** belongs to the **Atea Baltic** group, managed by **Atea Baltic, UAB**. Atea describes its Lithuanian delivery coverage as end-to-end: needs analysis, solution design, implementation, and ongoing maintenance.
|
|
- Atea says it is the largest IT solutions and services provider in the Baltic states and has more than 700 employees across the Baltics.
|
|
- At group level, Atea describes itself as the Nordic and Baltic market leader in IT infrastructure and related services for businesses and public-sector organizations, with more than 8,000 employees in 88 cities across seven countries, including Lithuania.
|
|
- Public-sector relevance is explicit: Atea Lithuania runs the recurring **Atea Public IT** conference for state-sector leaders. The 2026 event covered public-sector IT effectiveness, security, NIS2, and AI regulation; AWS appeared among the event partners.
|
|
- Atea Lithuania publishes guidance on public cloud for government organizations and explicitly discusses Amazon/AWS alongside Google and Microsoft, shared responsibility, resilience, security, backup, cost, and sustainability.
|
|
- Atea Lithuania states that management systems include ISO 9001, ISO 14001, ISO/IEC 27001, ISO/IEC 20000-1, ISO 37001, and ISO 45001. Exact certificate scope/validity should be checked from certificates before using these as procurement evidence.
|
|
- **Important evidence boundary:** AWS appearing as an Atea event partner and Atea discussing Amazon cloud establish public AWS engagement, but do **not** by themselves prove a specific current AWS Partner Network tier, competency, or certification. Verify any such claim from AWS Partner Finder or formal Atea evidence before using it in a bid.
|
|
|
|
### Sources
|
|
- https://www.atea.lt/apie-atea/
|
|
- https://www.atea.lt/apie-atea/atea-grupes-imones-lietuvoje/
|
|
- https://www.atea.com/who-we-are/
|
|
- https://www.atea.lt/blogas/kuo-viesoji-debesija-svarbi-valstybes-organizacijoms/
|
|
- https://www.atea.lt/renginiai/2026/atea-public-it-kaip-technologijos-tampa-efektyvumo-varikliu/
|
|
- https://www.atea.lt/apie-atea/vadybos-sistemos/
|
|
|
|
## Decisions and Guardrails
|
|
|
|
- ✅ This channel is the continuity hub for ongoing Atea-related topics.
|
|
- ✅ Keep all four workstreams visible even when details are incomplete.
|
|
- ✅ Preserve user-provided terminology while recording likely corrections separately.
|
|
- ✅ Separate verified facts, internal statements, and assumptions.
|
|
- ✅ Never perform active security testing without explicit written authorization and agreed scope.
|
|
|
|
## People & Roles
|
|
|
|
- **RootAtSkic** — initiated the channel tracking request and supplied the current topic list.
|
|
- **Atea/customer owners and contacts** — 🔲 not yet recorded.
|
|
|
|
## Open Action Items
|
|
|
|
- [ ] Capture owner, Atea contact, customer contact, stage, next milestone, and deadlines for each of the four workstreams.
|
|
- [x] Confirm acronym: **VSSA DPVP** — confirmed by RootAtSkic on 2026-07-29.
|
|
- [ ] Define owners, priorities, discovery/estimation plan, dependencies, and commercial route for DPVP Phase 2.
|
|
- [ ] Obtain the Valstybės duomenų agentūra portal URL and written authorization before any active testing.
|
|
- [ ] Obtain the Lietuvos Geležinkeliai RFP/procurement link and deadlines.
|
|
- [ ] Verify Atea's current AWS partner tier/competencies from an authoritative AWS source if required for contracting or the RFP.
|
|
- [x] Provide an overall executive summary in Markdown — standalone file `atea-storm-overall-executive-summary.md` delivered in `#atea-storm` on 2026-07-30 at 07:09 UTC after the request was reiterated; the **Executive Summary** section above remains the living summary.
|
|
|
|
## Channel History Anchor
|
|
|
|
- Latest processed human message: `1532283616321863771` — 2026-07-30 07:08:02 UTC (reiterated the request for an overall executive summary in Markdown as a file, directly mentioning Hermes).
|
|
- Earlier relevant human message: `1532005971805868103` — 2026-07-29 12:44:46 UTC (first requested an overall executive summary in Markdown as a file).
|
|
- Earlier relevant human message: `1532005549879726090` — 2026-07-29 12:43:06 UTC (DPVP Phase 2 opportunity scope).
|
|
- Earlier relevant human message: `1531661589214793738` — 2026-07-28 13:56:19 UTC (Valstybės duomenų agentūra AWS portal audit option).
|