5.4 KiB
VSSA — DPVP Action Plan
🔵 Workstream: Digital Platform Value Proposition
Active Items
| ID | Item | Status | Added |
|---|---|---|---|
| ACT-01 | Apptio: investigate why AWS account connection was lost | 🔵 Active | 2026-07-14 |
| ACT-02 | Apptio: onboard Azure costs data | 🔵 Active | 2026-07-14 |
| ACT-03 | Review cost estimations for July | 🔵 Active | 2026-07-14 |
| ACT-04 | Check tags/labels coming in correctly; add additional tag for Atea | 🔵 Active | 2026-07-14 |
| ACT-05 | Introduce new groups/roles for financial monitoring (VSSA + non-VSSA) | 🔵 Active | 2026-07-14 |
| ACT-06 | Monitoring & pushing of Azure costs data export | 🔵 Active | 2026-07-14 |
| ACT-07 | Check documentation progress with Algirdas | 🔵 Active | 2026-07-14 |
| ACT-08 | Organize new cloud orgs for staging/testing | 🔵 Active | 2026-07-14 |
| ACT-09 | Versioning strategy | 🔵 Active | 2026-07-14 |
| ACT-10 | Follow up with Julius Sulcas re: scheduled pipeline & AWS Orgs cost allocation tags | ⏳ Waiting | 2026-07-14 |
| ACT-11 | Custom domain creation on Azure tenants | 🔵 Active | 2026-07-15 |
| ACT-12 | AWS Identity architecture: all VSSA users needing AWS Orgs access → records in main VSSA tenant IDC + federation to member accounts | 🔵 Active | 2026-07-15 |
| ACT-13 | Release 0.1.0.0 → testing results — GCP start feeling | 🔵 Active | 2026-07-24 |
| ACT-14 | Organize scanning of AWS organization — spun up using DPVP, then scanned by Atea | 🔵 Active | 2026-07-27 |
| ACT-15 | DPVP Platform Phase 2 opportunity — scope, prioritise, estimate, and define delivery/commercial approach | 🟡 Opportunity | 2026-07-29 |
| ACT-16 | Make merge-request approvals mandatory in the staging environment | 🔵 Active | 2026-07-29 |
| ACT-17 | Check with Atea about role assumption for TFE OIDC setup | 🔵 Active | 2026-07-30 |
| ACT-18 | Review and update DPVP documentation together with VSSA stakeholders | 🔵 Active | 2026-08-19 |
| ACT-19 | Security: define how to remove or limit cloud access for existing users | 🔵 Active | 2026-08-19 |
| ACT-20 | Define how DPVP user access is monitored and audited | 🔵 Active | 2026-08-19 |
| ACT-21 | Define DPVP roles and permissions, with Jira as the target for granting and revoking access | 🔵 Active | 2026-08-19 |
| ACT-22 | Backup concept: organize backups at the project level | 🔵 Active | 2026-08-19 |
| ACT-23 | Define the DPVP Architecture Decision process | 🔵 Active | 2026-08-19 |
DPVP Platform — Phase 2 Opportunity
Executive Summary
DPVP Phase 2 is an opportunity to expand the platform across five areas: the operator portal, backend execution, VSSA on-premises onboarding, complex hybrid services, and multi-cloud organization scanning.
The proposed scope below contains only the capabilities currently identified for discussion.
1. DPVP Portal
Provide a workspace through which VSSA operators and clients can access and use DPVP services.
Operator-guided services
- Guided organisation creation, update, and deletion.
- Guided project creation, update, and deletion.
Service-request processing
- Combine multiple Jira requests into a single DPVP service for processing.
Cloud estate visibility
- Provide a close-to-real-time view of the organisation farm within the cloud.
Global configuration
- Manage configuration across organisations.
- Manage Terraform template versions.
- Manage default tags.
Client access and workspace
- Allow VSSA clients to self-register or use their own login method.
- Provide each client with a workspace.
- Allow clients to receive cloud-service credentials through HashiCorp tooling.
2. DPVP Backend
Move the execution currently implemented in GitLab pipelines to another technology, with the target approach to be evaluated between:
- a web server; or
- cloud functions.
3. VSSA On-Premises Data-Centre Onboarding
Introduce DPVP support for onboarding a VSSA on-premises data centre.
4. Complex Services
Introduce complex DPVP services covering:
- backup for on-premises workloads and systems;
- web-application deployment on Kubernetes;
- cloud-based disaster recovery; and
- a cloud observability toolkit connected to on-premises environments.
5. Multi-Cloud Organization Scanning Service
Introduce an organization scanning service covering:
- Amazon Web Services (AWS);
- Microsoft Azure; and
- Google Cloud Platform (GCP).
The scan types, security/compliance baselines, authorization and access model, reporting, remediation workflow, execution frequency, and acceptance criteria remain to be defined. This is proposed Phase 2 scope, not an approved testing authorization.
Opportunity Qualification — Open
- Confirm opportunity owner and Atea/VSSA stakeholders.
- Prioritise capabilities and define Phase 2 boundaries.
- Run technical discovery and produce estimates.
- Define dependencies, acceptance criteria, and target dates.
- Select/evaluate backend execution approach: web server or cloud functions.
- Define the delivery and commercial/procurement approach.
- Define authorized assets, scan types/baselines, access, reporting, remediation workflow, frequency, and acceptance criteria for the AWS/Azure/GCP organization scanning service.
Completed
| ID | Item | Completed |
|---|---|---|
| DONE-01 | Deploy env variables to production | 2026-07-15 |
Notes
- Julius Sulcas was on time off — follow up when back