Files
knowledge-wiki/workstreams/vssa-dpvp.md
T

5.1 KiB

VSSA — DPVP Action Plan

🔵 Workstream: Digital Platform Value Proposition

Active Items

ID Item Status Added
ACT-05 Introduce new groups/roles for financial monitoring (VSSA + non-VSSA) 🔵 Active 2026-07-14
ACT-06 Monitoring & pushing of Azure costs data export 🔵 Active 2026-07-14
ACT-09 Versioning strategy 🔵 Active 2026-07-14
ACT-10 Julius: locate the documentation for the nightly scheduled job that enables AWS cost allocation tags 🔵 Active 2026-07-14
ACT-11 Custom domain creation on Azure tenants 🔵 Active 2026-07-15
ACT-12 AWS Identity architecture: all VSSA users needing AWS Orgs access → records in main VSSA tenant IDC + federation to member accounts 🔵 Active 2026-07-15
ACT-13 Release 0.1.0.0 → testing results — GCP start feeling 🔵 Active 2026-07-24
ACT-14 Organize scanning of AWS organization — spun up using DPVP, then scanned by Atea 🔵 Active 2026-07-27
ACT-15 DPVP Platform Phase 2 opportunity — scope, prioritise, estimate, and define delivery/commercial approach 🟡 Opportunity 2026-07-29
ACT-16 Make merge-request approvals mandatory in the staging environment 🔵 Active 2026-07-29
ACT-18 Review and update DPVP documentation together with VSSA stakeholders 🔵 Active 2026-08-19
ACT-19 Security: define how to remove or limit cloud access for existing users 🔵 Active 2026-08-19
ACT-20 Define how DPVP user access is monitored and audited 🔵 Active 2026-08-19
ACT-21 Define DPVP roles and permissions, with Jira as the target for granting and revoking access 🔵 Active 2026-08-19
ACT-24 Document the approach for onboarding Azure cost data into Apptio 🔵 Active 2026-08-25
ACT-25 Evaluate unit testing options 🔵 Active 2026-08-26
ACT-26 Review cloud roles during the VSSA DPVP Architects call discussion 🔵 Active 2026-09-03

DPVP Platform — Phase 2 Opportunity

Executive Summary

DPVP Phase 2 is an opportunity to expand the platform across five areas: the operator portal, backend execution, VSSA on-premises onboarding, complex hybrid services, and multi-cloud organization scanning.

The proposed scope below contains only the capabilities currently identified for discussion.

1. DPVP Portal

Provide a workspace through which VSSA operators and clients can access and use DPVP services.

Operator-guided services

  • Guided organisation creation, update, and deletion.
  • Guided project creation, update, and deletion.

Service-request processing

  • Combine multiple Jira requests into a single DPVP service for processing.

Cloud estate visibility

  • Provide a close-to-real-time view of the organisation farm within the cloud.

Global configuration

  • Manage configuration across organisations.
  • Manage Terraform template versions.
  • Manage default tags.

Client access and workspace

  • Allow VSSA clients to self-register or use their own login method.
  • Provide each client with a workspace.
  • Allow clients to receive cloud-service credentials through HashiCorp tooling.

2. DPVP Backend

Move the execution currently implemented in GitLab pipelines to another technology, with the target approach to be evaluated between:

  • a web server; or
  • cloud functions.

3. VSSA On-Premises Data-Centre Onboarding

Introduce DPVP support for onboarding a VSSA on-premises data centre.

4. Complex Services

Introduce complex DPVP services covering:

  • backup for on-premises workloads and systems;
  • web-application deployment on Kubernetes;
  • cloud-based disaster recovery; and
  • a cloud observability toolkit connected to on-premises environments.

5. Multi-Cloud Organization Scanning Service

Introduce an organization scanning service covering:

  • Amazon Web Services (AWS);
  • Microsoft Azure; and
  • Google Cloud Platform (GCP).

The scan types, security/compliance baselines, authorization and access model, reporting, remediation workflow, execution frequency, and acceptance criteria remain to be defined. This is proposed Phase 2 scope, not an approved testing authorization.

Opportunity Qualification — Open

  • Confirm opportunity owner and Atea/VSSA stakeholders.
  • Prioritise capabilities and define Phase 2 boundaries.
  • Run technical discovery and produce estimates.
  • Define dependencies, acceptance criteria, and target dates.
  • Select/evaluate backend execution approach: web server or cloud functions.
  • Define the delivery and commercial/procurement approach.
  • Define authorized assets, scan types/baselines, access, reporting, remediation workflow, frequency, and acceptance criteria for the AWS/Azure/GCP organization scanning service.

Completed

ID Item Completed
DONE-01 Deploy env variables to production 2026-07-15
DONE-02 Apptio: investigate why AWS account connection was lost 2026-08-25
DONE-03 Apptio: onboard Azure costs data 2026-08-25

Notes

  • Julius Sulcas was on time off — follow up when back