Open Items Index
Tracker for gaps and follow-ups surfaced while writing the Region Deployment docs. For progress/status on any item, follow the linked issue rather than this page — this index just points at where the tracking actually lives.
| Item | Tracking issue |
|---|---|
Keycloak realm rename (cogrion), M365 SMTP, Entra master-realm login, stale region-deployment docs | sparqd/project-management#276 |
| Secrets Manager naming convention + untracked/missing secrets | sparqd/project-management#277 |
— IaC side (naming, rds.tf reorg, secret shells) | cogrion-terraform#78 |
| — OpenBao SaaS admin token bootstrap Job + CronJob | cogrion-gitops#7 |
| CI buildspec writes cplane chart tag bumps to a dead legacy gitops repo | sparqd/project-management#275 |
gitops layout restructure (closed — historical record of the pre-d555d0b vs. current layout) | cogrion-gitops#6 |
Cross-account automation hub migration off legacy 558824711273 — SCP tightening for new cogrion-automation-hub (803283180859) | sparqd/project-management#361 |
cplane-ui-prod-sgp pipeline branch/env/secret-name fixes | cogrion-terraform#120 |
cogrion-codebuild's Cloudflare API token access (identity + resource policy) — resource-policy half still pending main merge + apply | cogrion-terraform#121 |
| Private-subnet NACL ephemeral-port range breaks NAT-routed egress (ArgoCD git timeouts) | sparqd/project-management#1114 |
Enable ArgoCD metrics + alerts, alerts/ collection convention in cogrion-gitops | sparqd/project-management#1115 |
| Repro/verification test for NAT SNAT port vs. NACL mismatch | sparqd/project-management#1116 |
| Enable VPC Flow Logs (REJECT-only) on dev-sgp private subnets | sparqd/project-management#1117 |
What's still unverified across these docs
- Whether
REDIS_PASSWORDis genuinely self-generated by the Bitnami valkey subchart or is a real gap — flagged, not confirmed - prod-sgp has much of the Secret Management and OpenBao content unwalked-through in its own right — most of what's documented is dev-sgp-specific until prod-sgp parity is confirmed, at which point these pages should note what differs
- Teardown is a one-paragraph placeholder, not a verified procedure