Deployments/teleicu.ohc.network
From OHC Network Wiki
More languages
More actions
teleicu.ohc.network is the 10BedICU project's CARE staging environment. Each week it stages the proposed TeleICU production release and runs end-to-end testing before that release is promoted to the production TeleICU deployments.
Service overview
| Purpose | Stage weekly CARE production release candidates and perform E2E testing before rollout to TeleICU production deployments |
|---|---|
| Scope and users | Pre-production release gate for the TeleICU deployment fleet |
| Data and criticality | Classification: Not documented Service tier: Staging / production release gate |
| Public endpoints | Frontend: https://teleicu.ohc.network |
Governance and responsibility
| Accountable organisation | 10BedICU |
|---|---|
| Platform operator | 10BedICU |
| Supporting organisations | None documented |
| Service ownership | Clinical/product: Not documented Technical: 10BedICU Data controller: Not documented |
| Support and escalation | Not documented |
| Commercial ownership | Billing owner: Not documented |
Application and infrastructure
| Component | Deployment details | Source and release |
|---|---|---|
| Frontend | Provider: Google Kubernetes Engine GCP-native deployment on GKE provisioned and configured with OpenTofu |
Repository Revision: not documented |
| Backend | Provider: Google Kubernetes Engine GCP-native deployment on GKE provisioned and configured with OpenTofu |
Repository Revision: not documented |
| Database | Provider: Google Cloud Platform GCP-native managed data service; exact product, engine, version, topology, and region remain to be documented |
Schema change process not documented |
| Object/file storage | Provider: Google Cloud Platform GCP-native storage; exact service and lifecycle remain to be documented |
Change process not documented |
| Runtime and network | Primary provider: Google Cloud Platform Region(s): Not documented Runtime/orchestrator: Google Kubernetes Engine (GKE), managed with OpenTofu |
Ingress, egress, DNS, CDN/WAF, and private connectivity not documented |
| Supporting services | Cache: Not documented Queue/broker: Not documented Search: Not documented |
Identity: Not documented Messaging: Not documented Other dependencies: Not documented |
CARE plugins
The list below is generated from the deployment-plugin inventory. Repository and maintainer data come from each plugin page; configuration must name flags or secret references only, never secret values.
No enabled plugins are documented for this deployment.
Delivery and change management
| CI/CD and deployment | A CI release pipeline deploys the weekly TeleICU production release candidate to this staging environment |
|---|---|
| Configuration source | OpenTofu tfvars are the source of truth for deployment configuration |
| Release policy | Weekly release staging followed by E2E validation before promotion to TeleICU production deployments |
| Change records | Issue tracker, deployment history, or change log is not documented |
| Validation | End-to-end tests are run against the staged weekly release to reduce regressions before production rollout; test suite, sign-off criteria, and evidence location remain to be documented |
Security, privacy, and compliance
| Identity and access | Application, GKE, and platform security use GCP-native capabilities; authentication, authorization, and access-review procedures remain to be documented |
|---|---|
| Secrets management | GCP-native secret/configuration facilities; secret names, rotation, and ownership remain to be documented Do not place secret values on this wiki. |
| Encryption and boundaries | Encryption in transit/at rest, network boundaries, and key ownership are not documented |
| Audit and assurance | Audit trail, retention, reviewers, and security assessment are not documented |
| Privacy and retention | Purpose limitation, residency, retention, deletion, consent, and data-subject processes are not documented |
| Compliance | Applicable law, policy, agreements, and evidence location are not documented |
Observability and operations
| Health and monitoring | GCP-provided native monitoring for the GKE environment; dashboards, checks, and ownership remain to be documented |
|---|---|
| Alerting | GCP-provided native alerting; routes and severity policy remain to be documented |
| Logs and traces | Collection, access, redaction, retention, and tracing are not documented |
| Service objectives | Availability target, SLIs/SLOs, capacity thresholds, and error budget are not documented |
| Runbooks | Not documented |
| Routine operations | Patching, certificate/domain renewal, scaling, housekeeping, and ownership are not documented |
Continuity and recovery
| Backups | GCP-provided native backup capabilities; covered resources, schedule, retention, and restore ownership remain to be documented |
|---|---|
| Restore assurance | Last restore test, result, and evidence are not documented |
| Recovery objectives | RPO: Not documented · RTO: Not documented |
| Disaster recovery | Failure scenarios, alternate region/site, failover, and failback are not documented |
| Decommissioning | Shutdown approval, export, retention, deletion, DNS, and cost cleanup are not documented |
Risks, decisions, and review
| Known limitations and risks | This staging environment is the weekly validation gate for multiple TeleICU production deployments; incomplete E2E coverage may allow regressions through |
|---|---|
| Architecture decisions | Decision records and accepted trade-offs are not documented |
| Open actions | None documented |
| Review record | Status: draft Last reviewed: 2026-08-25 Review owner: Not documented |