Skip to content

Operations & Status

Live environment status, the current priority list, and the CI/CD pipeline reference for the Bedrock Cybersecurity documentation platform.

System status

EnvironmentStatusKey Services
Azure PROD🟢 Operationalciriusgroup.com · Palo Alto × 2 · Arctic Wolf · Cortex XDR
Azure DDE🟢 Operationalciriusdde.com · AVD · Medicare patient access
AWS DR🟢 Standby7-account org · Palo Alto × 2 · Veeam targets
SOC Platform🟢 soc.bedrockcybersecurity.orgIncident triage · known-good rules · CM tickets
SecOps Dashboard🟢 secops.bedrockcybersecurity.orgMetrics aggregator (read-only)
Logging🟢 Activecirius-logging-law-central · 6-year WORM archive

Update this table after any incident, environment change, or status shift.

Active priorities — June 2026

#ItemStatus
1Kill chain Phase 1 — EventID 4688 + PowerShell logging✅ Complete
2Kill chain Phase 2 — 6 detection agents (execution, persistence, cred dump, lateral, exfil, evasion)✅ Complete — agents live
3Orchestrator split — PROD / DDE / AWS as separate Container Apps Jobs✅ Complete (since consolidated)
4VNET UDR route tables — force spoke-to-spoke through Palo Alto NVA🔴 In progress
5HITRUST audit prep🟡 Sep 2026
6Twingate device compliance certs🟡 Planned
7pgaudit on psql-secops-prod🟢 Backlog

CI/CD workflows

WorkflowTriggerPurposeSecOps
pr-validationPR → mainBuilds VitePress site — gate for merge
security-scanPR → mainBandit · Checkov · Trivy → SecOps findings✅ findings
auto-mergePR open/syncQueues squash-merge on CI pass
ingest-changesPR mergedCM record to SecOps for 2-hour alert window✅ CM record
deploy-docspush → mainVitePress build → Cloudflare Pages✅ on failure
baseline-scanMonday + pushCode embedding baseline (requires BASELINE_ROLE_ARN var)

Internal use only — Cirius Group