<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Procurement on Sakura Sky: Cloud, Data, Security</title><link>https://www.sakurasky.com/tags/procurement/</link><description>Recent content in Procurement on Sakura Sky: Cloud, Data, Security</description><generator>Hugo</generator><language>en-US</language><copyright>Sakura Sky</copyright><lastBuildDate>Tue, 29 Sep 2026 00:00:00 -0400</lastBuildDate><atom:link href="https://www.sakurasky.com/tags/procurement/index.xml" rel="self" type="application/rss+xml"/><item><title>Sovereign Cloud Is an Architecture, Not a Procurement</title><link>https://www.sakurasky.com/blog/government-engineering-part-1/</link><pubDate>Tue, 29 Sep 2026 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/government-engineering-part-1/</guid><description>&lt;style&gt;&#10; &#10;.series-pull-quote {&#10; float: right;&#10; clear: both;&#10; width: 340px;&#10; margin-left: 2rem;&#10; margin-bottom: 1.5rem;&#10; border: 1px solid #e9ecef;&#10; border-radius: 6px;&#10; overflow: hidden;&#10; background-color: #ffffff;&#10; &#10; position: relative;&#10; z-index: 20;&#10;}&#10;&#10; &#10;@media (max-width: 768px) {&#10; .series-pull-quote {&#10; float: none;&#10; clear: both;&#10; width: 100%;&#10; margin-left: 0;&#10; }&#10;}&#10;&#10;.series-header {&#10; background-color: #f8f9fa;&#10; color: #6c757d;&#10; font-size: 0.65rem;&#10; font-weight: 700;&#10; letter-spacing: 0.05em;&#10; padding: 0.8rem 1.25rem;&#10; border-bottom: 1px solid #e9ecef;&#10;}&#10;&#10;.part-label {&#10; display: block;&#10; font-size: 0.6rem;&#10; color: #adb5bd;&#10; margin-bottom: 0.15rem;&#10; text-transform: uppercase;&#10;}&#10;&#10;.nav-link-text {&#10; font-size: 0.85rem;&#10; line-height: 1.4;&#10; color: #495057;&#10; text-decoration: none;&#10; &#10; position: relative;&#10; z-index: 21;&#10;}&#10;&#10; &#10;.active-part {&#10; border-left: 4px solid #000 !important;&#10; background-color: #ffffff !important;&#10;}&#10;&#10;.active-part .nav-link-text {&#10; font-size: 0.9rem;&#10; font-weight: 700;&#10; color: #212529;&#10; text-decoration: underline;&#10; text-underline-offset: 3px;&#10;}&#10;&#10;.locked-part .nav-link-text {&#10; color: #ced4da;&#10;}&#10;&#10;.list-group-item {&#10; border-bottom: 1px solid #f8f9fa;&#10; padding: 1rem 1.25rem !important;&#10;}&#10;&lt;/style&gt;&#10;&#10;&lt;aside class="series-pull-quote shadow-sm"&gt;&#10; &lt;div class="series-header"&gt;&#10; READ MORE IN THIS SERIES&#10; &lt;/div&gt;&#10; &lt;div class="list-group list-group-flush"&gt;&#10; &#10; &#10; &#10;&#10; &lt;div class="list-group-item active-part "&gt;&#10; &lt;div class="d-flex justify-content-between align-items-center"&gt;&#10; &lt;div&gt;&#10; &#10; &lt;a href="https://www.sakurasky.com/blog/government-engineering-part-1/" class="nav-link-text"&gt;Part 1 - Sovereign Cloud Is an Architecture, Not a Procurement&lt;/a&gt;&#10; &#10; &lt;/div&gt;&#10;&#10; &lt;/div&gt;&#10; &lt;/div&gt;&#10; &#10; &#10; &#10;&#10; &lt;div class="list-group-item locked-part"&gt;&#10; &lt;div class="d-flex justify-content-between align-items-center"&gt;&#10; &lt;div&gt;&#10; &#10; &lt;span class="nav-link-text"&gt;Part 2 - API Governance Done Properly&lt;/span&gt;&#10; &#10; &lt;/div&gt;&#10;&#10; &lt;/div&gt;&#10; &lt;/div&gt;&#10; &#10; &#10; &#10;&#10; &lt;div class="list-group-item locked-part"&gt;&#10; &lt;div class="d-flex justify-content-between align-items-center"&gt;&#10; &lt;div&gt;&#10; &#10; &lt;span class="nav-link-text"&gt;Part 3 - Legacy Modernisation That Meets the Audit Bar&lt;/span&gt;&#10; &#10; &lt;/div&gt;&#10;&#10; &lt;/div&gt;&#10; &lt;/div&gt;&#10; &#10; &lt;/div&gt;&#10;&lt;/aside&gt;&#10;&#10;&#10;&lt;p&gt;The agency in this story is a composite, drawn from several engagements, though every detail in it is one we&amp;rsquo;ve seen. It signed a sovereign cloud contract after a careful procurement. The platform was certified, the data would stay in-country, and the provider&amp;rsquo;s operating entity met the ownership conditions the policy asked for. Well into the second year, a team mapping dependencies for an unrelated migration counted thirty-two services in the agency&amp;rsquo;s stack that still reached outside the sovereign boundary. The identity directory synchronised to a global tenant. Logs and traces went to a monitoring service hosted overseas, and that vendor&amp;rsquo;s support staff, in another jurisdiction, could see them. A CI/CD service and a handful of developer tools each had their own route out. Separately, the platform&amp;rsquo;s key management service was still running on the provider&amp;rsquo;s defaults, with the settings that would have given the agency its own key custody left for a later phase.&lt;/p&gt;</description></item></channel></rss>