# OSVauco / OPAX – TODO > Managed by PLAN thread. Update when phases move between sections. > Last updated: 2026-05-22 --- ## NOW - [ ] Phase 3 — verify GEMINI.md Nemotron loop and boot script `NESTE OPPGAVE` display. - [ ] Confirm Cloud Run `opax-mcp-core` is back online after crash and `curl https://opax.vauco.no/ping` returns `200 OK`. - [ ] Re-verify domain mapping `opax.vauco.no` → `ghs.googlehosted.com` still active after Cloud Run redeploy. --- ## NEXT - [ ] Phase 4 — Docs hardening: update `LEARNINGS.md`, `SECRETS-SETUP.md`, `IAP-SETUP.md` with current state. - [ ] Phase 5 — Medioteq staging: deploy `medioteq-oss-core` to Medioteq GCP project → map `medioteq-oss.vauco.no` → Google OAuth. - [ ] Phase 5b — Medioteq prod: deploy `medioteq-os-core` → map `medioteq-os.vauco.no` → BankID prep. - [ ] Create `docs/MEDIOTEQ-IAM-CONTRACT.md` and `docs/MEDIOTEQ-GOVERNANCE-WHITEPAPER.md`. - [ ] Add cross-project status endpoint in OPAX so hub can query Medioteq project status without touching clinical data. --- ## LATER - [ ] IAP on `opax.vauco.no` (restrict to `@vauco.no` only). - [ ] BankID on `medioteq-os.vauco.no`. - [ ] Multi-client onboard pattern: `-oss-core` → `-os-core` with IAM contract template. - [ ] `opax-mcp/` restructured as proper module subtree. - [ ] Full boot cycle acceptance test (automated). --- ## BLOCKED - Cloud Run `opax-mcp-core` crashed — must redeploy before Phase 3 verification can complete. *(2026-05-22)*