Block a user
Refactor scripts/backup.sh — currently 200 LoC unstructured
Switch from terragrunt to native terraform
Tag all terraform resources with cost-center
Document the terraform state-locking setup
Add lint job for ansible playbooks
Cache pip wheels in CI to speed builds
Move ansible facts cache to memcached
Document the OIDC discovery endpoint behavior
Add proper integration tests via testcontainers
Drop legacy /v0 endpoints
Implement WebAuthn/passkey registration
Add rate-limit on /login by IP+username
Move to argon2id for password hashing
Implement refresh-token rotation
OIDC: add Microsoft Entra ID
Add audit log for all token issuance