
Sebastian Norris engineered robust cloud infrastructure and access controls for the ministryofjustice/modernisation-platform, focusing on secure, scalable deployment pipelines and environment management. He implemented features such as dynamic IAM policy updates, Oracle database connectivity across legacy and modern systems, and role-based access for specialized user groups, leveraging Terraform, AWS, and HCL. His work included enabling CI/CD workflows, refining firewall and network configurations, and introducing group-based permissions to streamline onboarding and governance. By addressing both feature delivery and targeted bug fixes, Sebastian demonstrated depth in DevOps, configuration management, and team collaboration, resulting in more reliable deployments and improved operational security across environments.
March 2026 (ministryofjustice/modernisation-platform): Delivered data governance enhancements by introducing a Data Architect User Group and associated access controls in the Delius Core configuration. This RBAC improvement strengthens role management, auditability, and security posture across the platform. No major bugs were reported this month. The work is traceable via commit 2cbd9597557370b036c709fc88b82cd76bce9a96 with message 'add data architects to delius core'. Overall business value: faster onboarding for data architects, reduced risk through stricter access controls, and improved compliance readiness.
March 2026 (ministryofjustice/modernisation-platform): Delivered data governance enhancements by introducing a Data Architect User Group and associated access controls in the Delius Core configuration. This RBAC improvement strengthens role management, auditability, and security posture across the platform. No major bugs were reported this month. The work is traceable via commit 2cbd9597557370b036c709fc88b82cd76bce9a96 with message 'add data architects to delius core'. Overall business value: faster onboarding for data architects, reduced risk through stricter access controls, and improved compliance readiness.
February 2026 — Key delivery: Added test environment access for the hmpps-vcms-write-team by introducing a new developer group to the test environment configuration (commit 207e100289631aa3ea7c7f145eb2026979829425). No major bugs fixed in this period. Impact: accelerates dev/test cycles and onboarding; improves security via explicit group-based access; enables faster validation of features in ministryofjustice/modernisation-platform. Technologies/skills demonstrated: environment configuration, RBAC, Git commits, cross-team collaboration.
February 2026 — Key delivery: Added test environment access for the hmpps-vcms-write-team by introducing a new developer group to the test environment configuration (commit 207e100289631aa3ea7c7f145eb2026979829425). No major bugs fixed in this period. Impact: accelerates dev/test cycles and onboarding; improves security via explicit group-based access; enables faster validation of features in ministryofjustice/modernisation-platform. Technologies/skills demonstrated: environment configuration, RBAC, Git commits, cross-team collaboration.
October 2025 monthly summary for ministryofjustice/modernisation-platform focusing on cross-environment Oracle database connectivity and firewall consolidation. Consolidated firewall rule updates enabled Oracle connectivity between legacy systems, the modernisation platform (MP), and staging/preproduction environments, improving cross-environment data access and integration for testing and deployment workflows. Result: faster end-to-end data access, reduced manual firewall changes, and more reliable cross-environment testing. Delivered via two commits that implemented Oracle connectivity across environments, ensuring traceability and reproducibility.
October 2025 monthly summary for ministryofjustice/modernisation-platform focusing on cross-environment Oracle database connectivity and firewall consolidation. Consolidated firewall rule updates enabled Oracle connectivity between legacy systems, the modernisation platform (MP), and staging/preproduction environments, improving cross-environment data access and integration for testing and deployment workflows. Result: faster end-to-end data access, reduced manual firewall changes, and more reliable cross-environment testing. Delivered via two commits that implemented Oracle connectivity across environments, ensuring traceability and reproducibility.
September 2025 monthly summary for ministryofjustice/modernisation-platform. Focused on delivering access controls and enabling Civica integration with VCMS. No major bug fixes reported this month.
September 2025 monthly summary for ministryofjustice/modernisation-platform. Focused on delivering access controls and enabling Civica integration with VCMS. No major bug fixes reported this month.
July 2025 monthly summary for ministryofjustice/modernisation-platform: Delivered the VCMS ECR Repository and CI/CD Access Configuration, enabling secure, automated deployment pipelines for the VCMS application across multiple environments. Updated Terraform core shared services to support CI/CD pipelines and related services with proper access controls, enhancing consistency, security, and deployment velocity.
July 2025 monthly summary for ministryofjustice/modernisation-platform: Delivered the VCMS ECR Repository and CI/CD Access Configuration, enabling secure, automated deployment pipelines for the VCMS application across multiple environments. Updated Terraform core shared services to support CI/CD pipelines and related services with proper access controls, enhancing consistency, security, and deployment velocity.
Month: 2025-04 — Features delivered: ECS Remote Command Execution Enablement in ministryofjustice/modernisation-platform. Added ecs:ExecuteCommand permission to the IAM policy for OIDC roles, enabling remote debugging and on-demand command execution within ECS tasks. Implementation tracked in commit bca7780f9047032c43a4b6b9ab9d6335b6a48321 with message 'add ecs commands to oidc role'. Impact includes faster debugging, reduced MTTR, and a more auditable remote execution workflow.
Month: 2025-04 — Features delivered: ECS Remote Command Execution Enablement in ministryofjustice/modernisation-platform. Added ecs:ExecuteCommand permission to the IAM policy for OIDC roles, enabling remote debugging and on-demand command execution within ECS tasks. Implementation tracked in commit bca7780f9047032c43a4b6b9ab9d6335b6a48321 with message 'add ecs commands to oidc role'. Impact includes faster debugging, reduced MTTR, and a more auditable remote execution workflow.
Monthly summary for 2025-03 (ministryofjustice/modernisation-platform) Key features delivered: - Dynamic Load Balancer Rule Management: Enabled the OIDC role to modify load balancer rules by updating the IAM policy to include elasticloadbalancing:ModifyRule, enabling dynamic rule management and faster response to traffic shaping needs. Commit reference provided for traceability. Major bugs fixed: - No major bugs reported within this scope for March 2025. Overall impact and accomplishments: - Improves agility in operational traffic management by allowing programmatic, policy-driven updates to load balancer rules, reducing manual intervention and risk. - Strengthens security posture through explicit least-privilege permission for dynamic rule management and better traceability via commit history. - Demonstrates end-to-end execution from policy changes to deployment readiness within the modernisation platform scope. Technologies/skills demonstrated: - IAM policy updates and least-privilege access control - AWS Elastic Load Balancing rule management permissions - OIDC-based access control integration - Version control traceability (single commit reference)
Monthly summary for 2025-03 (ministryofjustice/modernisation-platform) Key features delivered: - Dynamic Load Balancer Rule Management: Enabled the OIDC role to modify load balancer rules by updating the IAM policy to include elasticloadbalancing:ModifyRule, enabling dynamic rule management and faster response to traffic shaping needs. Commit reference provided for traceability. Major bugs fixed: - No major bugs reported within this scope for March 2025. Overall impact and accomplishments: - Improves agility in operational traffic management by allowing programmatic, policy-driven updates to load balancer rules, reducing manual intervention and risk. - Strengthens security posture through explicit least-privilege permission for dynamic rule management and better traceability via commit history. - Demonstrates end-to-end execution from policy changes to deployment readiness within the modernisation platform scope. Technologies/skills demonstrated: - IAM policy updates and least-privilege access control - AWS Elastic Load Balancing rule management permissions - OIDC-based access control integration - Version control traceability (single commit reference)
February 2025 monthly performance summary for ministryofjustice/hmpps-env-configs: Implemented a critical network access fix to enable Prisma VPN connectivity to Alfresco in pre-production and production environments by updating allowed CIDR blocks. This removed a connectivity blocker for developers and automated processes and aligns with security policies for remote access to critical content services. The change was implemented in a single commit (d01cd9cfe4d63a6f557e9298ab0bc26235abc3fc, 'allow prisma vpn for alfresco pre + prod'), and validated against environment-specific access configurations. Overall, this work demonstrates effective collaboration between networking/config management and security teams, delivering measurable business value through uninterrupted access to Alfresco for content workflows.
February 2025 monthly performance summary for ministryofjustice/hmpps-env-configs: Implemented a critical network access fix to enable Prisma VPN connectivity to Alfresco in pre-production and production environments by updating allowed CIDR blocks. This removed a connectivity blocker for developers and automated processes and aligns with security policies for remote access to critical content services. The change was implemented in a single commit (d01cd9cfe4d63a6f557e9298ab0bc26235abc3fc, 'allow prisma vpn for alfresco pre + prod'), and validated against environment-specific access configurations. Overall, this work demonstrates effective collaboration between networking/config management and security teams, delivering measurable business value through uninterrupted access to Alfresco for content workflows.
January 2025 monthly summary for ministryofjustice/modernisation-platform: delivered key infrastructure and access improvements to support production-ready connectivity and secure operations for Delius Core and MIS, with notable enhancements in environment access control and security posture.
January 2025 monthly summary for ministryofjustice/modernisation-platform: delivered key infrastructure and access improvements to support production-ready connectivity and secure operations for Delius Core and MIS, with notable enhancements in environment access control and security posture.
In November 2024, delivered cross-environment ECR access for core WebLogic modules and related services to enable CI/CD deployment across preproduction and production environments; updated CODEOWNERS to include a new collaborator for clearer ownership and review responsibilities; and performed targeted code cleanup to remove extraneous spaces, improving readability. These changes reduce deployment friction, improve governance, and enhance code quality, contributing to faster, more reliable releases and better collaboration across environments.
In November 2024, delivered cross-environment ECR access for core WebLogic modules and related services to enable CI/CD deployment across preproduction and production environments; updated CODEOWNERS to include a new collaborator for clearer ownership and review responsibilities; and performed targeted code cleanup to remove extraneous spaces, improving readability. These changes reduce deployment friction, improve governance, and enhance code quality, contributing to faster, more reliable releases and better collaboration across environments.

Overview of all repositories you've contributed to across your timeline