This is a new service – your feedback will help us to improve it.

  1. Home
  2. Documentation
  3. Modernisation Platform User Guide
  4. Creating networking resources in the Modernisation Platform

Creating networking resources in the Modernisation Platform

Overview

In the Modernisation Platform, we provide the core networking resources that you will need for your application.

For each account there are networking resources that we provide as standard, and additional resources that can be added if needed.

These are defined in JSON files in the environment-networks directory.

The Modernisation Platform will work with you to create these files based on details in your environment request, and assign you VPC and subnet CIDR ranges.

Standard resources

VPC

VPC (AWS Virtual Private Cloud), providing out of the box network isolation.

Subnet Sets

Three different subnet types spread across all three availability zones (eu-west-2a, eu-west-2b, eu-west2c), making a total of nine subnets:

  • Private (for private resources such as application servers)
  • Public (for public resources such as load balancers)
  • Data (for data resources such as databases)

If your business unit needs more address space than this provides, we can add secondary CIDR blocks to the VPC, which creates further subnets.

DNS Zones

Hosted public and private DNS zones for your application domain names.

Certificate Services

Amazon issued public certificates and shared live and non live subordinate private CA(Certificate Authority) for private certificates.

VPC Endpoints

Endpoints for EC2, EC2 Messages, SSM and SSM Messages, plus a gateway endpoint for S3, are created in your VPC's protected subnets.

If you need an endpoint for another AWS service, we can add it using the additional_endpoints option. See environments-networks json explained.

There is also a centralised VPC endpoints hub, which offers a wider set of services. It currently serves isolated network accounts only.

Additional networking resources

Connectivity to other VPCs or external parties

As default your VPC is isolated, if you need connectivity to other VPCs with in the MoJ, or VPN (Virtual private network) connections to external parties this can be created.

Linux Bastion

Connecting to servers should be done via AWS Systems Manager, but if it is not possible to install the SSM agent due to the age of the operating system, then a secure bastion server can be provisioned. A bastion can also be used for connecting locally to RDS databases via port forwarding. We provide a module to create a bastion instance.

Extended DNS

Allow your VPC to have access to additional DNS zones in other VPCs.

Isolated Network

If you require an isolated environment that is separated from the standard resources detailed above with no internet or shared network connectivity please select the 'Isolated' option under subnet sets (Networking Options) when submitting your new environment request.

This option will trigger the copy of a different set of platform environment templates which can be found here.

An isolated account builds its own VPC inside the account, rather than using shared subnets from a business unit VPC. This means:

  • you get private subnets only, one per availability zone - there are no public or data subnets
  • there is no Transit Gateway attachment, so no connectivity to the wider MoJ network, to other Modernisation Platform accounts, or to the centralised NAT gateway
  • a smaller set of VPC endpoints is created in your account, supplemented by the centralised VPC endpoints hub

This option is used by the MoJ hosting platforms that run on top of the Modernisation Platform, such as Cloud Platform and Container Platform, as well as by applications that need to be separated from shared networking.

Moving between the standard and isolated models after an account has been created is not straightforward, so it is worth being confident about which one you need up front. If you are unsure, please ask in #ask-modernisation-platform.

Things to be aware of

  • PSN connectivity is available in production and preproduction only. There is no route to the PSN range from development, test or sandbox environments, so PSN connectivity cannot be tested there.
  • Sandbox is not routable. Sandbox VPCs have no connectivity to the wider MoJ network or to other Modernisation Platform environments, and should be used for local experimentation only.
  • Outbound internet traffic is inspected. Traffic from private subnets leaves through a centralised NAT gateway and is subject to AWS Network Firewall rules, including FQDN-based inspection. You may need a firewall rule to reach an external endpoint.
  • Networking is shared across your business unit. VPCs, NACLs and protected subnet capacity are shared between all the accounts in a business unit, so changes affect more than one application.

Additional information

You can view our architecture for Networking on the dedicated networking approach page, which also explains what you get by doing this.

Last reviewed: 15 September 2026Review status: ✓ Up to dateOwner: #modernisation-platformSource: View source on GitHub

Was this page useful?