Skip to main content
Last updated: 25 Jun 2021

app_domain handling in GOV.UK during migration to AWS

Deprecation note: This page should be removed after all machines in Carrenza have been shutdown and all reference to this has been removed from govuk-puppet

The app-by-app migration plan to move GOV.UK to AWS introduced an $app_domain_internal parameter in addition to the previously used $app_domain.

This is necessary because in AWS we use a <environment> domain in addition to the <environment> domain.

Furthermore, the app_domain parameter may be set to the <environment> for migrated apps as well. The exact configuration depends on the current state of the migrated app as well as its dependencies.

For example, migrated backend applications, such as Support, may be configured to use the <environment> $app_domain to facilitate access to Signon over the internet.

Applications in Carrenza which talk to AWS over the VPN need to resolve <environment> The names under point to private IP addresses in AWS.

At the moment this is only done for RabbitMQ exchange federation because the performance platform (backdrop) still depends on RabbitMQ.

As a rule of thumb:

  • Applications which have been moved to AWS and have all their dependencies in AWS will use $app_domain=<environment> and $app_domain_internal=<environment>
  • Applications which remain in Carrenza, including all their dependencies, will only use app_domain=<environment>
  • Applications having dependencies in both AWS and Carrenza will require some customisation of service resolution in form of a Plek URI override and may use either $app_domain=<environment> or $app_domain=<environment>

Note: we use Plek to generate the correct base URLs for internal GOV.UK services. These URLs can be overridden when a Plek instance is instantiated.

Since setting the correct service discovery environment for a particular app is complicated due to the migration to AWS, please take extra care to make sure you understand the effects of changes to the app_domain parameter and Plek URI overrides via environment variables.

If in doubt, please talk to GOV.UK Replatforming to make sure your changes will not have unintended side effects.