Azure DNS
Azure DNS hosts public DNS zones on Microsoft's global name servers. The Azure Enterprise Baseline keeps the organization's apex domain and one zone per stage in acme-core-dns, signs the important ones with DNSSEC, and lets the Web App Blueprint write records only in the stage zones.
What it does
A public DNS zone answers internet queries for a domain once its name servers are delegated to: by the registrar for an apex domain, or by NS records in the parent zone for a subdomain. DNSSEC signs a zone's records so resolvers can verify them; the chain of trust runs through a DS record in the parent zone (or at the registrar, for the apex). Access is by Azure RBAC: DNS Zone Contributor on a zone lets a principal write its records and nothing else. Azure DNS bills per zone and per million queries, and has no query logging for public zones.
How BuiltForProd uses it
The dns-zones unit in acme-core-dns creates, in acme-glob-dns-dns-zones-rg under a CanNotDelete lock:
| Zone | Delegation | DNSSEC |
|---|---|---|
company.com | at the registrar | signed |
prod.company.com, staging.company.com | NS records in the apex (TTL 300) | signed |
dev.company.com, sandbox.company.com | NS records in the apex (TTL 300) | unsigned |
Each zone costs $0.50 a month plus $0.40 per million queries, as the module comment states. The unit's settings add more: additional_domains gives every further apex domain the same four stage zones, delegated_zones delegates a subdomain to name servers outside Azure DNS, and dnssec_zones (["apex", "prod", "staging"]) picks the signed zones.
DNSSEC through AzAPI. The azurerm provider has no DNSSEC resource, so the module signs each zone with an azapi_resource of type Microsoft.Network/dnsZones/dnssecConfigs. It then writes the DS record of each signed stage zone into the apex, which closes the chain inside Azure DNS, and outputs the apex's DS record for the registrar.
Who writes the stage zones. The Web App Blueprint's infrastructure identity holds DNS Zone Contributor on every stage zone, plus a Role Based Access Control Administrator grant on the resource group that is constrained to that one role. With it, the blueprint:
- writes, for its Azure Front Door custom domains
blueprint-appandblueprint-api, the_dnsauthTXT records that validate the managed certificates and the CNAME records to the Front Door endpoints; - gives cert-manager's workload identity DNS Zone Contributor on the stage zone, so it can answer DNS-01 challenges for the ingress certificates.
Private names, such as internal.company.com, live in Azure Private DNS instead.
Terms you will see
| Term | Meaning |
|---|---|
| Apex zone | The organization's domain, company.com, delegated by the registrar. |
| Stage zone | <stage>.company.com, delegated from the apex with NS records. |
| DNSSEC | Signed DNS records that resolvers can verify. |
| DS record | The parent's record of a signed child zone's key, which links the chain of trust. |
| DNS Zone Contributor | The built-in role that writes the records of one zone. |
| Constrained grant | A role assignment right limited by a condition to assigning one role. |
Where to read more
- Azure Enterprise Baseline overview and Azure Web App Blueprint overview.
- Azure role-based access control for how the zone roles are granted.
- Least privilege for why each writer gets only the zones it needs.