Azure Private DNS
Azure Private DNS hosts zones that resolve only inside the virtual networks linked to them. The Azure Enterprise Baseline keeps one copy of every private zone in acme-core-network and links every network of the landing zone to all of them, so private names resolve the same way everywhere.
What it does
A private DNS zone holds records like a public zone, but answers only queries that arrive through Azure-provided DNS from a linked virtual network. A link can turn on auto-registration, which adds a record for every virtual machine in the network. A Private Link zone, such as privatelink.vaultcore.azure.net, is the zone Azure expects for one service's private endpoints: the service's public name is a CNAME into it, so the same name returns the private address from a linked network. A link's resolution policy decides what happens when a Private Link zone has no record for a name: Default answers that the name does not exist, NxDomainRedirect falls back to public resolution.
How BuiltForProd uses it
The private-dns unit (module private-dns-zones) creates the zones in acme-core-network, in acme-eus2-network-private-dns-rg, under a CanNotDelete lock, and links them to the hub; each zone costs about $0.50 a month.
inputs = {
internal_zone_name = "internal.${include.root.locals.domain_name}"
privatelink_zone_names = [ # @optional: one zone per PaaS type that gets a private endpoint
"privatelink.vaultcore.azure.net",
"privatelink.blob.core.windows.net",
"privatelink.dfs.core.windows.net",
"privatelink.queue.core.windows.net",
"privatelink.web.core.windows.net",
"privatelink.azurecr.io",
"privatelink.redis.azure.net",
"privatelink.mongocluster.cosmos.azure.com",
"privatelink.${include.root.locals.azure_region}.azmk8s.io",
"privatelink.azuredatabricks.net",
]
link_vnet_ids = { hub = dependency.vnet.outputs.vnet_id }
registration_enabled = false
privatelink_resolution_policy = "Default" # @optional: NxDomainRedirect resolves publicly when no private endpoint record exists
Links. Every stage spoke and the runner network link themselves to every zone with the private-dns-link unit, which writes the links into acme-core-network through the hub provider alias. Auto-registration is off on every link, and the resolution policy is Default, with NxDomainRedirect as the switch.
Who writes records.
- Private endpoints register their own records through a private DNS zone group; the two blueprint infrastructure identities hold Private DNS Zone Contributor on the zones' resource group for that, plus a constrained Role Based Access Control Administrator grant that lets them give exactly that role to identities they create.
- In the Web App Blueprint, the AKS application routing add-on writes A records for internal ingress hosts, such as
argocd.<stage>.internal.company.com, intointernal.company.com; it holds Private DNS Zone Contributor on that zone only. - A private AKS cluster registers its API server in
privatelink.eastus2.azmk8s.io.
The spokes and the runner network use Azure-provided DNS, which answers from the linked zones directly. Clients outside Azure DNS, such as VPN clients and the firewall's DNS proxy, reach the same zones through the DNS Private Resolver in the hub. There are no Azure Monitor Private Link Scope zones: the Log Analytics workspaces keep their public endpoints.
Terms you will see
| Term | Meaning |
|---|---|
| Private DNS zone | A zone that answers only queries from linked virtual networks. |
| Virtual network link | The connection between a zone and one virtual network. |
| Private Link zone | The privatelink.* zone for one service's private endpoints. |
| Auto-registration | Automatic records for virtual machines in a linked network; off here. |
| Resolution policy | The link setting for names missing from a Private Link zone: Default here. |
| Internal zone | internal.company.com, for the platform's own private host names. |
Where to read more
- Azure Enterprise Baseline overview and Azure Web App Blueprint overview.
- Private Link for the endpoints whose records live here.
- Hub-and-spoke networking for shared services in the hub.