Skip to main content

Azure Private DNS

Azure Private DNS hosts zones that resolve only inside the virtual networks linked to them. The Azure Enterprise Baseline keeps one copy of every private zone in acme-core-network and links every network of the landing zone to all of them, so private names resolve the same way everywhere.

What it does​

A private DNS zone holds records like a public zone, but answers only queries that arrive through Azure-provided DNS from a linked virtual network. A link can turn on auto-registration, which adds a record for every virtual machine in the network. A Private Link zone, such as privatelink.vaultcore.azure.net, is the zone Azure expects for one service's private endpoints: the service's public name is a CNAME into it, so the same name returns the private address from a linked network. A link's resolution policy decides what happens when a Private Link zone has no record for a name: Default answers that the name does not exist, NxDomainRedirect falls back to public resolution.

How BuiltForProd uses it​

The private-dns unit (module private-dns-zones) creates the zones in acme-core-network, in acme-eus2-network-private-dns-rg, under a CanNotDelete lock, and links them to the hub; each zone costs about $0.50 a month.

Azure/acme-azure-platform-baseline/units/private-dns/terragrunt.hcl (lines 48-64)
inputs = {
internal_zone_name = "internal.${include.root.locals.domain_name}"
privatelink_zone_names = [ # @optional: one zone per PaaS type that gets a private endpoint
"privatelink.vaultcore.azure.net",
"privatelink.blob.core.windows.net",
"privatelink.dfs.core.windows.net",
"privatelink.queue.core.windows.net",
"privatelink.web.core.windows.net",
"privatelink.azurecr.io",
"privatelink.redis.azure.net",
"privatelink.mongocluster.cosmos.azure.com",
"privatelink.${include.root.locals.azure_region}.azmk8s.io",
"privatelink.azuredatabricks.net",
]
link_vnet_ids = { hub = dependency.vnet.outputs.vnet_id }
registration_enabled = false
privatelink_resolution_policy = "Default" # @optional: NxDomainRedirect resolves publicly when no private endpoint record exists

Links. Every stage spoke and the runner network link themselves to every zone with the private-dns-link unit, which writes the links into acme-core-network through the hub provider alias. Auto-registration is off on every link, and the resolution policy is Default, with NxDomainRedirect as the switch.

Who writes records.

  • Private endpoints register their own records through a private DNS zone group; the two blueprint infrastructure identities hold Private DNS Zone Contributor on the zones' resource group for that, plus a constrained Role Based Access Control Administrator grant that lets them give exactly that role to identities they create.
  • In the Web App Blueprint, the AKS application routing add-on writes A records for internal ingress hosts, such as argocd.<stage>.internal.company.com, into internal.company.com; it holds Private DNS Zone Contributor on that zone only.
  • A private AKS cluster registers its API server in privatelink.eastus2.azmk8s.io.

The spokes and the runner network use Azure-provided DNS, which answers from the linked zones directly. Clients outside Azure DNS, such as VPN clients and the firewall's DNS proxy, reach the same zones through the DNS Private Resolver in the hub. There are no Azure Monitor Private Link Scope zones: the Log Analytics workspaces keep their public endpoints.

Terms you will see​

TermMeaning
Private DNS zoneA zone that answers only queries from linked virtual networks.
Virtual network linkThe connection between a zone and one virtual network.
Private Link zoneThe privatelink.* zone for one service's private endpoints.
Auto-registrationAutomatic records for virtual machines in a linked network; off here.
Resolution policyThe link setting for names missing from a Private Link zone: Default here.
Internal zoneinternal.company.com, for the platform's own private host names.

Where to read more​