Cloud DNS
Cloud DNS hosts public and private DNS zones on Google's name servers. The GCP Enterprise Baseline hosts the company domain and one subdomain per stage in acme-core-dns, a private zone for every network in acme-core-network, and lets each stage write only its own records.
What it does
A managed zone holds the records of one DNS name. A public zone answers the internet; a private zone answers only the VPC networks it is attached to. A parent zone delegates a subdomain with NS records. DNSSEC signs a zone's records, and a DS record in the parent links the signatures into a chain of trust. Public zones can log the queries they answer; for private names, a DNS server policy with logging on a network logs every query its resources make. IAM can be granted on a single zone.
How BuiltForProd uses it
Public zones (dns-zones unit, acme-core-dns):
| Zone | DNS name | DNSSEC | Query logging |
|---|---|---|---|
acme-apex | company.com | on | on |
acme-prod | prod.company.com | on | on |
acme-staging | staging.company.com | on | on |
acme-dev | dev.company.com | off | off |
acme-sandbox | sandbox.company.com | off | off |
The apex delegates each stage subdomain with NS records written by the same unit, so a stage zone resolves as soon as it exists, and holds the DS records of the signed stage zones. Signing uses ECDSA P-256 keys with NSEC3 and has no surcharge; the zone lists are @optional values in the unit, and further apex domains can be added at $0.20 per zone per month.
The private zone acme-internal (internal.company.com, private-dns unit, acme-core-network) is attached directly to the hub, prod and nonprod VPC networks, so every stage project resolves it through the Shared VPC without DNS peering. The DNS server policy acme-vpc-dns-logging logs every query of the three networks (enable_dns_query_logging = true in network.hcl, CIS Google Cloud Foundations Benchmark 2.12; billed as Logging ingestion), and the organization sink brings those logs to the central bucket.
Who writes records. Grants are per zone, never project-wide:
| Zone | roles/dns.admin on the zone |
|---|---|
acme-<stage> | that stage's deployer sa-acme-terraform-deployer |
acme-internal | the four stage deployers |
The Web App Blueprint writes through those identities: its Certificate Manager DNS authorizations and its external-dns records. Listing zones is a project-level permission that zone IAM cannot give, so each external-dns release also holds roles/dns.reader on its host project (acme-core-dns for the public release, acme-core-network for the internal one), for every stage listed in webapp_gke_stages of environments/plat/plat.hcl.
The contract. pm-publish writes each stage's public zone and the private zone, with their projects, as dns--public-zone, dns--public-zone-project, dns--private-zone and dns--private-zone-project.
Terms you will see
| Term | Meaning |
|---|---|
| Apex zone | acme-apex, the zone of the company domain itself. |
| Stage zone | acme-<stage>, a delegated subdomain such as prod.company.com. |
| DS record | The parent's link to a signed child zone's key. |
| DNS server policy | The network-level setting that logs every private DNS query. |
| Zone-level IAM | A role granted on one zone only. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App Blueprint overview.
- VPC networks for the networks the private zone is attached to.
- Shared VPC for how stage projects use the host's networks.