Skip to main content

Cloud DNS

Cloud DNS hosts public and private DNS zones on Google's name servers. The GCP Enterprise Baseline hosts the company domain and one subdomain per stage in acme-core-dns, a private zone for every network in acme-core-network, and lets each stage write only its own records.

What it does​

A managed zone holds the records of one DNS name. A public zone answers the internet; a private zone answers only the VPC networks it is attached to. A parent zone delegates a subdomain with NS records. DNSSEC signs a zone's records, and a DS record in the parent links the signatures into a chain of trust. Public zones can log the queries they answer; for private names, a DNS server policy with logging on a network logs every query its resources make. IAM can be granted on a single zone.

How BuiltForProd uses it​

Public zones (dns-zones unit, acme-core-dns):

ZoneDNS nameDNSSECQuery logging
acme-apexcompany.comonon
acme-prodprod.company.comonon
acme-stagingstaging.company.comonon
acme-devdev.company.comoffoff
acme-sandboxsandbox.company.comoffoff

The apex delegates each stage subdomain with NS records written by the same unit, so a stage zone resolves as soon as it exists, and holds the DS records of the signed stage zones. Signing uses ECDSA P-256 keys with NSEC3 and has no surcharge; the zone lists are @optional values in the unit, and further apex domains can be added at $0.20 per zone per month.

The private zone acme-internal (internal.company.com, private-dns unit, acme-core-network) is attached directly to the hub, prod and nonprod VPC networks, so every stage project resolves it through the Shared VPC without DNS peering. The DNS server policy acme-vpc-dns-logging logs every query of the three networks (enable_dns_query_logging = true in network.hcl, CIS Google Cloud Foundations Benchmark 2.12; billed as Logging ingestion), and the organization sink brings those logs to the central bucket.

Who writes records. Grants are per zone, never project-wide:

Zoneroles/dns.admin on the zone
acme-<stage>that stage's deployer sa-acme-terraform-deployer
acme-internalthe four stage deployers

The Web App Blueprint writes through those identities: its Certificate Manager DNS authorizations and its external-dns records. Listing zones is a project-level permission that zone IAM cannot give, so each external-dns release also holds roles/dns.reader on its host project (acme-core-dns for the public release, acme-core-network for the internal one), for every stage listed in webapp_gke_stages of environments/plat/plat.hcl.

The contract. pm-publish writes each stage's public zone and the private zone, with their projects, as dns--public-zone, dns--public-zone-project, dns--private-zone and dns--private-zone-project.

Terms you will see​

TermMeaning
Apex zoneacme-apex, the zone of the company domain itself.
Stage zoneacme-<stage>, a delegated subdomain such as prod.company.com.
DS recordThe parent's link to a signed child zone's key.
DNS server policyThe network-level setting that logs every private DNS query.
Zone-level IAMA role granted on one zone only.

Where to read more​