Skip to main content
provisioning · gcp

Cloud DNS

category
DNS

What does zop.dev create for Cloud DNS?

zop.dev provisions Cloud DNS managed zones with NS delegation and CAA records applied by default, plus dns_admin and dns_viewer IAM grants. GCP hosts the 1 master zone that AWS Route 53, Azure DNS, and OCI zones all delegate into, making it the root of cross-cloud name resolution.

Module backing Cloud DNS.
Field Value
Cloudgcp

Cloud DNS hosts zop.dev’s master DNS zones and per-environment zones on GCP. zop.dev provisions managed zones with delegation and admin/viewer access baked in.

Managed zone with delegation and CAA records

Managed zone, NS delegation and CAA records, and dns_admin / dns_viewer IAM grants.

Zone name is the only required input

Terminal window
Zone name; delegation and CAA records applied by default.

The dns and dns-record resource types

GCP hosts the master zone that AWS Route 53, Azure DNS, and OCI DNS zones delegate into. The provisioner API adds dns and dns-record resource types.

The zone every other cloud depends on

Cloud DNS plays two roles here. It hosts per-environment zones for GCP workloads, like Route 53 does for AWS. It also hosts the organization’s master zone, into which every other cloud’s zones delegate their NS records. That second role gives one GCP project an outsized blast radius: a deletion or bad edit in the master zone can break name resolution for environments on AWS, Azure, and OCI simultaneously, clouds that otherwise share nothing with it. Whatever protections the organization applies to production infrastructure (restricted access, change review), the master zone’s project deserves the same, regardless of how little else runs there.

Two grants, two audiences

Zones come with dns_admin and dns_viewer IAM grants, splitting the people who change records from the people who need to see them. The viewer grant is the underused one: letting engineers inspect zones during incidents removes the most common reason record-edit access gets handed out too widely. Given the master zone’s blast radius, keeping dns_admin short is one of the cheaper risk reductions available.

Small fees, wide API surface

Cloud DNS bills about 0.20 USD per managed zone per month plus query charges. Cost is not the concern here; correctness is. Zones outliving their environments keep resolving, and stale records pointing at released addresses are takeover material, so teardown includes the zone and its delegation entry in the master zone. Beyond the module’s defaults (delegation and CAA records applied automatically), the provisioner API adds dns and dns-record resource types, so one-off records and zones are manageable through the same machinery rather than by console edits nobody tracks.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·