Skip to main content

Overview of Private DNS

Private DNS is a service for managing port domain names in Cloud Platform private networks. It allows accessing cloud servers and Managed Kubernetes cluster nodes in private networks using domain names, as well as resolving public domains.

The service cannot be used as a public DNS service. If you need public DNS, use DNS hosting.

Private DNS can also be used for dedicated servers; for details, see the Configure DNS in a dedicated server private network guide.

You can work with the service in the Control Panel, using the API, and via Terraform.

The service supports user roles and types.

Records of Private DNS operations are saved in the audit logs.

How it works

Network resource records are stored in a private DNS zone. You create the zone and records manually. For records of types A and AAAA, you can enable automatic updates by adding the network to the zone. Multiple networks can be added to one zone. If a network is added to a zone, A and AAAA records will be created and updated automatically when ports in the network are created or modified. In the Control Panel, such records are displayed with the Auto label.

For devices in a private network to resolve domain names from private DNS zones, you must connect the network to a DNS resolver. Networks connected to the DNS resolver have access to the records of all private DNS zones within their pool and project. Connecting a network to a DNS resolver does not automatically provide access to servers in another private network by domain name — networks must be connected at L3, for example, via a global router.

For devices in a private network to resolve public domains, the network must be connected to a DNS resolver, and recursor (recursive lookup function) must be enabled for it. The subnet where the device is located must have internet access.

Each network in a pool is served by two DNS resolvers located in the same pool, but on different hardware. When connecting a network to a DNS resolver, two service resolver ports are created in it. If one of the DNS resolvers fails, the other will continue processing requests. In a multi-AZ pool, DNS resolvers are located in different availability zones: if a data center in one availability zone fails completely, the other will continue operating.

The DNS service operates independently of the subnet DHCP settings — DNS resolver IP addresses are not configured on devices automatically, even if DHCP is enabled on the network. When connecting a network to a DNS resolver, the resolver IP addresses must be manually specified in the subnet settings.

Available private DNS record types

AMaps a domain name to a server IP address in an IPv4 network
AAAAMaps a domain name to a server IP address in an IPv6 network
MXPoints to a server for receiving incoming mail for a domain. If a domain has multiple mail servers, an MX record must be created for each server specifying the priority for load balancing
TXTContains any text information to be added to domain settings. For example, it can store a DKIM key for outgoing emails
CNAMEMaps an alias domain to the primary (canonical) domain so that both lead to the primary domain's IP address. A CNAME record cannot be added for a second-level domain. A domain with a CNAME record cannot have other resource records

Limits

Within a single pool in a project, you can:

  • connect up to 10 networks to a private DNS resolver;
  • create up to 100 DNS zones.

The maximum number of DNS records per zone is 1,000.

The processing rate for domain name resolution requests is 5,000 RPS. Single request resolution time:

  • for private domains — no more than 1 ms;
  • for public domains — no more than 1 ms for cached domains.

Pricing

You can create DNS zones and records in them for free.

Connecting a network to a private DNS resolver is billable. For connection prices, see selectel.ru.