This page provides directions for creating, updating, listing, and deleting Cloud DNS managed zones. Before you use this page, familiarize yourself with the Cloud DNS overview and Key terms.
Before you begin
The Cloud DNS API requires that you create a Cloud DNS project and enable the Cloud DNS API.
If you are creating an application that uses the REST API, you must also create an OAuth 2.0 client ID.
- If you don't already have one, sign up for a Google Account.
- Enable the Cloud DNS API in the Google Cloud console. You can choose an existing Compute Engine or App Engine project, or you can create a new project.
- If you need to make requests to the REST API, you need to create an OAuth 2.0 ID. See Setting up OAuth 2.0.
- In the project, note the following information that you need to input in
later steps:
-
The client ID (
xxxxxx.apps.googleusercontent.com). - The project ID that you want to use. You can find the ID at the top of the Overview page in the Google Cloud console. You can also ask your user to provide the project name that they want to use in your app.
-
The client ID (
If you have not run the Google Cloud CLI previously, you must run the following command to specify the project name and authenticate with the Google Cloud console:
gcloud auth login
If you want to run a gcloud command on Google Cloud resources
in another project, specify the --project option for this command and for the
other gcloud commands throughout this page.
Create managed zones
Each managed zone that you create is associated with a Google Cloud project. The following sections describe how to create the type of managed zone that Cloud DNS supports.
Create a public zone
To create a new managed zone, complete the following steps.
Console
In the Google Cloud console, go to the Create a DNS zone page.
For the Zone type, select Public.
Enter a Zone name such as
my-new-zone.Enter a DNS name suffix for the zone using a domain name that you own. All records in the zone share this suffix, for example:
example.com.Under DNSSEC, select Off, On, or Transfer. For more information, see Enable DNSSEC for existing managed zones.
Click Create. The Zone details page is displayed.
gcloud
Run the
dns managed-zones create
command:
gcloud dns managed-zones create NAME \
--description=DESCRIPTION \
--dns-name=DNS_SUFFIX \
--labels=LABELS \
--visibility=public
Replace the following:
NAME: a name for your zoneDESCRIPTION: a description for your zoneDNS_SUFFIX: the DNS suffix for your zone, such asexample.comLABELS: an optional comma-delimited list of key-value pairs such asdept=marketingorproject=project1; for more information, see the SDK documentation
Terraform
API
Send a POST request using the
managedZones.create
method:
POST https://dns.googleapis.com/dns/v1/projects/PROJECT_ID/managedZones
{
"name": "NAME",
"description": "DESCRIPTION",
"dnsName": "DNS_NAME",
"visibility": "public"
}
Replace the following:
PROJECT_ID: the ID of the project where the managed zone is createdNAME: a name for your zoneDESCRIPTION: a description for your zoneDNS_NAME: the DNS suffix for your zone, such asexample.com
Create a private zone
To create a new managed private zone with private DNS records managed by Cloud DNS, complete the following steps. For more information, see Best practices for Cloud DNS private zones.
Console
In the Google Cloud console, go to the Create a DNS zone page.
For the Zone type, select Private.
Enter a Zone name such as
my-new-zone.Enter a DNS name suffix for the private zone. All records in the zone share this suffix, for example:
example.private.Optional: Add a description.
Under Options, select Default (private).
Select the Virtual Private Cloud (VPC) networks to which the private zone must be visible. Only the VPC networks that you select are authorized to query records in the zone.
Click Create.
gcloud
Run the
dns managed-zones create
command:
gcloud dns managed-zones create NAME \
--description=DESCRIPTION \
--dns-name=DNS_SUFFIX \
--networks=VPC_NETWORK_LIST \
--labels=LABELS \
--visibility=private
Replace the following:
NAME: a name for your zoneDESCRIPTION: a description for your zoneDNS_SUFFIX: the DNS suffix for your zone, such asexample.privateVPC_NETWORK_LIST: a comma-delimited list of VPC networks that are authorized to query the zoneLABELS: an optional comma-delimited list of key-value pairs such asdept=marketingorproject=project1; for more information, see the SDK documentation
Terraform
API
Send a POST request using the
managedZones.create method:
POST https://dns.googleapis.com/dns/v1/projects/PROJECT_ID/managedZones
{
"name": "NAME",
"description": "DESCRIPTION",
"dnsName": "DNS_NAME",
"visibility": "private",
"privateVisibilityConfig": {
"kind": "dns#managedZonePrivateVisibilityConfig",
"networks": [
{
"kind": "dns#managedZonePrivateVisibilityConfigNetwork",
"networkUrl": "VPC_NETWORK_1"
},
{
"kind": "dns#managedZonePrivateVisibilityConfigNetwork",
"networkUrl": "VPC_NETWORK_2"
},
....
]
}
}
Replace the following:
PROJECT_ID: the ID of the project where the managed zone is createdNAME: a name for your zoneDESCRIPTION: a description for your zoneDNS_NAME: the DNS suffix for your zone, such asexample.privateVPC_NETWORK_1andVPC_NETWORK_2: URLs for VPC networks in the same project that can query records in this zone. You can add multiple VPC networks as indicated. To determine the URL for a VPC network, use the followinggcloudcommand, replacingVPC_NETWORK_NAMEwith the network's name:gcloud compute networks describe VPC_NETWORK_NAME \ --format="get(selfLink)"
Create a zone with specific IAM permissions
The Identity and Access Management (IAM) permission for individual resource managed zone lets you set up specific read, write, or administrator permissions for different managed zones under the same project.
For instructions about how to create a zone with specific Identity and Access Management (IAM) permissions, see Create a zone with specific IAM permissions.
Create a Service Directory DNS zone
You can create a Service Directory zone that allows your Google Cloud-based services to query your Service Directory namespace through DNS.
For detailed instructions about how to create a Service Directory DNS zone, see Configuring a Service Directory DNS zone.
For instructions about how to use DNS to query your Service Directory, see Querying using DNS.
Create a managed reverse lookup private zone
A managed reverse lookup zone is a private zone with a special attribute that instructs Cloud DNS to perform a PTR lookup against Compute Engine DNS data. You must set up managed reverse lookup zones for Cloud DNS to correctly resolve non-RFC 1918 PTR records for your virtual machine (VM) instances.
For instructions on how to create a new managed reverse lookup private zone, see Create a managed reverse lookup zone.
Create a forwarding zone
Forwarding zones let you target name servers for specific private zones. For instructions on how to create a new managed private forwarding zone, see Create a forwarding zone.
Create a peering zone
DNS peering lets you send requests for records that come from one zone's namespace to another VPC network. For instructions on how to create a peering zone, see Create a peering zone.