A company has a multi-VPC architecture for different environments (development, staging, production) within the same AWS Region. Each VPC uses a distinct CIDR block. They need to simplify DNS resolution across these VPCs so that instances in one VPC can resolve private DNS hostnames (e.g., `app.dev.internal`) of instances in another VPC, without relying on IP addresses or complex routing table entries. All VPCs are connected via a Transit Gateway. Which Route 53 feature should be enabled and configured to achieve this seamless private DNS resolution?
- APrivate Hosted Zones associated with all relevant VPCs, along with DNS resolution enabled on the Transit Gateway.
- BPublic Hosted Zones with CNAME records for inter-VPC resolution.
- CRoute 53 Resolver Outbound Endpoints in each VPC to query a central DNS server.
- DVPC DNS resolution through DHCP option sets configured with custom DNS servers.
Show answer & explanationAnswer & explanation
Correct answer: A. Private Hosted Zones associated with all relevant VPCs, along with DNS resolution enabled on the Transit Gateway.
Private Hosted Zones allow you to manage DNS records for resources within your VPCs. By associating a Private Hosted Zone with multiple VPCs and enabling DNS resolution on the Transit Gateway, instances in any associated VPC can resolve hostnames within that private zone, facilitating seamless inter-VPC private DNS resolution without manual configuration on each instance or complex routing.
Why the other options are wrong
- B. Public Hosted Zones are for public internet domains and cannot resolve private VPC hostnames directly between VPCs.
- C. Route 53 Resolver Outbound Endpoints are for querying on-premises DNS servers, not for resolving private hostnames across VPCs within AWS.
- D. While DHCP option sets configure DNS resolvers, using custom DNS servers would require deploying and managing those servers, which is less 'serverless' and scalable than Route 53's built-in features for this use case.
Route 53 Private Hosted Zones for Inter-VPC DNS
A Route 53 Private Hosted Zone can be associated with multiple VPCs, allowing resources in those VPCs to resolve DNS records defined within the zone for internal communication, especially when combined with Transit Gateway DNS support.
- Manages DNS records for private domains within AWS VPCs.
- Can be associated with multiple VPCs, even across accounts.
- Requires VPC DNS resolution and DNS hostnames to be enabled in the VPCs.
Memory trick: Private Hosted Zone: The secret phone book shared among all your cloud neighborhoods.