Skip to content

GCP.DNS reference

Source: src/GCP/DNS/ManagedZone.ts

A Cloud DNS managed zone.

Name, DNS name, and visibility are identity — changing them replaces the zone. Description, labels, query logging, and the private-zone network list update in place.

Generated name (public)

const zone = yield* GCP.DNS.ManagedZone("Public", {
forceDestroy: true,
});

Explicit name, DNS name, and labels

const zone = yield* GCP.DNS.ManagedZone("Public", {
zoneName: "app-public",
dnsName: "app.example.com.",
description: "application public zone",
labels: { env: "prod" },
enableLogging: true,
forceDestroy: true,
});
const zone = yield* GCP.DNS.ManagedZone("Internal", {
dnsName: "internal.example.com.",
visibility: "private",
networks: ["app-vpc"],
forceDestroy: true,
});

Source: src/GCP/DNS/Policy.ts

A Cloud DNS server policy applied to one or more VPC networks.

A policy controls inbound DNS forwarding, outbound forwarding to alternative name servers, query logging, and DNS64. Name is identity — changing it replaces the policy. A VPC network can belong to at most one server policy.

DNS policies have no labels. Alchemy stamps alchemy-stack / alchemy-stage / alchemy-id into the description so list and pnpm nuke:gcp can identify owned policies.

Generated name, logging enabled

const vpc = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const policy = yield* GCP.DNS.Policy("CorpDns", {
enableLogging: true,
networks: [vpc.networkName],
});

Explicit name, inbound forwarding, and description

const policy = yield* GCP.DNS.Policy("CorpDns", {
policyName: "corp-dns",
description: "inbound resolver for on-prem",
enableInboundForwarding: true,
enableLogging: true,
networks: ["app-vpc"],
});
const policy = yield* GCP.DNS.Policy("Forward", {
networks: ["app-vpc"],
alternativeNameServers: [{ ipv4Address: "192.0.2.53" }],
});

Source: src/GCP/DNS/ResourceRecordSet.ts

A Cloud DNS resource record set inside a managed zone.

Identity is (managedZone, name, type). TTL, rrdatas, and routingPolicy are mutable. Record sets have no labels; list / nuke discover them by enumerating managed zones stamped with alchemy-* labels and skipping the zone’s apex SOA/NS records.

A record

const zone = yield* GCP.DNS.ManagedZone("Public", { forceDestroy: true });
const www = yield* GCP.DNS.ResourceRecordSet("Www", {
managedZone: zone.zoneName,
name: "www",
type: "A",
ttl: 300,
rrdatas: ["203.0.113.10"],
});

TXT record

const verify = yield* GCP.DNS.ResourceRecordSet("Verify", {
managedZone: zone.zoneName,
name: zone.dnsName,
type: "TXT",
ttl: 60,
rrdatas: ['"v=spf1 -all"'],
});

Generated subdomain

const record = yield* GCP.DNS.ResourceRecordSet("Probe", {
managedZone: zone.zoneName,
type: "A",
rrdatas: ["203.0.113.20"],
});

Source: src/GCP/DNS/ResponsePolicy.ts

A Cloud DNS response policy applied to one or more VPC networks.

Response policies override DNS answers for selected names (via response policy rules) for VMs in bound networks. Name is identity — changing it replaces the policy. Description, labels, and the network / GKE cluster lists update in place.

ResponsePolicy: Creating a Response Policy

Section titled “ResponsePolicy: Creating a Response Policy”

Generated name bound to a VPC

const vpc = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const policy = yield* GCP.DNS.ResponsePolicy("Overrides", {
networks: [vpc.networkName],
});

Explicit name, description, and labels

const policy = yield* GCP.DNS.ResponsePolicy("Overrides", {
responsePolicyName: "app-overrides",
description: "split-horizon answers",
labels: { env: "prod" },
networks: ["app-vpc"],
});

Source: src/GCP/DNS/ResponsePolicyRule.ts

A Cloud DNS response policy rule.

Identity is (responsePolicy, ruleName). dnsName, localData, and behavior update in place. Rules have no labels; list / nuke discover them by enumerating response policies stamped with alchemy-* labels.

Local A record override

const policy = yield* GCP.DNS.ResponsePolicy("Overrides", {
networks: ["app-vpc"],
});
const rule = yield* GCP.DNS.ResponsePolicyRule("Internal", {
responsePolicy: policy.responsePolicyName,
dnsName: "app.internal.example.com.",
localData: [{ type: "A", ttl: 300, rrdatas: ["10.0.0.10"] }],
});

Bypass the response policy for a name

const passthrough = yield* GCP.DNS.ResponsePolicyRule("Passthrough", {
responsePolicy: policy.responsePolicyName,
dnsName: "cdn.example.com.",
behavior: "bypassResponsePolicy",
});