GCP.DNS reference
ManagedZone
Section titled “ManagedZone”Source:
src/GCP/DNS/ManagedZone.ts
A Cloud DNS managed zone.
Name, DNS name, and visibility are identity — changing them replaces the zone. Description, labels, query logging, and the private-zone network list update in place.
ManagedZone: Creating a Zone
Section titled “ManagedZone: Creating a Zone”Generated name (public)
const zone = yield* GCP.DNS.ManagedZone("Public", { forceDestroy: true,});Explicit name, DNS name, and labels
const zone = yield* GCP.DNS.ManagedZone("Public", { zoneName: "app-public", dnsName: "app.example.com.", description: "application public zone", labels: { env: "prod" }, enableLogging: true, forceDestroy: true,});ManagedZone: Private Zone
Section titled “ManagedZone: Private Zone”const zone = yield* GCP.DNS.ManagedZone("Internal", { dnsName: "internal.example.com.", visibility: "private", networks: ["app-vpc"], forceDestroy: true,});Policy
Section titled “Policy”Source:
src/GCP/DNS/Policy.ts
A Cloud DNS server policy applied to one or more VPC networks.
A policy controls inbound DNS forwarding, outbound forwarding to alternative name servers, query logging, and DNS64. Name is identity — changing it replaces the policy. A VPC network can belong to at most one server policy.
DNS policies have no labels. Alchemy stamps
alchemy-stack / alchemy-stage / alchemy-id into the description
so list and pnpm nuke:gcp can identify owned policies.
Policy: Creating a Policy
Section titled “Policy: Creating a Policy”Generated name, logging enabled
const vpc = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const policy = yield* GCP.DNS.Policy("CorpDns", { enableLogging: true, networks: [vpc.networkName],});Explicit name, inbound forwarding, and description
const policy = yield* GCP.DNS.Policy("CorpDns", { policyName: "corp-dns", description: "inbound resolver for on-prem", enableInboundForwarding: true, enableLogging: true, networks: ["app-vpc"],});Policy: Outbound Forwarding
Section titled “Policy: Outbound Forwarding”const policy = yield* GCP.DNS.Policy("Forward", { networks: ["app-vpc"], alternativeNameServers: [{ ipv4Address: "192.0.2.53" }],});ResourceRecordSet
Section titled “ResourceRecordSet”Source:
src/GCP/DNS/ResourceRecordSet.ts
A Cloud DNS resource record set inside a managed zone.
Identity is (managedZone, name, type). TTL, rrdatas, and
routingPolicy are mutable. Record sets have no labels; list / nuke
discover them by enumerating managed zones stamped with alchemy-*
labels and skipping the zone’s apex SOA/NS records.
ResourceRecordSet: Creating a Record Set
Section titled “ResourceRecordSet: Creating a Record Set”A record
const zone = yield* GCP.DNS.ManagedZone("Public", { forceDestroy: true });const www = yield* GCP.DNS.ResourceRecordSet("Www", { managedZone: zone.zoneName, name: "www", type: "A", ttl: 300, rrdatas: ["203.0.113.10"],});TXT record
const verify = yield* GCP.DNS.ResourceRecordSet("Verify", { managedZone: zone.zoneName, name: zone.dnsName, type: "TXT", ttl: 60, rrdatas: ['"v=spf1 -all"'],});Generated subdomain
const record = yield* GCP.DNS.ResourceRecordSet("Probe", { managedZone: zone.zoneName, type: "A", rrdatas: ["203.0.113.20"],});ResponsePolicy
Section titled “ResponsePolicy”Source:
src/GCP/DNS/ResponsePolicy.ts
A Cloud DNS response policy applied to one or more VPC networks.
Response policies override DNS answers for selected names (via response policy rules) for VMs in bound networks. Name is identity — changing it replaces the policy. Description, labels, and the network / GKE cluster lists update in place.
ResponsePolicy: Creating a Response Policy
Section titled “ResponsePolicy: Creating a Response Policy”Generated name bound to a VPC
const vpc = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const policy = yield* GCP.DNS.ResponsePolicy("Overrides", { networks: [vpc.networkName],});Explicit name, description, and labels
const policy = yield* GCP.DNS.ResponsePolicy("Overrides", { responsePolicyName: "app-overrides", description: "split-horizon answers", labels: { env: "prod" }, networks: ["app-vpc"],});ResponsePolicyRule
Section titled “ResponsePolicyRule”Source:
src/GCP/DNS/ResponsePolicyRule.ts
A Cloud DNS response policy rule.
Identity is (responsePolicy, ruleName). dnsName, localData, and
behavior update in place. Rules have no labels; list / nuke
discover them by enumerating response policies stamped with
alchemy-* labels.
ResponsePolicyRule: Creating a Rule
Section titled “ResponsePolicyRule: Creating a Rule”Local A record override
const policy = yield* GCP.DNS.ResponsePolicy("Overrides", { networks: ["app-vpc"],});const rule = yield* GCP.DNS.ResponsePolicyRule("Internal", { responsePolicy: policy.responsePolicyName, dnsName: "app.internal.example.com.", localData: [{ type: "A", ttl: 300, rrdatas: ["10.0.0.10"] }],});Bypass the response policy for a name
const passthrough = yield* GCP.DNS.ResponsePolicyRule("Passthrough", { responsePolicy: policy.responsePolicyName, dnsName: "cdn.example.com.", behavior: "bypassResponsePolicy",});