Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To manage internal DNS names with infrastructure code, enable DNS in the target network, declare a private DNS zone and its network association, add records for your services, then deploy and test from a network that should be able to resolve them. The example below uses Amazon Route 53 and Terraform; the resources and network requirements are provider-specific, not universal Terraform syntax.

What makes an internal hostname resolve?

An internal hostname needs both a DNS record and a private DNS zone that is visible to the client making the query. In Amazon Route 53, a private hosted zone holds DNS information for a domain within the VPCs associated with that zone. It is not a public zone: a query from outside the associated VPCs or a supported hybrid path will not be answered from that private zone.

A record maps a name to a target. For example, an A record can map a service name to an IPv4 address; an AAAA record serves an IPv6 address. AWS uses db.example.com as an example hostname in its private hosted zone documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Deploy a Route 53 private zone in four steps

1. Enable DNS in the VPC

For each VPC that will use the private hosted zone, confirm that both DNS support and DNS hostnames are enabled. AWS identifies both VPC attributes as required for private hosted-zone use. Check the VPC configuration before creating the zone so a successful Terraform deployment does not leave clients without the expected DNS behavior. See AWS’s private hosted zone considerations.

2. Declare the private zone and associate the VPCs

In Terraform, define a Route 53 hosted zone as private and associate it with the VPCs whose clients need to resolve names in that zone. A private zone must remain associated with at least one VPC when managed with the Terraform AWS provider. The Terraform AWS provider documentation describes the zone resource and its association configuration.

Choose one association-management approach for a zone: inline VPC association blocks on the zone or separate zone-association resources. The provider documentation warns against mixing those approaches for the same zone because persistent plan differences can result. Confirm the guidance for the provider version pinned in your configuration.

Before applying, check for an existing private zone with the same namespace already associated with any target VPC. AWS says identical private-zone namespaces cannot both be associated with the same VPC; the conflict can prevent the intended deployment. See AWS’s private hosted zone creation guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Declare records for internal services

Add a record for each hostname clients need. Set the record name, type, and target to match the service and address family: for instance, an A record for an IPv4 address or an AAAA record for an IPv6 address. Keep the record in the private zone so it is returned to clients using that zone through an associated network.

4. Apply the plan and verify from an intended network

  1. Review the Terraform plan and confirm the zone, VPC associations, and records are the intended ones.

  2. Apply the configuration.

  3. Query the hostname from a client in an associated VPC, or through a supported hybrid setup that reaches the private DNS namespace.

    Rank #4
    PUSR TCP232-302 TCP IP to Serial Support DNS DHCP Modbus Gateway Device Server RS232 to Ethernet Converter
    • ARM core, Cortex-M0 solution, equipped with deeply optimized TCP/IP protocol stack. It has low latency and strong scalability, stable and reliable
    • Supports custom webpage function to help users improve brand influence
    • Supports Modbus RTU to Modbus TCP protocol conversion and multi-host polling
    • Supports hardware and software watchdog, automatically restarts when the device goes down.
    • Versatile operation modes: TCP Server, TCP Client, UDP, HTTP client.

A query from an unrelated laptop or public network is not a valid test of the private zone. AWS explains that a query outside the associated VPC context is resolved recursively on the internet rather than answered from the private hosted zone. Run the test where the service’s intended clients will make their queries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Decide which networks need to resolve the name

List the networks and client locations before choosing associations. If only one VPC needs the hostname, associate the zone with that VPC. If clients in multiple VPCs need it, associate each required VPC. For hybrid clients, verify that the DNS query path is supported and reaches the private namespace; merely having network connectivity to a service does not establish that its private-zone record will resolve.

Best Value
WatchGuard Firebox T145 with 1 Year Standard Support - Tabletop Firewall, 2.5Gb, 1Gb & SFP Ports, Enterprise Security for Branch Locations (WGT145000+WGT1450061)
  • Watchguard T145 Firebox with 1 Year Standard Support License (WGT145001) - The Firebox T145 delivers enterprise-grade protection for branch offices and retail sites. With a blend of 2.5Gb, 1Gb, and SFP/SFP+ ports, it supports high throughput, AI-driven malware protection, and DNS filtering for robust network defense.
  • Standard Support covers software updates and round-the-clock emergency help. Add a Basic or Total Security Suite to activate IPS, gateway antivirus, and web filtering so threats are blocked before they reach users.
  • Standard Support provides reliable technical assistance and software updates for WatchGuard Firebox appliances. Offering 24x7 help for emergencies and business-hours support for routine needs, it ensures your network stays secure and operational.
  • Interfaces and deployment: 2.5Gb and 1Gb Ethernet with SFP or SFP+ fiber for clean aggregation and segmented backhaul at the edge.
  • Performance and scale: UTM up to 710 Mbps with inspection on; flexible VPN topologies for hub and spoke or mesh designs.

The relevant design questions are:

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this differs across cloud providers

The four-step idea—enable the provider’s private DNS capability, create a private zone, connect it to the relevant networks, and add records—can guide the workflow, but AWS resource syntax and VPC requirements do not apply to other clouds. Microsoft provides a separate Terraform quickstart for Azure private DNS zones. Consult the chosen provider’s current documentation for its network links, DNS settings, and Terraform resources.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.