1. Map authority before endpoints
A fictional financial application moved to AWS, but files.corp.bank.test remains in the data center. The design must say who answers for corp.bank.test and who answers for aws.bank.test. Writing “hybrid DNS” on a diagram is insufficient. For each namespace, record consumer origins, authority, forwarding direction, covered VPCs and owner. The exercise aims to make a query terminate at the right authority while retaining environment separation. An application IP and a DNS server IP have different roles; conditional forwarding toward the former does not make the application authoritative.
2. Choose direction and association
For on-premises clients querying a private hosted zone associated with the Resolver VPC, design entry through an inbound endpoint with private connectivity to its IPs. For AWS clients querying local corp.bank.test authority, design an outbound rule with on-premises DNS targets. Associate the rule with consuming VPCs. If Apps-A works and Apps-B does not, check B’s association before duplicating endpoints. An association selects applicable forwarding; it does not create VPN routes, permissions or an available server. Separate these diagnostic steps to avoid changing records when only an association is missing.
3. Trace a loop without generating traffic
Use the table below as a tabletop exercise. The files.corp.bank.test query leaves the VPC context through its corp.bank.test rule. On-premises DNS forwards that same suffix back to the same VPC’s inbound endpoint, where it encounters the rule again. The sequence repeats without reaching local authority. Mark every visited context/namespace pair; a repeated pair reveals a loop in this model. Correct local forwarding toward appropriate authority and repeat the trace. Increasing timeouts or switching UDP to TCP retains the circular dependency. This model does not represent caching, delegation, DNSSEC or every service precedence rule.
4. Diagnose transport and actual source
With outbound forwarding, on-premises DNS observes endpoint source IPs, not necessarily the original application IP. An ACL allowing only the application CIDR can block those queries. Confirm actual source IPs, authorized destinations and return paths before expanding rules. This lesson’s conventional DNS exercises use UDP and TCP on port 53. A successful short UDP query does not prove the TCP path that other responses may require. Actual exercises need authorization, known destinations and recorded outcomes. The local table only identifies the control to review; it neither opens ports nor sends queries.
5. Demonstrate usable redundancy
Two IPs in different AZs are insufficient when the source can reach only one. For an inbound endpoint, verify that authorized origins reach both IPs and that the on-premises forwarder can use the alternative. For outbound, AWS describes random selection among DNS targets; list position does not establish a fixed primary/secondary relationship. In the batch case, 10.30.1.10 responds while 10.30.2.10 is blocked. Fix that path and exercise both targets. Do not infer a 50% failure rate merely from two targets: retries, timing and observed behavior need measurement.
6. Prepare handover with bounded evidence
Give RUN a map of namespaces, associations, endpoints, paths, owners and positive and negative checks. Include the response when only one target answers and who may approve a temporary redundancy exception. In the workshop, explain the loop’s cause, configuration to review and expected corrected result. In operations, collect evidence from the actual source and confirm both resolution and application function. A resolved name does not prove batch completion. The technical manager’s summary should distinguish reviewed models, exercised connectivity and observed functional outcomes, retaining identified gaps rather than converting them into guarantees.
namespace: corp.bank.test
VPC -> OUTBOUND -> ONPREM -> INBOUND -> VPC [cycle]
VPC -> OUTBOUND -> ONPREM -> AUTHORITY [terminates]The VPC→OUTBOUND→ONPREM→INBOUND→VPC model repeats a context; ONPREM→AUTHORITY terminates it. It does not execute AWS.
Common pitfalls
Target order as priority; association as connectivity; two interfaces as proven failover; resolution as batch completion.
Related topics: Transit Gateway and return paths · Evidence-led diagnosis
Identify authority, direction, association, actual source and path before changing DNS.
Reference: VPC Resolver outbound forwarding · ANS-C01