Concept and mechanism
Hybrid resolution needs defined direction and authority. VPC queries for an on-premises namespace use an outbound path and matching rule; inbound serves the opposite direction. Rules and zones can compete. For the same domain, a Resolver forwarding rule takes precedence over an associated private zone. Among overlapping private zones, the most specific is selected; a missing record there does not automatically trigger a search in the broader zone. Keep an inventory of domains, VPC associations, and owners. A namespace can look correct from an external laptop yet fail inside an application because it follows another authority and path.
Guided application
For endpoints, separate private transport from authorization. An endpoint policy does not replace identity or resource policies, and service support varies. High availability also requires actual capacity: creating consumers in several subnets does not automatically distribute a provider’s targets concentrated in one AZ. In automation, check inputs and plan effects rather than syntax alone. For supported paths, Reachability Analyzer can join the pipeline as configuration analysis. Then run representative resolution, connection, and operational tests using the correct identities. Record what passed, what failed, and what remains unobserved. That evidence makes RUN handover concrete and enables repeatable checks after future changes.
The corp.example rule forwards on-premises despite an identically named private zone. Check the rule before editing the wrong record.
Common pitfalls
Inbound for both directions; name treated as unique authority; private endpoint treated as IAM grant.
Related topics: Evidence-led diagnosis · Capacity, cost, and resilience
Test from the actual source using its actual resolver and identity.
Reference: ANS-C01 domain 2 · ANS-C01