← AWS Solutions Architect Associate: architecture decisions
20 / 20 · 60 MIN

Hybrid DNS, private views, and handover

Trace a query between the datacenter and AWS, diagnose zone conflicts, and prepare operational handover.

Identify who asks the question

Record the client, the resolver it actually uses, the full name, record type, and observed answer. An on-premises query for private AWS names enters through an inbound endpoint. A VPC query for on-premises authority can leave through outbound with a forwarding rule associated with the VPC. Direction refers to the query rather than the final application’s location. Avoid forwarding directly to VPC+2 from another network. This local address does not replace supported endpoints for integration between networks. Draw the query path before changing records.

Design the name views

Create a table for each client population with required names and expected authority. Associating private example.com can change portal.example.com resolution for internal clients even if the intention was only payments.example.com. If the name is absent from the matching private zone, do not expect automatic fallback to public DNS. With overlapping private zones, the more specific one guides lookup. Decide whether the zone should cover the entire domain or a narrower subdomain and document how other names continue to work for every affected client population.

Distinguish rule, zone, and transport

A forwarding rule for the same domain as a private zone takes precedence in that conflict. Among forwarding rules, the most specific matching suffix is selected. Check these relationships and the VPC association before changing records. Then inspect transport: this exercise uses traditional DNS with UDP and TCP on port 53, not DoH. A small successful UDP answer does not establish that the TCP path works. A timeout requires a different investigation from a negative answer consistent with the selected DNS view.

Reuse without losing scope

A central team can share forwarding rules within a Region to reuse the referenced outbound endpoint. Consumer VPCs need the intended associations; sharing a rule does not automatically connect every application. For inbound queries, the private zone must be available in the VPC where the endpoint was created. The inventory should relate each zone, rule, VPC, account, and owner. When evaluating reuse, include volume, shared dependency, change ownership, and observability. This exercise establishes no current quota, price, or guaranteed saving from centralization.

Forty-minute workshop

For the first ten minutes, draw both directions and the Prod and on-premises views. For the next ten, use the previous lesson’s model to predict selection between example.com and apps.example.com, including a missing name. Spend another ten minutes analyzing the endpoint with two IPs but only one configured in the consumer. In the final ten, write acceptance criteria, an authorized failure check, and a rollback plan. Submit the diagram and predicted answers. Completing the local model does not mean AWS failures were executed.

Accept the complete service

Correct resolution of a private IP does not establish that the client can use the application. If TCP/443 times out after the correct DNS answer, investigate routes, filters, and the listener without experimentally publishing the zone. For handover, RUN needs example queries, expected answers, evidence locations, escalation contacts, and observed behavior with one DNS target unavailable. Two console IPs help only if the consumer uses them. Measure recovery in the real rehearsal against the approved requirement rather than promising timings from this exercise.

# Workshop: 40 minutes / Oficina: 40 minutos
# 00-10: Query direction and authority / Direção e autoridade
# 10-20: Predict the local model / Prever o modelo local
# 20-30: Consumer uses one of two IPs / Consumidor usa um de dois IPs
# 30-40: Acceptance, failure drill, rollback / Aceitação, ensaio, reversão
# Deliverable: diagram + expected results / Diagrama + resultados esperados
# No AWS resources or live failures are executed by this guide.
IN PRACTICE

The portal resolves outside the VPC and receives NXDOMAIN inside. The new private zone covers the name but lacks the record.

Common pitfalls

Expecting public fallback; swapping inbound and outbound; missing rule associations; accepting two IPs without testing the consumer.

Related topics: Networks, endpoints, and hybrid connectivity · Resilience, capacity, and recovery · Private access and startup without hidden dependencies

Take this idea with you

Explain the selected view and query path before changing DNS. Then confirm the application works and RUN can operate it.

Create account

Reference: Resolving DNS between VPCs and networks · SAA-C03

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.