Identify who asks the question
Record the client, the resolver it actually uses, the full name, record type, and observed answer. An on-premises query for private AWS names enters through an inbound endpoint. A VPC query for on-premises authority can leave through outbound with a forwarding rule associated with the VPC. Direction refers to the query rather than the final application’s location. Avoid forwarding directly to VPC+2 from another network. This local address does not replace supported endpoints for integration between networks. Draw the query path before changing records.
Design the name views
Create a table for each client population with required names and expected authority. Associating private example.com can change portal.example.com resolution for internal clients even if the intention was only payments.example.com. If the name is absent from the matching private zone, do not expect automatic fallback to public DNS. With overlapping private zones, the more specific one guides lookup. Decide whether the zone should cover the entire domain or a narrower subdomain and document how other names continue to work for every affected client population.
Distinguish rule, zone, and transport
A forwarding rule for the same domain as a private zone takes precedence in that conflict. Among forwarding rules, the most specific matching suffix is selected. Check these relationships and the VPC association before changing records. Then inspect transport: this exercise uses traditional DNS with UDP and TCP on port 53, not DoH. A small successful UDP answer does not establish that the TCP path works. A timeout requires a different investigation from a negative answer consistent with the selected DNS view.
Reuse without losing scope
A central team can share forwarding rules within a Region to reuse the referenced outbound endpoint. Consumer VPCs need the intended associations; sharing a rule does not automatically connect every application. For inbound queries, the private zone must be available in the VPC where the endpoint was created. The inventory should relate each zone, rule, VPC, account, and owner. When evaluating reuse, include volume, shared dependency, change ownership, and observability. This exercise establishes no current quota, price, or guaranteed saving from centralization.
Forty-minute workshop
For the first ten minutes, draw both directions and the Prod and on-premises views. For the next ten, use the previous lesson’s model to predict selection between example.com and apps.example.com, including a missing name. Spend another ten minutes analyzing the endpoint with two IPs but only one configured in the consumer. In the final ten, write acceptance criteria, an authorized failure check, and a rollback plan. Submit the diagram and predicted answers. Completing the local model does not mean AWS failures were executed.
Accept the complete service
Correct resolution of a private IP does not establish that the client can use the application. If TCP/443 times out after the correct DNS answer, investigate routes, filters, and the listener without experimentally publishing the zone. For handover, RUN needs example queries, expected answers, evidence locations, escalation contacts, and observed behavior with one DNS target unavailable. Two console IPs help only if the consumer uses them. Measure recovery in the real rehearsal against the approved requirement rather than promising timings from this exercise.
# Workshop: 40 minutes / Oficina: 40 minutos
# 00-10: Query direction and authority / Direção e autoridade
# 10-20: Predict the local model / Prever o modelo local
# 20-30: Consumer uses one of two IPs / Consumidor usa um de dois IPs
# 30-40: Acceptance, failure drill, rollback / Aceitação, ensaio, reversão
# Deliverable: diagram + expected results / Diagrama + resultados esperados
# No AWS resources or live failures are executed by this guide.
The portal resolves outside the VPC and receives NXDOMAIN inside. The new private zone covers the name but lacks the record.
Common pitfalls
Expecting public fallback; swapping inbound and outbound; missing rule associations; accepting two IPs without testing the consumer.
Related topics: Networks, endpoints, and hybrid connectivity · Resilience, capacity, and recovery · Private access and startup without hidden dependencies
Explain the selected view and query path before changing DNS. Then confirm the application works and RUN can operate it.
Reference: Resolving DNS between VPCs and networks · SAA-C03