← AWS Solutions Architect Professional: complex decisions
18 / 25 · 75 MIN

Hybrid DNS and authority across accounts

Distinguish query path, name authority, and capacity needed during failure.

Draw direction and resolution context

Route 53 VPC Resolver, formerly Route 53 Resolver, provides inbound and outbound paths. A datacenter resolver queries private AWS names through an inbound endpoint; a VPC application uses rules and an outbound endpoint to query datacenter authorities. Do not forward datacenter queries directly to the VPC+2 address as a substitute for an inbound endpoint. Networking and resolution are separate requirements: a Transit Gateway with correct routes does not automatically associate private zones with every VPC. To answer through an inbound endpoint using a private hosted zone, confirm zone association with that endpoint’s VPC. In the exercise, the name exists in the business VPC but the query arrives at the shared-DNS VPC. Evidence should identify the resolver’s actual context before concluding that a record is missing.

Choose authority before changing records

The most specific match decides between overlapping private zones. If the selected zone lacks the requested name and type, do not assume fallback to the public zone or a less-specific private zone. A forwarding rule associated with the VPC for the same domain as a private hosted zone takes precedence over that zone. In the original example, the fundos.example private zone contains close.fundos.example, but a fundos.example rule forwards the query to the datacenter. The team should review intended authority, not create more copies of the record without understanding the path. System rules allow subdomain exceptions to broader forwarding rules. Draw arrows in both directions to avoid resolvers repeatedly forwarding the same name to each other. Also record query type: an A record does not establish that an AAAA query receives the intended answer.

Test targets, protocols, and failure capacity

An outbound rule with multiple target IPs does not define an ordered primary-and-standby list: target selection is random, and an unresponsive target can cause retries and delay. Confirm reachability of every target from the endpoint. For Do53, include TCP and UDP as required by the configured path rather than concluding that one small UDP response proves every case. Endpoints use IPs in different zones, but redundancy does not prove capacity after losing a zone. In the fictional model, two paths were tested at 5000 queries per second each against total demand of 7000. With only one remaining, demonstrated capacity is short by 2000 queries per second. These values are exercise assumptions, not AWS quotas. Plan degraded-mode rehearsal with latency, error, and capacity criteria as well as normal-operation tests.

Associate, observe, and hand over operations

For direct cross-account private-zone association, the zone account authorizes the VPC and the VPC account performs the association. Authorization does not complete association. Removing the used authorization afterward does not remove the existing association. If Profiles are used, inventory must include that additional mechanism rather than assuming one API lists all configuration. Sharing an outbound rule also indirectly shares its endpoint; confirm association and the rule’s actual path. In query logs, answers supplied from the Resolver cache might not generate another entry. Silence therefore proves neither interface disuse nor zero query volume. Handover includes zone, rule, and endpoint owners, evidence identifying name and type, tests by VPC and source, failure capacity, and criteria for retiring old configuration.

measured_qps_per_path = 5000
demand_qps = 7000
healthy_paths = 2
surviving_paths = 1
normal_capacity_qps = healthy_paths * measured_qps_per_path # 10000
failure_capacity_qps = surviving_paths * measured_qps_per_path # 5000
shortfall_qps = max(0, demand_qps - failure_capacity_qps) # 2000
# Fictional measured capacities, not AWS quotas or a queuing simulation.
IN PRACTICE

A monthly interface at a fictional bank resolves its name through the datacenter. After moving the application, the selected private zone lacks that record. Public testing passes, but the VPC receives NXDOMAIN. The PM requests validation in the actual consumer context before accepting cutover.

Common pitfalls

Reversing inbound and outbound; assuming public fallback; interpreting targets as priority; inferring disuse from missing logs; confusing authorization with association.

Related topics: Transit Gateway and traffic inspection

Take this idea with you

Hybrid DNS is accepted when consumers resolve through intended authority and the path remains functional under agreed failure conditions.

Create account

Reference: Route 53 VPC Resolver overview · SAP-C02

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.