AWS basics · Lesson 8 · 35 min

Route 53: names for your cloud

Nobody wants to type web-alb-8803023897.us-east-1.elb.amazonaws.com. Route 53 is AWS's DNS service: it can register domain names, and it answers the world's DNS questions about them. (The name is a joke: DNS uses port 53.) In this lesson www.cht-demo.com goes to your load balancer, and you'll check every step with dig, like in the networking lessons.

You will learn

  • Registrar vs DNS hosting, and what a hosted zone is
  • The NS and SOA records every zone starts with, and delegation
  • Record types: A, AAAA, CNAME, TXT, MX, and Route 53's alias records
  • change-resource-record-sets with JSON change batches: CREATE, UPSERT, DELETE
  • TTLs, and checking your work with dig, host and nslookup

Two different jobs

JobWhat it meansRoute 53 part
RegistrarYou rent the name cht-demo.com for a year (about $14 for a .com). The registrar tells the .com servers which name servers are in charge of itRoute 53 Domains (aws route53domains)
DNS hostingThose name servers hold the records: "www is this address"Hosted zones (aws route53)

The two can be different companies: a name bought elsewhere can still use Route 53 for its records. You just point the registrar at Route 53's name servers. That pointing is called delegation, and if it's wrong, nothing resolves (SERVFAIL), however perfect your records are.

A hosted zone

A hosted zone is the set of records for one domain. It costs $0.50 a month. When you register a domain with Route 53, it creates the zone for you. Every zone starts with two records you don't touch:

aws route53 list-resource-record-sets --hosted-zone-id $ZONE --query 'ResourceRecordSets[].[Name,Type]' --output text
cht-demo.com.	NS
cht-demo.com.	SOA

Notice the dot at the end: cht-demo.com. is the fully qualified name. DNS tools show it that way, and Route 53 adds it for you.

Record types you'll use

TypePoints a name atExample
Aan IPv4 addresstest.cht-demo.com → 203.0.113.10
AAAAan IPv6 address→ 2001:db8::10
CNAMEanother name ("look that up instead"). Not allowed at the bare domainblog.cht-demo.com → www.cht-demo.com
TXTtext, in quotes: domain ownership proofs, email security (SPF)"v=spf1 -all"
MXthe mail servers for the domain, with a priority10 mail.cht-demo.com
Alias (Route 53 only)an AWS resource: load balancer, CloudFront, S3 website. Works at the bare domain, follows the resource's changing IPs, and lookups are freecht-demo.com → web-alb

Changing records: a change batch

Every change is a JSON change batch: a list of actions, applied all together or not at all.

{
  "Changes": [
    {
      "Action": "CREATE",                      # or UPSERT (create or replace), or DELETE
      "ResourceRecordSet": {
        "Name": "test.cht-demo.com",
        "Type": "A",
        "TTL": 300,                            # seconds that others may cache the answer
        "ResourceRecords": [ { "Value": "203.0.113.10" } ]
      }
    }
  ]
}
aws route53 change-resource-record-sets --hosted-zone-id $ZONE --change-batch file://dns/test-a.json
aws route53 get-change --id /change/C0…       # PENDING, then INSYNC: on every AWS name server

An alias record has an AliasTarget instead of TTL and ResourceRecords. It needs the load balancer's DNS name and its canonical hosted zone ID. That's the zone AWS keeps for all load balancers in the region, not your zone:

aws elbv2 describe-load-balancers --names web-alb \
  --query 'LoadBalancers[0].[DNSName,CanonicalHostedZoneId]' --output text

TTL: why changes take time

Resolvers everywhere remember answers for the record's TTL. Change an A record with TTL 3600, and some people keep the old address for up to an hour. Before a planned move, lower the TTL to 60 a day ahead. Move, then raise it again. Alias records to AWS resources use the resource's own short TTL, which is one reason to prefer them.

Ask the source, not the cache

dig @ns-1493.awsdns-58.com www.cht-demo.com asks one of the zone's own name servers directly: no caches, and the aa (authoritative answer) flag in the reply. If that's right and a normal dig is wrong, you're looking at an old cached answer, or at a delegation problem.

Practice: give your site a name 🏷️

The sandbox owns cht-demo.com, registered through Route 53, so its hosted zone already exists. The load balancer web-alb with two healthy servers is running. Templates for the change batches are in ~/dns. On Rocky, dig and host come in the bind-utils package. Ubuntu has them already.

Quick check

1. Why can't you put a CNAME on the bare domain cht-demo.com?

2. Your records look perfect, but every lookup gives SERVFAIL. What do you check?

3. You'll move www to a new IP next week. Its TTL is 86400 (a day). What should you do first?

Finished the missions and the quiz? Mark it done to track your progress.