Skip site navigation (1)Skip section navigation (2)

  
 
  

home | help
COREDNS-ROUTE53(7)		 CoreDNS Plugins	      COREDNS-ROUTE53(7)

NAME
     route53 - enables serving zone data from AWS route53.

DESCRIPTION
     The route53 plugin is useful for serving zones from resource record sets in
     AWS   route53.   This   plugin   supports	 all  Amazon  Route  53  records
     (https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/ResourceRecord-
     Types.html   <https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/Re-
     sourceRecordTypes.html>).	 The  route53 plugin can be used when CoreDNS is
     deployed on AWS or elsewhere.

SYNTAX
	    route53 [ZONE:HOSTED_ZONE_ID...] {
		aws_access_key [AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY] # Deprecated, uses other authentication methods instead.
		aws_endpoint ENDPOINT
		credentials PROFILE [FILENAME]
		fallthrough [ZONES...]
		refresh DURATION
	    }

     *	 ZONE the name of the domain to be accessed.  When  there  are	multiple
	 zones	with  overlapping  domains  (private  vs.  public  hosted zone),
	 CoreDNS does the lookup in the given order here.  Therefore, for a non-
	 existing resource record, SOA response will be from the rightmost zone.

     *	 HOSTED_ZONE_ID the ID of the hosted zone  that  contains  the	resource
	 record sets to be accessed.

     *	 AWS_ACCESS_KEY_ID  and  AWS_SECRET_ACCESS_KEY the AWS access key ID and
	 secret access key to be used when querying AWS (optional). If they  are
	 not  provided,  CoreDNS tries to access AWS credentials the same way as
	 AWS CLI - environment variables, shared credential file (and optionally
	 shared config file if AWS_SDK_LOAD_CONFIG env is set), and  lastly  EC2
	 Instance  Roles.   Note the usage of aws_access_key has been deprecated
	 and may be removed in future versions.  Instead,  user  can  use  other
	 methods  to  pass  crentials, e.g., with environmental variable AWS_AC-
	 CESS_KEY_ID and AWS_SECRET_ACCESS_KEY, respectively.

     *	 aws_endpoint can be used to control the endpoint to use  when	querying
	 AWS  (optional). ENDPOINT is the URL of the endpoint to use. If this is
	 not provided the default AWS endpoint resolution will occur.

     *	 credentials is used for overriding the shared credentials FILENAME  and
	 the  PROFILE  name for a given zone. PROFILE is the AWS account profile
	 name. Defaults to default. FILENAME is the AWS shared credentials file-
	 name, defaults to ~/.aws/credentials. CoreDNS	will  only  load  shared
	 credentials file and not shared config file (~/.aws/config) by default.
	 Set  AWS_SDK_LOAD_CONFIG  env variable to a truthy value to enable also
	 loading of ~/.aws/config (e.g. if you want to provide assumed IAM  role
	 configuration).  Will	be  ignored  if  static keys are set via aws_ac-
	 cess_key.

     *	 fallthrough If zone matches and no record can be  generated,  pass  re-
	 quest	to  the next plugin.  If ZONES is omitted, then fallthrough hap-
	 pens for all zones for which the plugin is authoritative.  If	specific
	 zones	are  listed  (for  example in-addr.arpa and ip6.arpa), then only
	 queries for those zones will be subject to fallthrough.

     *	 refresh can be used to control how long between record retrievals  from
	 Route	53.  It requires a duration string as a parameter to specify the
	 duration between update cycles. Each update cycle may	result	in  many
	 AWS  API  calls  depending  on how many domains use this plugin and how
	 many records are in each. Adjusting the update frequency may  help  re-
	 duce the potential of API rate-limiting imposed by AWS.

     *	 DURATION  A  duration string. Defaults to 1m. If units are unspecified,
	 seconds are assumed.

EXAMPLES
     Enable route53  with  implicit  AWS  credentials  and  resolve  CNAMEs  via
     10.0.0.1:

	    example.org {
		route53 example.org.:Z1Z2Z3Z4DZ5Z6Z7
	    }

	    . {
		forward . 10.0.0.1
	    }

     Enable route53 with explicit AWS credentials:

	    example.org {
		route53 example.org.:Z1Z2Z3Z4DZ5Z6Z7 {
		  aws_access_key AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY # Deprecated, uses other authentication methods instead.
		}
	    }

     Enable route53 with an explicit AWS endpoint:

	    example.org {
		route53 example.org.:Z1Z2Z3Z4DZ5Z6Z7 {
		  aws_endpoint https://test.us-west-2.amazonaws.com
		}
	    }

     Enable route53 with fallthrough:

	    . {
		route53 example.org.:Z1Z2Z3Z4DZ5Z6Z7 example.gov.:Z654321543245 {
		  fallthrough example.gov.
		}
	    }

     Enable route53 with multiple hosted zones with the same domain:

	    example.org {
		route53 example.org.:Z1Z2Z3Z4DZ5Z6Z7 example.org.:Z93A52145678156
	    }

     Enable route53 and refresh records every 3 minutes

	    example.org {
		route53 example.org.:Z1Z2Z3Z4DZ5Z6Z7 {
		  refresh 3m
		}
	    }

AUTHENTICATION
     Route53   plugin  uses  AWS  Go  SDK  <https://docs.aws.amazon.com/sdk-for-
     go/v1/developer-guide/configuring-sdk.html> for authentication, where there
     is a list of accepted configuration methods.  Note  the  usage  of  aws_ac-
     cess_key  in Corefile has been deprecated and may be removed in future ver-
     sions. Instead, user can use other methods to pass  crentials,  e.g.,  with
     environmental variable AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY, respec-
     tively.

CoreDNS 			   March 2026		      COREDNS-ROUTE53(7)

Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=coredns-route53&sektion=7&manpath=FreeBSD+Ports+15.1.quarterly>

home | help