DNS Provider Connections
Connect your DNS providers to Orkestia to manage DNS records, configure custom domains, and automate DNS operations.
What are DNS Provider Connections?
DNS Provider Connections allow Orkestia to manage DNS records in your DNS provider accounts. Instead of manually configuring DNS records, Orkestia can automatically create, update, and manage DNS records for your applications and custom domains.
Benefits
Automated DNS Management
Automatically create and update DNS records for your domains.
Multi-Provider Support
Use Cloudflare, Route 53, Google DNS, Vercel, or other providers.
Custom Domain Support
Easily configure custom domains for your applications.
Secure Credential Storage
Credentials are encrypted and stored securely.
Zone Synchronization
Automatically sync and cache DNS zones for faster access.
Unified Interface
Manage DNS across different providers with a single interface.
Supported Providers
| Provider | Authentication | Best For |
|---|---|---|
| Cloudflare | Scoped API Token | CDN, DDoS protection, proxy features |
| AWS Route 53 | AWS Connection (IAM Role) | AWS infrastructure, existing AWS accounts |
| Google Cloud DNS | Project ID + Service Account Key | Google Cloud Platform users |
| Vercel DNS | API Token | Vercel deployments |
Connection Scopes
Organization-wide (Default)
DNS connections are available to all sites in your organization. This is the recommended approach when you want to use the same DNS provider for all deployments.
Site-specific
Coming SoonSite-specific connections will allow you to connect different DNS providers to individual sites.
How It Works
Connection Statuses
| Status | Description |
|---|---|
| Active | Connection is valid and ready to use |
| Pending | Connection created, awaiting validation |
| Invalid | Validation failed - check credentials or permissions |
| Suspended | Too many validation failures |
| Error | Connection error occurred |
| Disconnected | Connection was disabled |
Provider Capabilities
Cloudflare
- Proxy/CDN support
- Apex domain support
- DDoS protection
- Built-in SSL
AWS Route 53
- Apex domain support
- Integration with AWS services
- ACM certificate support
- Zone configuration (all or specific zones)
Google Cloud DNS
- Apex domain support
- Integration with GCP services
- Service account authentication
Vercel DNS
- Simple API token authentication
- Integration with Vercel deployments
Required Permissions
Cloudflare
- Scoped API Token:
Zone:Read,DNS:Editpermissions (the Cloudflare Edit zone DNS template). Orkestia uses a scoped API token — never a global API key.
AWS Route 53
Requires existing AWS connection with:
route53:ChangeResourceRecordSetsroute53:GetHostedZoneroute53:ListHostedZonesroute53:ListResourceRecordSets
Google Cloud DNS
- Service account with
dns.adminordns.managedZones.*permissions
Vercel DNS
- API token with DNS management permissions
