DNS Providers
Setup Methods
Provider-specific setup instructions for Cloudflare, AWS Route 53, Google Cloud DNS, and Vercel DNS.
This guide covers the setup instructions for each DNS provider: Cloudflare, AWS Route 53, Google Cloud DNS, and Vercel DNS.
DNS providers are one slice of Orkestia's connection catalog. Route 53 in particular rides on the same AWS connection as the rest of your AWS workflows — see the workflow reference for the
aws.route53.* catalog.Cloudflare Setup
Connect your Cloudflare account to manage DNS zones and enable proxy/CDN features.
Prerequisites
- Cloudflare account with at least one zone
- A scoped API Token with
Zone:ReadandDNS:Editpermissions
API Token
Orkestia connects to Cloudflare with a scoped API token — never a global API key. Tokens are more secure and provide fine-grained, revocable permissions.
Create API Token in Cloudflare
- Log in to Cloudflare Dashboard
- Go to My Profile > API Tokens
- Click Create Token
- Use the Edit zone DNS template, or create a custom token with:
- Permissions:
Zone:Read,DNS:Edit - Zone Resources: Include all zones, or specific zones
- Permissions:
- Click Continue to summary and Create Token
- Copy the token immediately - it won't be shown again
Enter Token in Orkestia
- In Orkestia, select Cloudflare as your provider
- Choose API Token authentication method
- Paste your API token in the API Token field
- Enter a Connection Name (e.g., "My Cloudflare Account")
- Click Create Connection
Cloudflare Features
Once connected:
- Proxy/CDN - Enable Cloudflare proxy for DNS records
- DDoS Protection - Automatic DDoS protection
- SSL/TLS - Built-in SSL certificates
- Apex Domains - Support for root domain (example.com)
AWS Route 53 Setup
Connect AWS Route 53 using your existing AWS connection.
Prerequisites
- AWS account with Route 53 hosted zones
- Existing AWS connection in Orkestia (see AWS Connections)
- AWS connection with Route 53 permissions:
route53:ChangeResourceRecordSetsroute53:GetHostedZoneroute53:ListHostedZonesroute53:ListResourceRecordSets
Verify AWS Connection
- Go to Connections > AWS
- Verify you have an active AWS connection
- If not, create one following the AWS Connections guide
The AWS connection must have Route 53 permissions. If you created it without Route 53, you may need to update the IAM role permissions.
Configure Route 53 Connection
- In DNS Connections, click Add Connection
- Select AWS Route 53 as your provider
- Choose your AWS Connection from the dropdown
- Select AWS Region (default:
us-east-1) - Configure zone synchronization (see below)
- Enter a Connection Name
- Click Create Connection
Zone Synchronization Options
Sync All Zones (Recommended)
- Automatically discovers and syncs all hosted zones
- Best for most use cases
- New zones are detected automatically
Specific Zones
- Manually specify which zone IDs to sync
- Better for security and performance
- Zone ID format:
Z1234567890ABC(starts with 'Z')
Finding Route 53 Zone IDs
- Open AWS Route 53 Console
- Go to Hosted zones
- Click on a zone
- The Hosted zone ID is shown at the top
Route 53 Features
Once connected:
- Apex Domains - Support for root domain (example.com)
- ACM Integration - Use AWS Certificate Manager for SSL
- Zone Configuration - Control which zones are synced
- AWS Integration - Works seamlessly with other AWS services
Google Cloud DNS Setup
Connect Google Cloud DNS using a service account.
Prerequisites
- Google Cloud Platform project
- Service account with DNS admin permissions
- Service account key (JSON file)
Create Service Account
- Open Google Cloud Console
- Navigate to IAM & Admin > Service Accounts
- Click Create Service Account
- Enter a name (e.g., "orkestia-dns")
- Click Create and Continue
Grant DNS Permissions
- In Grant this service account access to project, add role:
- Cloud DNS Admin (
roles/dns.admin)
- Cloud DNS Admin (
- Click Continue and Done
Create Service Account Key
- Click on the service account you created
- Go to Keys tab
- Click Add Key > Create new key
- Choose JSON format
- Click Create - the JSON key file will download
Enter Credentials in Orkestia
- In Orkestia, select Google Cloud DNS as your provider
- Enter your Project ID
- Open the downloaded JSON key file
- Copy the entire JSON content
- Paste it into the Service Account Key field
- Enter a Connection Name
- Click Create Connection
Google Cloud DNS Features
Once connected:
- Apex Domains - Support for root domain (example.com)
- GCP Integration - Works with other Google Cloud services
- Service Account Auth - Secure authentication method
Vercel DNS Setup
Connect Vercel DNS using an API token.
Prerequisites
- Vercel account
- API token with DNS management permissions
Create API Token
- Log in to Vercel Dashboard
- Go to Settings > Tokens
- Click Create Token
- Enter a name (e.g., "Orkestia DNS")
- Set expiration (or leave as "No expiration")
- Click Create Token
- Copy the token immediately - it won't be shown again
Enter Token in Orkestia
- In Orkestia, select Vercel DNS as your provider
- Paste your API token in the API Token field
- Enter a Connection Name
- Click Create Connection
Vercel DNS Features
Once connected:
- Simple Authentication - Single API token
- Vercel Integration - Works with Vercel deployments
Connection Validation
After creating a connection, Orkestia automatically validates it:
- Tests Authentication - Verifies credentials work
- Lists Zones - Checks if zones can be accessed
- Validates Permissions - Ensures required permissions are present
- Syncs Zones - Fetches and caches available zones
| Result | Status | Meaning |
|---|---|---|
| Success | Active | Connection is ready to use |
| Failed | Invalid | Check credentials or permissions |
| Partial | Pending | Some zones may not be accessible |
Provider Comparison
| Provider | Auth Method | Setup Complexity | Best For |
|---|---|---|---|
| Cloudflare | Scoped API Token | Low | CDN, security features |
| Route 53 | AWS Connection | Medium | AWS infrastructure |
| Google DNS | Service Account | Medium | GCP users |
| Vercel DNS | API Token | Low | Vercel deployments |
Security Best Practices
- Use API Tokens - Prefer tokens over global API keys when available
- Least Privilege - Grant minimum required permissions
- Rotate Credentials - Regularly update API tokens and keys
- Secure Storage - Never share credentials or commit them to code
