Orkestia
Blog
DNS Providers

Setup Methods

Provider-specific setup instructions for Cloudflare, AWS Route 53, Google Cloud DNS, and Vercel DNS.

This guide covers the setup instructions for each DNS provider: Cloudflare, AWS Route 53, Google Cloud DNS, and Vercel DNS.

DNS providers are one slice of Orkestia's connection catalog. Route 53 in particular rides on the same AWS connection as the rest of your AWS workflows — see the workflow reference for the aws.route53.* catalog.

Cloudflare Setup

Connect your Cloudflare account to manage DNS zones and enable proxy/CDN features.

Prerequisites

  • Cloudflare account with at least one zone
  • A scoped API Token with Zone:Read and DNS:Edit permissions

API Token

Orkestia connects to Cloudflare with a scoped API token — never a global API key. Tokens are more secure and provide fine-grained, revocable permissions.

Create API Token in Cloudflare

  1. Log in to Cloudflare Dashboard
  2. Go to My Profile > API Tokens
  3. Click Create Token
  4. Use the Edit zone DNS template, or create a custom token with:
    • Permissions: Zone:Read, DNS:Edit
    • Zone Resources: Include all zones, or specific zones
  5. Click Continue to summary and Create Token
  6. Copy the token immediately - it won't be shown again

Enter Token in Orkestia

  1. In Orkestia, select Cloudflare as your provider
  2. Choose API Token authentication method
  3. Paste your API token in the API Token field
  4. Enter a Connection Name (e.g., "My Cloudflare Account")
  5. Click Create Connection

Cloudflare Features

Once connected:

  • Proxy/CDN - Enable Cloudflare proxy for DNS records
  • DDoS Protection - Automatic DDoS protection
  • SSL/TLS - Built-in SSL certificates
  • Apex Domains - Support for root domain (example.com)

AWS Route 53 Setup

Connect AWS Route 53 using your existing AWS connection.

Prerequisites

  • AWS account with Route 53 hosted zones
  • Existing AWS connection in Orkestia (see AWS Connections)
  • AWS connection with Route 53 permissions:
    • route53:ChangeResourceRecordSets
    • route53:GetHostedZone
    • route53:ListHostedZones
    • route53:ListResourceRecordSets

Verify AWS Connection

  1. Go to Connections > AWS
  2. Verify you have an active AWS connection
  3. If not, create one following the AWS Connections guide
The AWS connection must have Route 53 permissions. If you created it without Route 53, you may need to update the IAM role permissions.

Configure Route 53 Connection

  1. In DNS Connections, click Add Connection
  2. Select AWS Route 53 as your provider
  3. Choose your AWS Connection from the dropdown
  4. Select AWS Region (default: us-east-1)
  5. Configure zone synchronization (see below)
  6. Enter a Connection Name
  7. Click Create Connection

Zone Synchronization Options

Sync All Zones (Recommended)

  • Automatically discovers and syncs all hosted zones
  • Best for most use cases
  • New zones are detected automatically

Specific Zones

  • Manually specify which zone IDs to sync
  • Better for security and performance
  • Zone ID format: Z1234567890ABC (starts with 'Z')

Finding Route 53 Zone IDs

  1. Open AWS Route 53 Console
  2. Go to Hosted zones
  3. Click on a zone
  4. The Hosted zone ID is shown at the top

Route 53 Features

Once connected:

  • Apex Domains - Support for root domain (example.com)
  • ACM Integration - Use AWS Certificate Manager for SSL
  • Zone Configuration - Control which zones are synced
  • AWS Integration - Works seamlessly with other AWS services

Google Cloud DNS Setup

Connect Google Cloud DNS using a service account.

Prerequisites

  • Google Cloud Platform project
  • Service account with DNS admin permissions
  • Service account key (JSON file)

Create Service Account

  1. Open Google Cloud Console
  2. Navigate to IAM & Admin > Service Accounts
  3. Click Create Service Account
  4. Enter a name (e.g., "orkestia-dns")
  5. Click Create and Continue

Grant DNS Permissions

  1. In Grant this service account access to project, add role:
    • Cloud DNS Admin (roles/dns.admin)
  2. Click Continue and Done

Create Service Account Key

  1. Click on the service account you created
  2. Go to Keys tab
  3. Click Add Key > Create new key
  4. Choose JSON format
  5. Click Create - the JSON key file will download

Enter Credentials in Orkestia

  1. In Orkestia, select Google Cloud DNS as your provider
  2. Enter your Project ID
  3. Open the downloaded JSON key file
  4. Copy the entire JSON content
  5. Paste it into the Service Account Key field
  6. Enter a Connection Name
  7. Click Create Connection

Google Cloud DNS Features

Once connected:

  • Apex Domains - Support for root domain (example.com)
  • GCP Integration - Works with other Google Cloud services
  • Service Account Auth - Secure authentication method

Vercel DNS Setup

Connect Vercel DNS using an API token.

Prerequisites

  • Vercel account
  • API token with DNS management permissions

Create API Token

  1. Log in to Vercel Dashboard
  2. Go to Settings > Tokens
  3. Click Create Token
  4. Enter a name (e.g., "Orkestia DNS")
  5. Set expiration (or leave as "No expiration")
  6. Click Create Token
  7. Copy the token immediately - it won't be shown again

Enter Token in Orkestia

  1. In Orkestia, select Vercel DNS as your provider
  2. Paste your API token in the API Token field
  3. Enter a Connection Name
  4. Click Create Connection

Vercel DNS Features

Once connected:

  • Simple Authentication - Single API token
  • Vercel Integration - Works with Vercel deployments

Connection Validation

After creating a connection, Orkestia automatically validates it:

  1. Tests Authentication - Verifies credentials work
  2. Lists Zones - Checks if zones can be accessed
  3. Validates Permissions - Ensures required permissions are present
  4. Syncs Zones - Fetches and caches available zones
ResultStatusMeaning
SuccessActiveConnection is ready to use
FailedInvalidCheck credentials or permissions
PartialPendingSome zones may not be accessible

Provider Comparison

ProviderAuth MethodSetup ComplexityBest For
CloudflareScoped API TokenLowCDN, security features
Route 53AWS ConnectionMediumAWS infrastructure
Google DNSService AccountMediumGCP users
Vercel DNSAPI TokenLowVercel deployments

Security Best Practices

  • Use API Tokens - Prefer tokens over global API keys when available
  • Least Privilege - Grant minimum required permissions
  • Rotate Credentials - Regularly update API tokens and keys
  • Secure Storage - Never share credentials or commit them to code

Next Steps

Managing Connections

View, validate, and manage connections.

Zones and Records

Understand DNS zones and records.

Troubleshooting

Fix common connection issues.