Troubleshooting
Solutions for common DNS connection issues.
Connection Status: Invalid
Your connection shows Invalid status after validation.
Cause 1: Invalid Credentials
The API token, key, or credentials are incorrect or expired.
Solution:
- Verify credentials in your provider's dashboard
- Check if credentials have expired
- Generate new credentials if needed
- Update credentials in Orkestia connection settings
- Validate the connection again
Cause 2: Insufficient Permissions
The credentials don't have required permissions.
Solution by Provider:
| Provider | Required Permissions |
|---|---|
| Cloudflare | Scoped API token with Zone:Read and DNS:Edit |
| Route 53 | route53:ChangeResourceRecordSets, route53:GetHostedZone, route53:ListHostedZones, route53:ListResourceRecordSets |
| Google Cloud DNS | Service account with roles/dns.admin or dns.managedZones.* permissions |
| Vercel DNS | API token with DNS management permissions |
Cause 3: Provider API Issues
The DNS provider's API is experiencing issues.
Solution:
- Check provider status pages:
- Wait for provider to resolve issues
- Try validating again later
Cloudflare-Specific Issues
API Token Not Working
Symptoms: Validation fails with authentication error
Solutions:
- Verify Token Permissions - Token must have
Zone:ReadandDNS:Edit(the Edit zone DNS template) - Check Token Scope - Ensure token includes all zones or specific zones you need
- Regenerate Token - Create a new API token in Cloudflare and update the connection credentials
No Zones Found
Symptoms: Connection validates but shows 0 zones
Solutions:
- Verify Zones Exist - Check Cloudflare dashboard for zones
- Check Token Permissions - Token must have access to zones
- Refresh Zones - Click "Refresh Zones" in connection details
Route 53-Specific Issues
No AWS Connection Available
Symptoms: Can't select AWS connection in Route 53 setup
Solutions:
- Create AWS Connection First - Go to Connections > AWS
- Check AWS Connection Status - AWS connection must be Active
- Verify Route 53 Permissions - AWS connection must have Route 53 permissions
Zone IDs Not Working
Symptoms: "Invalid zone ID" error
Solutions:
- Verify Zone ID Format - Zone IDs must start with 'Z' (format:
Z1234567890ABC) - Verify Zone Exists - Check Route 53 console
- Check AWS Connection Access - AWS connection must have access to the zones
Zones Not Syncing
Symptoms: Connection validates but zones don't appear
Solutions:
- Check Zone Mode - If using "Specific Zones", verify zone IDs are correct
- Verify Route 53 Permissions - AWS connection needs
route53:ListHostedZones - Check AWS Region - Try different region (default: us-east-1)
- Refresh Zones - Click "Refresh Zones" in connection details
Google Cloud DNS-Specific Issues
Service Account Key Invalid
Symptoms: Validation fails with authentication error
Solutions:
- Verify JSON Format - Ensure key is valid JSON with entire content copied
- Check Service Account Permissions - Must have
roles/dns.admin - Verify Project ID - Project ID must match the service account's project
- Regenerate Key - Create new service account key
Project ID Not Found
Symptoms: "Project not found" error
Solutions:
- Verify Project ID - Use project ID (not project name), format:
my-project-123456 - Check Project Status - Ensure project is active
- Verify Service Account - Service account must be in the same project
Vercel DNS-Specific Issues
API Token Invalid
Symptoms: Validation fails with authentication error
Solutions:
- Verify Token - Check token in Vercel dashboard
- Check Token Permissions - Token must have DNS management permissions
- Regenerate Token - Create new API token in Vercel
Zone Synchronization Issues
Zones Not Appearing
Symptoms: Connection validates but no zones shown
Solutions:
- Wait for Sync - Zones sync after connection creation
- Manual Refresh - Click "Refresh Zones" in connection details
- Verify Zones Exist - Check provider console for zones
- Check Connection Status - Connection must be Active
Zones Out of Sync
Symptoms: Zones list doesn't match provider
Solutions:
- Refresh Zones - Click "Refresh Zones"
- Validate Connection - Zones refresh automatically after validation
- Check Provider - Verify zones exist in provider console
Credential Update Issues
Validation Fails After Update
Symptoms: Credentials updated but validation fails
Solutions:
- Verify New Credentials - Double-check credentials are correct
- Check Provider - Verify provider API is accessible
- Try Different Credentials - Generate new credentials
Quick Reference
| Issue | Likely Cause | Quick Fix |
|---|---|---|
| Invalid status | Wrong credentials | Update credentials |
| No zones | Permissions issue | Check provider permissions |
| Zones not syncing | Connection issue | Refresh zones |
| Route 53 no connection | No AWS connection | Create AWS connection first |
| Cloudflare token fails | Token permissions | Regenerate token with correct permissions |
| Google DNS key invalid | JSON format | Verify JSON is complete |
| Vercel token fails | Token expired | Generate new token |
| Zone IDs invalid | Wrong format | Use format: Z1234567890ABC |
Getting More Help
If you've tried the solutions above and still have issues:
- Check Provider Status - Verify provider APIs are operational
- Review Error Messages - Check connection details for specific errors
- Validate Connection - Try validating the connection again
- Contact Support - Reach out to Orkestia support with:
- Connection UUID
- Provider name
- Error messages
- Steps you've already tried
Provider Status Pages
- Cloudflare: https://www.cloudflarestatus.com/
- AWS: https://status.aws.amazon.com/
- Google Cloud: https://status.cloud.google.com/
- Vercel: https://www.vercel-status.com/
