Appearance
Amazon Route 53 — Theory (Bản gốc slide / Original slide)
1. DNS là gì? (What is DNS?)
- DNS (Domain Name System) = hệ thống dịch tên miền thân thiện với con người thành địa chỉ IP của máy
- Ví dụ:
www.google.com→172.217.18.36 - DNS là xương sống của Internet
- DNS dùng cấu trúc đặt tên phân cấp (hierarchical):
.com→example.com→www.example.com,api.example.com
- DNS (Domain Name System) translates human-friendly hostnames into machine IP addresses
- Example:
www.google.com→172.217.18.36 - DNS is the backbone of the Internet
- DNS uses a hierarchical naming structure:
.com→example.com→www.example.com,api.example.com
2. Thuật ngữ DNS (DNS Terminologies)
- Domain Registrar (nơi đăng ký tên miền): Amazon Route 53, GoDaddy, …
- DNS Records: A, AAAA, CNAME, NS, …
- Zone File: chứa các DNS record
- Name Server: giải quyết (resolve) các truy vấn DNS — Authoritative hoặc Non-Authoritative
- Top Level Domain (TLD):
.com,.us,.in,.gov,.org, … - Second Level Domain (SLD):
amazon.com,google.com, …
Cấu trúc một URL: http://api.www.example.com.
http→ Protocolapi.www→ Sub Domainexample→ SLD.com→ TLD- dấu
.cuối → Root - toàn bộ = FQDN (Fully Qualified Domain Name)
- Domain Registrar: Amazon Route 53, GoDaddy, …
- DNS Records: A, AAAA, CNAME, NS, …
- Zone File: contains the DNS records
- Name Server: resolves DNS queries — Authoritative or Non-Authoritative
- Top Level Domain (TLD):
.com,.us,.in,.gov,.org, … - Second Level Domain (SLD):
amazon.com,google.com, …
URL structure: http://api.www.example.com.
http→ Protocolapi.www→ Sub Domainexample→ SLD.com→ TLD- trailing
.→ Root - the whole thing = FQDN (Fully Qualified Domain Name)
3. DNS hoạt động thế nào? (How DNS Works)
- Trình duyệt muốn truy cập
example.com→ hỏi Local DNS Server (do công ty gán hoặc ISP cấp) - Local DNS Server hỏi Root DNS Server (quản lý bởi ICANN) → trả về NS của TLD
.com - Hỏi TLD DNS Server (
.com, quản lý bởi IANA) → trả về NS của SLDexample.com - Hỏi SLD DNS Server (quản lý bởi Domain Registrar) → trả về IP
9.10.11.12 - Local DNS Server cache kết quả (theo TTL) và trả về cho trình duyệt → trình duyệt kết nối tới Web Server
- Browser wants
example.com→ asks the Local DNS Server (assigned by your company or ISP) - Local DNS Server asks the Root DNS Server (managed by ICANN) → returns the NS for TLD
.com - Asks the TLD DNS Server (
.com, managed by IANA) → returns the NS for SLDexample.com - Asks the SLD DNS Server (managed by the Domain Registrar) → returns the IP
9.10.11.12 - Local DNS Server caches the result (per TTL) and returns it → the browser connects to the Web Server
4. Amazon Route 53 — Tổng quan (Overview)
- Một dịch vụ DNS highly available, scalable, fully managed và Authoritative
- Authoritative = bạn (khách hàng) có thể cập nhật các DNS record
- Route 53 cũng là một Domain Registrar
- Có khả năng kiểm tra sức khỏe (health check) tài nguyên
- Là dịch vụ AWS duy nhất cung cấp SLA 100% availability
- Vì sao tên là "53"? → tham chiếu port DNS truyền thống là 53
- A highly available, scalable, fully managed and Authoritative DNS service
- Authoritative = you (the customer) can update the DNS records
- Route 53 is also a Domain Registrar
- Ability to check the health of your resources
- The only AWS service that provides a 100% availability SLA
- Why "53"? → a reference to the traditional DNS port 53
5. Route 53 — Records & Record Types
Mỗi record định nghĩa cách route traffic cho một domain, gồm:
- Domain/subdomain Name — ví dụ
example.com - Record Type — ví dụ A hoặc AAAA
- Value — ví dụ
12.34.56.78 - Routing Policy — cách Route 53 phản hồi truy vấn
- TTL — thời gian record được cache tại DNS Resolver
Các Record Type cần biết:
- A — map hostname → IPv4
- AAAA — map hostname → IPv6
- CNAME — map hostname → một hostname khác
- Target phải có record A hoặc AAAA
- KHÔNG tạo được CNAME cho top node của namespace (Zone Apex), ví dụ không tạo cho
example.com, nhưng tạo được chowww.example.com
- NS — Name Servers cho Hosted Zone; kiểm soát cách route traffic cho domain
- (Nâng cao) CAA / DS / MX / NAPTR / PTR / SOA / TXT / SPF / SRV
Each record defines how to route traffic for a domain, containing:
- Domain/subdomain Name — e.g.,
example.com - Record Type — e.g., A or AAAA
- Value — e.g.,
12.34.56.78 - Routing Policy — how Route 53 responds to queries
- TTL — how long the record is cached at DNS Resolvers
Record types you must know:
- A — maps a hostname → IPv4
- AAAA — maps a hostname → IPv6
- CNAME — maps a hostname → another hostname
- The target must have an A or AAAA record
- CANNOT be created for the top node of a namespace (Zone Apex), e.g., not for
example.com, but OK forwww.example.com
- NS — Name Servers for the Hosted Zone; controls how traffic is routed for a domain
- (Advanced) CAA / DS / MX / NAPTR / PTR / SOA / TXT / SPF / SRV
6. Route 53 — Hosted Zones (Public vs Private)
- Hosted Zone = một container chứa các record định nghĩa cách route traffic tới một domain và các subdomain của nó
- Public Hosted Zone: chứa record định nghĩa cách route traffic trên Internet (public domain), ví dụ
application1.mypublicdomain.com - Private Hosted Zone: chứa record định nghĩa cách route traffic trong một hoặc nhiều VPC (private domain), ví dụ
application1.company.internal - Chi phí: $0.50/tháng cho mỗi hosted zone
- A Hosted Zone is a container for records that define how to route traffic to a domain and its subdomains
- Public Hosted Zone: records that define how to route traffic on the Internet (public domains), e.g.,
application1.mypublicdomain.com - Private Hosted Zone: records that define how to route traffic within one or more VPCs (private domains), e.g.,
application1.company.internal - Cost: $0.50/month per hosted zone
Đọc sơ đồ:
- Public Hosted Zone (trái): client trên Internet hỏi
example.com?→ Route 53 trả về public IP (54.22.33.44); zone này định tuyến tới các tài nguyên public như S3, CloudFront, EC2 (Public IP), ALB → ai cũng phân giải được - Private Hosted Zone (phải): chỉ hoạt động bên trong VPC; các tên
*.example.internalphân giải ra private IP (ví dụwebappgọiapi.internal→10.0.0.10,apigọidb.internal→10.0.0.35tới RDS) → không truy cập được từ ngoài Internet
Reading the diagram:
- Public Hosted Zone (left): an internet client asks
example.com?→ Route 53 returns a public IP (54.22.33.44); the zone routes to public resources like S3, CloudFront, EC2 (Public IP), ALB → anyone can resolve it - Private Hosted Zone (right): works only inside the VPC;
*.example.internalnames resolve to private IPs (e.g.,webappcallsapi.internal→10.0.0.10,apicallsdb.internal→10.0.0.35to RDS) → not reachable from the public Internet
7. Route 53 — TTL (Time To Live)
- Client cache kết quả DNS trong khoảng TTL của record
- High TTL (ví dụ 24 giờ):
- Ít traffic tới Route 53
- Record có thể bị lỗi thời (outdated)
- Low TTL (ví dụ 60 giây):
- Nhiều traffic tới Route 53 ($$)
- Record ít bị lỗi thời hơn, dễ thay đổi
- Trừ Alias record, TTL là bắt buộc cho mỗi DNS record
💡 Trước khi thay đổi lớn (đổi IP), nên hạ TTL trước để client cập nhật nhanh.
- Clients cache the DNS result for the record's TTL
- High TTL (e.g., 24 hr):
- Less traffic to Route 53
- Records may be outdated
- Low TTL (e.g., 60 sec):
- More traffic to Route 53 ($$)
- Records are outdated for less time, easy to change
- Except for Alias records, TTL is mandatory for each DNS record
💡 Before a big change (IP change), lower the TTL first so clients update quickly.
8. CNAME vs Alias
Các AWS resource (Load Balancer, CloudFront…) expose một hostname của AWS, ví dụ lb1-1234.us-east-2.elb.amazonaws.com, và bạn muốn dùng myapp.mydomain.com.
| CNAME | Alias | |
|---|---|---|
| Trỏ tới | Bất kỳ hostname nào | Một AWS resource |
| Zone Apex (root domain) | ❌ Chỉ non-root (something.mydomain.com) | ✅ Cả root & non-root (mydomain.com) |
| Chi phí | Tính phí query | Miễn phí |
| Health check | Không native | Native health check |
| TTL | Bạn đặt | Không đặt được (AWS tự quản) |
AWS resources (Load Balancer, CloudFront…) expose an AWS hostname, e.g., lb1-1234.us-east-2.elb.amazonaws.com, and you want myapp.mydomain.com.
| CNAME | Alias | |
|---|---|---|
| Points to | Any hostname | An AWS resource |
| Zone Apex (root domain) | ❌ Non-root only (something.mydomain.com) | ✅ Root & non-root (mydomain.com) |
| Cost | Query charged | Free |
| Health check | Not native | Native health check |
| TTL | You set it | Cannot set (AWS-managed) |
9. Route 53 — Alias Records
- Map một hostname tới một AWS resource; là phần mở rộng của DNS
- Tự động nhận biết thay đổi IP của resource
- Khác CNAME, dùng được cho top node (Zone Apex), ví dụ
example.com - Alias record luôn có type A/AAAA cho AWS resource
- Không đặt được TTL
Alias Record Targets (những gì Alias có thể trỏ tới):
- Elastic Load Balancers
- CloudFront Distributions
- API Gateway
- Elastic Beanstalk environments
- S3 Websites
- VPC Interface Endpoints
- Global Accelerator accelerator
- Route 53 record trong cùng hosted zone
⚠️ KHÔNG thể đặt Alias record trỏ tới một EC2 DNS name.
- Maps a hostname to an AWS resource; an extension to DNS
- Automatically recognizes changes in the resource's IPs
- Unlike CNAME, works for the top node (Zone Apex), e.g.,
example.com - Alias records are always type A/AAAA for AWS resources
- You can't set the TTL
Alias Record Targets:
- Elastic Load Balancers
- CloudFront Distributions
- API Gateway
- Elastic Beanstalk environments
- S3 Websites
- VPC Interface Endpoints
- Global Accelerator accelerator
- A Route 53 record in the same hosted zone
⚠️ You cannot set an Alias record for an EC2 DNS name.
10. Route 53 — Routing Policies (Tổng quan)
- Routing Policy định nghĩa cách Route 53 phản hồi các truy vấn DNS
- ⚠️ Đừng nhầm chữ "Routing" ở đây với routing của Load Balancer: DNS không route traffic, nó chỉ trả lời truy vấn DNS
- Route 53 hỗ trợ các routing policy:
- Simple
- Weighted
- Failover
- Latency-based
- Geolocation
- Multi-Value Answer
- Geoproximity (dùng tính năng Route 53 Traffic Flow)
- IP-based
- A Routing Policy defines how Route 53 responds to DNS queries
- ⚠️ Don't confuse "Routing" here with Load Balancer routing: DNS does not route traffic, it only responds to DNS queries
- Route 53 supports these routing policies:
- Simple
- Weighted
- Failover
- Latency-based
- Geolocation
- Multi-Value Answer
- Geoproximity (uses the Route 53 Traffic Flow feature)
- IP-based
11. Routing Policy — Simple
- Thường dùng để route traffic tới một resource duy nhất
- Có thể chỉ định nhiều value trong cùng một record → client chọn ngẫu nhiên một value
- Khi bật Alias, chỉ được chỉ định một AWS resource
- KHÔNG thể gắn với Health Check
- Typically routes traffic to a single resource
- Can specify multiple values in the same record → the client picks one at random
- When Alias is enabled, you can specify only one AWS resource
- CANNOT be associated with Health Checks
12. Routing Policy — Weighted
- Kiểm soát % request đi tới mỗi resource; gán mỗi record một trọng số (weight) tương đối
- Công thức:
traffic(%) = weight của record / tổng weight của tất cả record - Weight không cần cộng bằng 100
- Các record phải cùng name và cùng type
- Có thể gắn với Health Checks
- Use case: load balancing giữa các region, test phiên bản mới của ứng dụng…
- Gán weight = 0 để ngừng gửi traffic tới một resource; nếu tất cả đều 0 thì mọi record được trả về đều nhau
- Controls the % of requests going to each resource; assign each record a relative weight
- Formula:
traffic(%) = weight of a record / sum of all weights - Weights don't need to sum to 100
- Records must have the same name and type
- Can be associated with Health Checks
- Use cases: load balancing between regions, testing new versions of an app…
- Set weight = 0 to stop sending traffic to a resource; if all are 0, records are returned equally
13. Routing Policy — Latency-based
- Route tới resource có độ trễ (latency) thấp nhất so với người dùng
- Rất hữu ích khi latency là ưu tiên
- Latency dựa trên traffic giữa user và các AWS Region
- Ví dụ: user ở Đức có thể được trỏ tới US nếu đó là nơi có latency thấp nhất
- Có thể gắn với Health Checks (có khả năng failover)
- Routes to the resource with the lowest latency relative to the user
- Very helpful when latency is a priority
- Latency is based on traffic between users and AWS Regions
- Example: users in Germany may be directed to the US if that has the lowest latency
- Can be associated with Health Checks (has failover capability)
14. Routing Policy — Failover (Active-Passive)
- Mô hình Active-Passive: có một Primary và một Secondary (Disaster Recovery)
- Health Check trên Primary là BẮT BUỘC
- Khi Primary unhealthy → Route 53 tự động failover, trả về Secondary
- An Active-Passive setup: a Primary and a Secondary (Disaster Recovery)
- A Health Check on the Primary is MANDATORY
- When the Primary is unhealthy → Route 53 fails over and returns the Secondary
15. Routing Policy — Geolocation, Geoproximity, IP-based, Multi-Value
Geolocation:
- Khác với Latency-based! Route dựa trên vị trí của user
- Chỉ định vị trí theo Continent, Country, hoặc US State (nếu chồng lấn, chọn vị trí cụ thể nhất)
- Nên tạo một record "Default" (khi không khớp vị trí nào)
- Use case: localization website, giới hạn phân phối nội dung, load balancing…
- Có thể gắn với Health Checks
Geoproximity:
- Route dựa trên vị trí địa lý của cả user lẫn resource
- Có thể dịch chuyển thêm traffic theo bias đã định nghĩa:
- Mở rộng (1 → 99): nhiều traffic hơn tới resource
- Thu hẹp (-1 → -99): ít traffic hơn
- Resource có thể là AWS (chỉ định Region) hoặc non-AWS (chỉ định Lat/Long)
- Phải dùng Route 53 Traffic Flow
IP-based Routing:
- Route dựa trên địa chỉ IP của client
- Bạn cung cấp danh sách CIDR → endpoint/location (user-IP-to-endpoint mappings)
- Use case: tối ưu hiệu năng, giảm chi phí mạng; ví dụ route user của một ISP cụ thể tới một endpoint riêng
Multi-Value:
- Dùng khi route tới nhiều resource; Route 53 trả về nhiều value
- Có thể gắn Health Checks (chỉ trả về value của resource healthy)
- Trả về tối đa 8 healthy record cho mỗi truy vấn Multi-Value
- Không thay thế được ELB
Geolocation:
- Different from Latency-based! Routes based on user location
- Specify location by Continent, Country, or US State (if overlapping, the most precise wins)
- Should create a "Default" record (when no location matches)
- Use cases: website localization, restrict content distribution, load balancing…
- Can be associated with Health Checks
Geoproximity:
- Routes based on the geographic location of both users and resources
- Can shift more traffic using a defined bias:
- Expand (1 → 99): more traffic to the resource
- Shrink (-1 → -99): less traffic
- Resources can be AWS (specify Region) or non-AWS (specify Lat/Long)
- Must use Route 53 Traffic Flow
IP-based Routing:
- Routes based on the clients' IP addresses
- You provide a list of CIDR → endpoint/location (user-IP-to-endpoint mappings)
- Use cases: optimize performance, reduce network costs; e.g., route a specific ISP's users to a specific endpoint
Multi-Value:
- Used to route to multiple resources; Route 53 returns multiple values
- Can be associated with Health Checks (returns only healthy resources)
- Returns up to 8 healthy records per Multi-Value query
- Not a substitute for an ELB
16. Route 53 — Health Checks
- HTTP Health Checks chỉ dành cho tài nguyên public
- Health Check → Automated DNS Failover, có 3 loại:
- Health check monitor một endpoint (application, server, AWS resource)
- Health check monitor các health check khác (Calculated Health Checks)
- Health check monitor CloudWatch Alarms (full control!) — ví dụ throttle của DynamoDB, alarm trên RDS, custom metrics… (hữu ích cho tài nguyên private)
- Health Checks được tích hợp với CloudWatch metrics
Monitor an Endpoint:
- Khoảng 15 global health checker kiểm tra endpoint
- Healthy/Unhealthy Threshold = 3 (mặc định)
- Interval = 30 giây (có thể đặt 10 giây — tốn phí hơn)
- Protocol hỗ trợ: HTTP, HTTPS, TCP
- Nếu > 18% health checker báo healthy → Route 53 coi là Healthy
- Health check pass chỉ khi endpoint trả về status 2xx / 3xx
- Có thể pass/fail dựa trên text trong 5120 byte đầu của response
- Phải cho phép incoming request từ dải IP của Route 53 Health Checkers trên firewall/router
Calculated Health Checks:
- Kết hợp kết quả của nhiều health check thành một health check (parent)
- Dùng OR, AND, NOT; monitor tối đa 256 child health check
- Chỉ định bao nhiêu child cần pass để parent pass
- Usage: bảo trì website mà không làm fail toàn bộ
Private Hosted Zones:
- Health checker của Route 53 nằm ngoài VPC → không truy cập được endpoint private
- Giải pháp: tạo CloudWatch Metric + CloudWatch Alarm, rồi tạo Health Check giám sát chính alarm đó
- HTTP Health Checks are only for public resources
- Health Check → Automated DNS Failover, in 3 kinds:
- Health checks that monitor an endpoint (application, server, AWS resource)
- Health checks that monitor other health checks (Calculated Health Checks)
- Health checks that monitor CloudWatch Alarms (full control!) — e.g., DynamoDB throttles, RDS alarms, custom metrics… (helpful for private resources)
- Health Checks are integrated with CloudWatch metrics
Monitor an Endpoint:
- About 15 global health checkers check the endpoint
- Healthy/Unhealthy Threshold = 3 (default)
- Interval = 30 sec (can set 10 sec — higher cost)
- Supported protocols: HTTP, HTTPS, TCP
- If > 18% of health checkers report healthy → Route 53 considers it Healthy
- A health check passes only when the endpoint returns 2xx / 3xx status codes
- Can pass/fail based on the text in the first 5120 bytes of the response
- You must allow incoming requests from the Route 53 Health Checkers' IP range on your firewall/router
Calculated Health Checks:
- Combine results of multiple health checks into one (parent)
- Use OR, AND, NOT; monitor up to 256 child health checks
- Specify how many children must pass for the parent to pass
- Usage: perform maintenance without failing all health checks
Private Hosted Zones:
- Route 53 health checkers are outside the VPC → can't reach private endpoints
- Solution: create a CloudWatch Metric + CloudWatch Alarm, then a Health Check that monitors that alarm
17. Domain Registrar vs. DNS Service
- Bạn mua/đăng ký tên miền tại một Domain Registrar (thường trả phí hằng năm) — ví dụ GoDaddy, Amazon Registrar Inc.…
- Domain Registrar thường kèm sẵn một DNS service để quản lý record
- Nhưng bạn có thể dùng một DNS service khác để quản lý record
- Ví dụ: mua domain ở GoDaddy nhưng dùng Route 53 để quản lý DNS record
Dùng registrar bên thứ 3 với Route 53:
- Tạo một Hosted Zone trong Route 53
- Cập nhật NS Records trên trang của registrar bên thứ 3 để trỏ tới Route 53 Name Servers
💡 Domain Registrar ≠ DNS Service — nhưng mọi Domain Registrar thường đi kèm một số tính năng DNS.
- You buy/register a domain at a Domain Registrar (usually annual fees) — e.g., GoDaddy, Amazon Registrar Inc.…
- A Domain Registrar usually includes a DNS service to manage records
- But you can use a different DNS service to manage records
- Example: buy the domain at GoDaddy but use Route 53 to manage DNS records
Using a 3rd-party registrar with Route 53:
- Create a Hosted Zone in Route 53
- Update the NS Records on the 3rd-party registrar's site to use Route 53 Name Servers
💡 Domain Registrar ≠ DNS Service — but every Domain Registrar usually comes with some DNS features.
18. Route 53 — Hybrid DNS
- Mặc định, Route 53 Resolver tự động trả lời truy vấn DNS cho:
- Local domain names của EC2 instance
- Record trong Private Hosted Zones
- Record trong public Name Servers
- Hybrid DNS = giải quyết truy vấn DNS giữa VPC (Route 53 Resolver) và các mạng khác của bạn (các DNS Resolver khác)
- Các "mạng" đó có thể là:
- Chính VPC / VPC được peer (Peered VPC)
- Mạng on-premises (kết nối qua Direct Connect hoặc AWS VPN)
💡 Dùng khi bạn có hạ tầng lai (hybrid): một phần trên AWS, một phần ở data center riêng, và hai bên cần phân giải tên miền của nhau.
- By default, the Route 53 Resolver automatically answers DNS queries for:
- Local domain names of EC2 instances
- Records in Private Hosted Zones
- Records in public Name Servers
- Hybrid DNS = resolving DNS queries between the VPC (Route 53 Resolver) and your other networks (other DNS Resolvers)
- Those "networks" can be:
- The VPC itself / a Peered VPC
- An on-premises network (connected via Direct Connect or AWS VPN)
💡 Used for hybrid infrastructure: part on AWS, part in your own data center, where both sides need to resolve each other's domain names.
19. Route 53 — Resolver Endpoints
- Inbound Endpoint (vào AWS):
- Cho phép các DNS Resolver của bạn (ví dụ ở on-premises) phân giải tên miền của AWS — ví dụ EC2 instance và record trong Private Hosted Zone
- Hướng: on-premises → AWS
- Outbound Endpoint (ra ngoài AWS):
- Route 53 Resolver forward các truy vấn DNS tới DNS Resolver của bạn (ví dụ on-premises), theo các resolver rule
- Hướng: AWS → on-premises
- Cả hai đi qua kết nối VPN hoặc Direct Connect
- Inbound Endpoint (into AWS):
- Lets your DNS Resolvers (e.g., on-premises) resolve AWS domain names — such as EC2 instances and records in Private Hosted Zones
- Direction: on-premises → AWS
- Outbound Endpoint (out of AWS):
- Route 53 Resolver forwards DNS queries to your DNS Resolvers (e.g., on-premises), following resolver rules
- Direction: AWS → on-premises
- Both traverse a VPN or Direct Connect connection