🏫 The School›🪪 AWS›☎️ धडा 23 — Route 53 routing policies & private zones: हुशार phonebook
🖼️ See the drawing + lab 🏠 Course home 🌿 Branch on GitHub ✏️ View source
🖼️ आकृती आणि labThe drawing + lab पूर्ण पानावर उघडा ↗Open full page ↗

☎️ धडा 23 — Route 53 routing policies & private zones: हुशार phonebook

📍 तुम्ही इथे आहात: 25 पैकी धडा 23 · मागील: lesson-22-nat-gateway · पुढील: lesson-24-waf-shield


📦 या ब्रँचमध्ये काय आहे

धडे 01–23. धडा 16 ने phonebook शिकवली; हा धडा phonebook च्या युक्त्या शिकवतो — ती वेगवेगळ्या फोन करणाऱ्यांना वेगवेगळी उत्तरे कशी देते.

🧒 5 वर्षांच्या मुलाला समजावल्यासारखे

साध्या phonebook मध्ये प्रत्येक नावाला एक आकडा असतो. Route 53 च्या phonebook मध्ये एक receptionist आहे, जी उत्तर देण्याआधी कोण फोन करत आहे आणि काय निरोगी आहे हे पाहते. तिचे सात मूड (routing policies):

आणि बाहेरचा कोणीही वाचू शकत नाही अशी phonebook: private hosted zone 🔒. Campus च्या आत, बाकांना db.school.internal म्हणायचे असते, कार्यालय पुन्हा बांधल्यावर बदलणारा RDS endpoint नाही. Private zone म्हणजे तुमच्या VPC(s) ला जोडलेले phonebook चे पान: आत resolve होते, बाहेर अदृश्य. "बाक दप्तर कार्यालय / cache / एकमेकांना नावाने कसे शोधतात?" हा प्रत्येक प्रश्न इथेच संपतो.

🗺️ आकृती

flowchart LR
    c["🧒 caller"]
    r["☎️ Route 53 receptionist"]
    w["⚖️ weighted: v1 90% / v2 10%"]
    l["🏃 latency: nearest campus"]
    f["🚑 failover: primary ↔ backup<br/>health-checked"]
    p["🔒 private zone (inside VPC)<br/>db.school.internal → RDS"]
    c -->|"1 who is school.com?"| r
    r --> w
    r --> l
    r --> f
    r -.->|"desks only"| p

❓ काय

🤔 का

Blue/green deploys, multi-region मध्ये टिकणे, फक्त-EU data, canary releases, आणि VPC च्या आत service discovery — हे सगळे DNS निर्णय आहेत. Receptionist चे मूड समजणारी team हे एका record बदलाने ship करते; बाकी सगळे proxies बांधतात.

🔧 कसे

# a weighted canary: two records, same name, weights 90 / 10
aws route53 change-resource-record-sets --hosted-zone-id $ZONE --change-batch file://canary.json
# a private zone for the campus
aws route53 create-hosted-zone --name school.internal --caller-reference $(date +%s) \
  --vpc VPCRegion=us-east-1,VPCId=$VPC --hosted-zone-config PrivateZone=true

🧪 करून पाहा (~15 मिनिटे, ~मोफत — private zone चा खर्च ~$0.50/month, नंतर destroy करा)

धडा 13 च्या VPC ला जोडलेला school.internal बनवा, A record db.school.internal → 10.0.101.50 जोडा, मग आतल्या बाकावरून: dig db.school.internal उत्तर देते; तुमच्या laptop वरून ते अस्तित्वातच नाही. हा असमतोल हाच धडा आहे. Zone delete करा.

✅ तपासा — तुम्हाला काय दिसायला हवे

VPC मधल्या बाकावरून dig db.school.internal उत्तर देते; तुमच्या laptop वरून ते NXDOMAIN आहे — हा असमतोलच धडा आहे.

🧹 साफसफाई — चालू ठेवू नका

Private hosted zone (~$0.50/month) आणि कोणतेही health checks delete करा

⚠️ नेहमीच्या चुका

⏭️ पुढे

फोन करणाऱ्यांना आता योग्य campus, पटकन सापडतो. त्यांच्यापैकी काही मित्र नाहीत. धडा 24: WAF & Shield — gate वरचा bouncer.

☎️ Lesson 23 — Route 53 routing policies & private zones: the clever phonebook

📍 You are here: Lesson 23 of 25 · Previous: lesson-22-nat-gateway · Next: lesson-24-waf-shield


📦 What's in this branch

Lessons 01–23. Lesson 16 taught the phonebook; this one teaches the phonebook's tricks — how it answers differently to different callers.

🧒 Explain like I'm 5

A plain phonebook has one number per name. Route 53's phonebook has a receptionist who looks at who's calling and what's healthy before answering. Her seven moods (routing policies):

And the phonebook nobody outside can read: the private hosted zone 🔒. Inside the campus, desks want to say db.school.internal, not an RDS endpoint that changes when you rebuild the office. A private zone is a phonebook page attached to your VPC(s): resolvable inside, invisible outside. Every "how do the desks find the record office / the cache / each other by name?" question ends here.

🗺️ Diagram

flowchart LR
    c["🧒 caller"]
    r["☎️ Route 53 receptionist"]
    w["⚖️ weighted: v1 90% / v2 10%"]
    l["🏃 latency: nearest campus"]
    f["🚑 failover: primary ↔ backup<br/>health-checked"]
    p["🔒 private zone (inside VPC)<br/>db.school.internal → RDS"]
    c -->|"1 who is school.com?"| r
    r --> w
    r --> l
    r --> f
    r -.->|"desks only"| p

❓ What

🤔 Why

Blue/green deploys, multi-region survival, EU-only data, canary releases, and service discovery inside the VPC are all DNS decisions. The team that understands the receptionist's moods ships those with a record change; everyone else builds proxies.

🔧 How

# a weighted canary: two records, same name, weights 90 / 10
aws route53 change-resource-record-sets --hosted-zone-id $ZONE --change-batch file://canary.json
# a private zone for the campus
aws route53 create-hosted-zone --name school.internal --caller-reference $(date +%s) \
  --vpc VPCRegion=us-east-1,VPCId=$VPC --hosted-zone-config PrivateZone=true

🧪 Try it (~15 min, ~free — a private zone costs ~$0.50/month, destroy after)

Create school.internal attached to lesson 13's VPC, add an A record db.school.internal → 10.0.101.50, then from a desk inside: dig db.school.internal answers; from your laptop it doesn't exist. That asymmetry is the lesson. Delete the zone.

✅ Verify — what you should see

from a desk inside the VPC dig db.school.internal answers; from your laptop it is NXDOMAIN — that asymmetry is the lesson.

🧹 Clean up — do not leave running

delete the private hosted zone (~$0.50/month) and any health checks

⚠️ Common mistakes

⏭️ Next

Callers can now find the right campus, fast. Some of them are not friends. Lesson 24: WAF & Shield — the bouncer at the gate.

← Previousnat gatewayNext →waf shield

This page is the lesson's README from the lesson-23-route53-routing branch, shown here so the whole School stays on one site. Code files open on GitHub at the same branch.