Amazon Web Services

DNS & Traffic Routing — Route 53

Resolve names to endpoints and shift traffic between regions using routing policies and health checks.

Route 53 is DNS with routing logic and health checking attached.

A telephone switchboard that knows where every caller is ringing from, which offices are open, and how busy each one is — and connects the call accordingly.

Key Concepts

1
The record types worth knowing.
    A / AAAA   name -> IP address
    CNAME      name -> another name. NOT allowed at the zone apex.
    ALIAS      an AWS-specific record that DOES work at the apex,
               points at an ALB, CloudFront or S3 website, and is free
2
The apex problem is a favourite question. example.com cannot be a CNAME — the DNS specification forbids it alongside the SOA and NS records. ALIAS exists to solve exactly that, and it resolves without an extra lookup.
example.com
3
Routing policies are where the real content is.
    simple       one record, one answer
    weighted     split by percentage -- canary and blue/green
    latency      send each user to the lowest-latency region
    failover     primary, and a secondary when health checks fail
    geolocation  route by the user's country -- data residency
    geoproximity shift traffic toward a region by a bias value
    multivalue   several healthy IPs, basic client-side spread
4
Weighted is how you release gradually.
    v1  weight 95
    v2  weight 5     -> move to 50/50, then 0/100, then delete v1
5
Health checks drive failover. Route 53 probes an endpoint from several locations and withdraws the record when it fails, so DNS stops handing out a dead address.
6
TTL decides how fast a change takes effect, and this is the limitation to state plainly:
7
    TTL 300  -> resolvers may serve the old answer for 5 more minutes
8
So DNS failover is minutes, not seconds. For faster failover you want a load balancer or a global accelerator, not DNS.
9
It is also a registrar, so the domain, the zone and the records can live in one place, with the zone delegated via NS records.
10
What the interviewer is probing.1. "Why can you not CNAME the apex, and what do you use instead?" Probing: a standard DNS question. Stalls: "You can." Moves up: the specification forbids a CNAME alongside the SOA and NS records at the apex; an ALIAS record solves it and resolves without an extra lookup.
11
2. "How fast is DNS failover really?" Probing: the TTL limit. Stalls: "Immediate, with health checks." Moves up: bounded by the TTL, because resolvers keep serving the old answer until it expires — minutes, not seconds.
12
3. "Which routing policy for a canary release?" Probing: the policies. Stalls: "Failover." Moves up: weighted — 95/5, then shift the weights, with no deployment change needed.
13
4. "Latency routing picked a region that is not the closest. Why?" Probing: what latency routing measures. Stalls: "It is broken." Moves up: it follows measured network latency, not geographic distance, and the two often differ.