Google Cloud
DNS & Traffic Routing — Cloud DNS
Host zones on anycast nameservers and understand why GCP leans on load balancing rather than DNS for failover.
Cloud DNS serves your zones from Google's anycast nameservers, with a 100% availability SLA.
One phone number for the whole company that always connects you to the nearest open office. You never have to be told a different number when one branch closes.
Key Concepts
1
Public and private zones.
public resolvable on the internet
private resolvable only inside the VPCs you authorise2
Private zones are how internal naming works without running your own DNS servers, and they are what make Private Service Connect and private Google API access resolve correctly.
3
The record types that matter.
A / AAAA name -> address
CNAME name -> name. NOT valid at the zone apex.
ALIAS not a Cloud DNS type -- GCP solves the apex problem
differently, by giving the global load balancer a
single anycast IP you point an A record at4
That is the key architectural difference. On other clouds you need DNS-level routing to send users to the nearest region. On GCP, the global external load balancer has one anycast IP worldwide, and Google's network routes each user to the closest healthy backend. So the DNS answer is the same everywhere and the routing happens below it.
5
Which means DNS failover is rarely the mechanism.
other clouds DNS returns a different address -> capped by TTL
GCP same address, backbone routes elsewhere -> seconds6
Routing policies do exist for cases where you need them — weighted round robin for canary, geolocation for data residency, and failover with health checks — and they are the right tool when endpoints are outside GCP.
7
DNSSEC is a checkbox on a public zone, signing responses so resolvers can detect tampering.
8
TTL is still the lever where DNS does the routing: low means faster change and more queries, high means cheaper and slower. For anything you intend to move, keep it at 60 seconds.
9
Cloud Domains registers the domain, and delegation to Cloud DNS is by NS records as usual.
10
What the interviewer is probing.1. "Why does GCP need less DNS-level routing than other clouds?" Probing: the anycast load
balancer. Stalls: "It does not." Moves up: the global load balancer has one anycast IP worldwide
and the backbone routes each user to the nearest healthy backend, so failover is not bound by TTL.
11
2. "How do you point a bare domain at a load balancer?" Probing: the apex. Stalls: "A
CNAME." Moves up: an A record to the load balancer's anycast IP — CNAME is invalid at the apex.
12
3. "What is a private zone for?" Probing: internal naming. Stalls: "Internal sites." *Moves
up:* resolving names inside authorised VPCs, which is what makes Private Service Connect and private
Google API access resolve correctly.
13
4. "When would you still use DNS routing policies?" Probing: the remaining use. Stalls:
"Never." Moves up: when endpoints are outside GCP, or for geolocation routing to satisfy data
residency.