Google Cloud

DNS & Traffic Routing — Cloud DNS

Host zones on anycast nameservers and understand why GCP leans on load balancing rather than DNS for failover.

Cloud DNS serves your zones from Google's anycast nameservers, with a 100% availability SLA.

One phone number for the whole company that always connects you to the nearest open office. You never have to be told a different number when one branch closes.

Key Concepts

1
Public and private zones.
    public    resolvable on the internet
    private   resolvable only inside the VPCs you authorise
2
Private zones are how internal naming works without running your own DNS servers, and they are what make Private Service Connect and private Google API access resolve correctly.
3
The record types that matter.
    A / AAAA   name -> address
    CNAME      name -> name. NOT valid at the zone apex.
    ALIAS      not a Cloud DNS type -- GCP solves the apex problem
               differently, by giving the global load balancer a
               single anycast IP you point an A record at
4
That is the key architectural difference. On other clouds you need DNS-level routing to send users to the nearest region. On GCP, the global external load balancer has one anycast IP worldwide, and Google's network routes each user to the closest healthy backend. So the DNS answer is the same everywhere and the routing happens below it.
5
Which means DNS failover is rarely the mechanism.
    other clouds  DNS returns a different address -> capped by TTL
    GCP           same address, backbone routes elsewhere -> seconds
6
Routing policies do exist for cases where you need them — weighted round robin for canary, geolocation for data residency, and failover with health checks — and they are the right tool when endpoints are outside GCP.
7
DNSSEC is a checkbox on a public zone, signing responses so resolvers can detect tampering.
8
TTL is still the lever where DNS does the routing: low means faster change and more queries, high means cheaper and slower. For anything you intend to move, keep it at 60 seconds.
9
Cloud Domains registers the domain, and delegation to Cloud DNS is by NS records as usual.
10
What the interviewer is probing.1. "Why does GCP need less DNS-level routing than other clouds?" Probing: the anycast load balancer. Stalls: "It does not." Moves up: the global load balancer has one anycast IP worldwide and the backbone routes each user to the nearest healthy backend, so failover is not bound by TTL.
11
2. "How do you point a bare domain at a load balancer?" Probing: the apex. Stalls: "A CNAME." Moves up: an A record to the load balancer's anycast IP — CNAME is invalid at the apex.
12
3. "What is a private zone for?" Probing: internal naming. Stalls: "Internal sites." *Moves up:* resolving names inside authorised VPCs, which is what makes Private Service Connect and private Google API access resolve correctly.
13
4. "When would you still use DNS routing policies?" Probing: the remaining use. Stalls: "Never." Moves up: when endpoints are outside GCP, or for geolocation routing to satisfy data residency.