AWSLive-testedattested

Route 53 Hosted Zone & Records

A Route 53 hosted zone (public or private via vpc_ids) plus a map-driven set of records, with name normalisation and the alias-vs-rdata distinction resolved and inputs validated.

terraformAWSaws

Compare DNS & Traffic Management across clouds →

Part of: AWS Production Landing Zone

aws-route53vizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o aws-route53-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/aws-route53/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle aws-route53-1.0.0.sigstore.json \
  aws-route53-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "819ec9afe872424a5c7d7c9c95b9f0d3510335ebe22e5645da74237d3403e829  aws-route53-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "route53" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-route53/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/aws-route53/badge)](https://www.iac-bazaar.com/catalog/aws-route53?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [Route 53 Hosted Zone & Records](https://www.iac-bazaar.com/catalog/aws-route53?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "route53" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-route53/aws"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-route53

Route 53 hosted zone (public by default) plus a clean, map-driven set of records. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0. The fiddly bits are handled for you: record names are normalised to the zone (use a relative label, @ for the apex, or a full FQDN), and the alias-vs-rdata distinction is resolved so ttl/records are only sent for standard records and the alias block only for alias targets.

Secure / sensible defaults:

  • Public zone by default; supply vpc_ids to make it a private zone resolvable only inside those VPCs (DNS is inherently public, so there is no "encryption" knob — the meaningful control is public vs. private).
  • force_destroy = false by default so you never silently delete records that were created outside Terraform; the live-test fixture flips it to true for guaranteed teardown.
  • Standalone aws_route53_record resources via for_each (stable addressing, no count churn when the record map changes).
  • Inputs are validated: record type is checked against the allowed set, and each record must set exactly one of records (rdata) or alias.

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/aws >= 6.0, < 7.0

Security notes

  • A public hosted zone is world-readable by design (anyone can query it). Use a private zone (vpc_ids) for internal-only names.
  • Keep force_destroy = false in production to avoid deleting records you did not provision through this module.
  • DNSSEC and query logging are out of scope for this module; enable them separately if your threat model requires signed responses or audit trails.

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs

Related modules

Static validatedLive test pending

aws-route53-health-check

A Route 53 health check over HTTPS with SNI, a search string so the page must render, latency measured, probed from several regions, and the CloudWatch alarm on HealthCheckStatus that sends to your topic on failure and recovery. The metrics live only in us-east-1 and the module refuses any other region; HTTP or TCP probes and a missing topic are accepted by name.

View module
Static validatedLive test pending

aws-dns-firewall

Domain lists, rule group, rules and VPC associations. Fail-open is an availability decision wearing a security name: closed makes a firewall fault a DNS outage, open resolves unfiltered without saying so. The module makes you choose.

View module
Static validatedLive test pending

aws-route53-resolver

Endpoints that carry DNS across the VPC boundary, with a precondition requiring addresses in two different subnets - the part the API does not check, and the reason a zone failure becomes every application failing at once.

View module
Static validatedLive test pending

civo-dns-zone

A Civo DNS zone with every record in one map, each with the TTL Civo requires per record, and the nameservers exported for the registrar. Civo does not sign zones and has no CAA or NS record types; dnssec_available says so, so a domain that needs DNSSEC is sent elsewhere before it is delegated.

View module
Static validatedLive test pending

do-dns-zone

A DigitalOcean domain and its records. Creating the zone does not delegate it: until the registrar's nameservers point here the zone is correct, complete and serving nobody, which looks exactly like a working zone. The domain's ip_address shortcut, which hides an apex A record from your records map, is deliberately not used, and a CNAME at the apex is refused.

View module
Static validatedLive test pending

tencent-dns-zone

A Tencent Cloud DNSPod zone with every record in one map, all on the default resolution line so every resolver gets the same answer, MX priority carried on the record, and the free-grade nameservers exported for the registrar. DNSSEC is not a resource in the provider; dnssec_available says so.

View module