A DNS Server Policy that Logs, Applies, and Blocks
A Cloud DNS server policy bound to no network resolves for nobody, and query logging is off by default, so nothing records which host resolved which name - the first question in most incidents. Refuses a policy with no networks, logs every query, and can add a response policy that answers listed domains with a sinkhole address before recursion, for every workload on every governed network at once.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "resolver_policy" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-resolver-policy/gcp"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
gcp-resolver-policy
A Cloud DNS server policy that logs what it resolves, applied to the
networks it is meant for, with a response policy that blocks what it
should. Works with Terraform and OpenTofu (>= 1.6), google provider
>= 6.0, < 7.0.
A server policy bound to no network resolves for nobody. Inbound forwarding, alternative name servers and query logging take effect only on the networks listed; a policy with none is fully configured and applied to nothing. Refused.
Query logging is off by default. Without it there is no record of which
host resolved which name - the first question in most incidents. On here;
off needs accept_no_query_logging.
A response policy blocks a domain for every workload at once. Rules
answer listed names with a sinkhole address before recursion, on every
governed network. Optional; created only when blocked_domains or
overridden_records is given.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage