mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 03:55:21 -04:00
The `tools.ietf.org` site now redirects to `www.rfc-editor.org`. * Update various URLs to the new site. * Make links to `www.rfc-editor.org` consistent. Signed-off-by: SuperQ <superq@gmail.com>
90 lines
2.9 KiB
Groff
90 lines
2.9 KiB
Groff
.\" Generated by Mmark Markdown Processer - mmark.miek.nl
|
|
.TH "COREDNS-AZURE" 7 "October 2026" "CoreDNS" "CoreDNS Plugins"
|
|
|
|
.SH "NAME"
|
|
.PP
|
|
\fIazure\fP - enables serving zone data from Microsoft Azure DNS service.
|
|
|
|
.SH "DESCRIPTION"
|
|
.PP
|
|
The azure plugin is useful for serving zones from Microsoft Azure DNS. The \fIazure\fP plugin supports
|
|
all the DNS records supported by Azure, viz. A, AAAA, CNAME, MX, NS, PTR, SOA, SRV, and TXT
|
|
record types. NS record type is not supported by azure private DNS.
|
|
|
|
.PP
|
|
Zone data is loaded asynchronously after startup and refreshed every minute.
|
|
An unavailable zone or zone-listing error is logged without preventing CoreDNS from
|
|
starting or other configured zones from being updated. Each zone listing,
|
|
including retries and pagination, has a one-minute timeout.
|
|
Configuration and credential initialization errors still prevent startup.
|
|
|
|
.PP
|
|
Until a zone has been successfully loaded, queries for it return SERVFAIL unless
|
|
\fB\fCfallthrough\fR is explicitly configured. Only complete, successful updates replace
|
|
the in-memory zone. Failed updates, including a deleted Azure zone returning an
|
|
error, retain the last successfully loaded data and are retried. Remove the zone
|
|
from the Corefile to stop serving this retained data. Snapshots are not persisted
|
|
across restarts or configuration reloads.
|
|
|
|
.SH "SYNTAX"
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
azure RESOURCE\_GROUP:ZONE... {
|
|
tenant TENANT\_ID
|
|
client CLIENT\_ID
|
|
secret CLIENT\_SECRET
|
|
subscription SUBSCRIPTION\_ID
|
|
environment ENVIRONMENT
|
|
fallthrough [ZONES...]
|
|
access private
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.IP \(bu 4
|
|
\fBRESOURCE_GROUP:ZONE\fP is the resource group to which the hosted zones belongs on Azure,
|
|
and \fBZONE\fP the zone that contains data.
|
|
.IP \(bu 4
|
|
\fBCLIENT_ID\fP and \fBCLIENT_SECRET\fP are the credentials for Azure, and \fB\fCtenant\fR specifies the
|
|
\fBTENANT_ID\fP to be used. \fBSUBSCRIPTION_ID\fP is the subscription ID. All of these are needed
|
|
to access the data in Azure.
|
|
.IP \(bu 4
|
|
\fB\fCenvironment\fR specifies the Azure \fBENVIRONMENT\fP.
|
|
.IP \(bu 4
|
|
\fB\fCfallthrough\fR If zone matches and no record can be generated, pass request to the next plugin.
|
|
If \fBZONES\fP is omitted, then fallthrough happens for all zones for which the plugin is
|
|
authoritative.
|
|
.IP \(bu 4
|
|
\fB\fCaccess\fR specifies if the zone is \fB\fCpublic\fR or \fB\fCprivate\fR. Default is \fB\fCpublic\fR.
|
|
|
|
|
|
.SH "EXAMPLES"
|
|
.PP
|
|
Enable the \fIazure\fP plugin with Azure credentials for private zones \fB\fCexample.org\fR, \fB\fCexample.private\fR:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
example.org {
|
|
azure resource\_group\_foo:example.org resource\_group\_foo:example.private {
|
|
tenant 123abc\-123abc\-123abc\-123abc
|
|
client 123abc\-123abc\-123abc\-234xyz
|
|
subscription 123abc\-123abc\-123abc\-563abc
|
|
secret mysecret
|
|
access private
|
|
}
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.SH "SEE ALSO"
|
|
.PP
|
|
The Azure DNS Overview
|
|
\[la]https://docs.microsoft.com/en-us/azure/dns/dns-overview\[ra].
|
|
|