Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Cloud DNS
  • Getting started
    • All guides
      • Creating an inbound DNS connection
      • Updating an inbound DNS connection
      • Deleting an inbound DNS connection
  • Access management
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes
  • FAQ
  1. Step-by-step guides
  2. DNS connections
  3. Creating an inbound DNS connection

Creating an inbound DNS connection

Written by
Yandex Cloud
Improved by
Danila N.
Updated at August 11, 2026
View in Markdown

Note

You can only create one inbound DNS connection per Virtual Private Cloud cloud network.

To create an inbound DNS connection:

Management console
CLI
Terraform
API
  1. In the management console, navigate to the folder where you want to create an inbound DNS connection.

  2. Navigate to Cloud DNS.

  3. In the left-hand panel, select  Inbound endpoints and click Create endpoint. In the window that opens:

    1. In the Name field, specify a name for the new DNS connection.

    2. Optionally, provide any description in the Description field.

    3. Optionally, set labels for the new resource in the Labels field.

    4. Optionally, enable Deletion protection to protect the new DNS connection from accidental deletion.

    5. Under Network settings, in the Network field, select the Yandex Virtual Private Cloud cloud network in which to create the inbound DNS connection.

    6. In the IP address field, select a reserved private IP address for the inbound DNS connection.

      The IP address can belong to any of the subnets in the cloud network selected in the previous step.

      If you have no reserved private IP address or want to reserve a new one, click Reserve and in the window that opens:

      1. In the Name field, enter a name for the IP address.

      2. In the Subnet field, select a subnet to reserve the address in.

      3. In the Internal IPv4 address field, specify the IP address to reserve.

        This IP address must belong to the IP address range of the subnet you selected. You cannot specify IP addresses already used by Yandex Cloud resources.

      4. Optionally, enable Deletion protection to protect the address from accidental deletion.

      5. Click Create to reserve the address.

    7. Click Create to create an inbound DNS connection.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. See the CLI command description for creating an inbound DNS connection:

    yc dns inbound-endpoint create --help
    
  2. Reserve an IP address for the inbound DNS connection in the required subnet:

    yc vpc address create \
      --name <name_of_address_to_reserve> \
      --description '<address_description>' \
      --internal-ipv4 subnet=<subnet_ID>,address=<IP_address>
    

    Where:

    • --name: Name of the private IP address to reserve.

    • --description: Description of the IP address to reserve. This is an optional setting.

    • --internal-ipv4: Attribute block for reserving a private IP address:

      • subnet: ID of the subnet the IP address will be reserved in.
      • address: IPv4 address to reserve. This IP address must belong to the IP address range of the subnet you selected. You cannot specify IP addresses already used by Yandex Cloud resources.

    Result:

    id: fl8not0e596n********
    folder_id: b1gt6g8ht345********
    created_at: "2026-07-05T13:21:12Z"
    name: my-address
    description: inbound endpoint address
    internal_ipv4_address:
      address: 192.168.3.3
      subnet_id: fl8dmq91iruu********
    reserved: true
    type: INTERNAL
    ip_version: IPV4
    

    Save the ID (id field value) of the reserved address to create a DNS connection later.

    For more information about the yc vpc address create command, see the CLI reference.

  3. Create an inbound DNS connection:

    yc dns inbound-endpoint create \
      --name <incoming_connection_name> \
      --description '<connection_description>' \
      --labels <key>=<value>[,<key>=<value>] \
      --network-id <network_ID> \
      --address-id <address_ID> \
      --deletion-protection
    

    Where:

    • --name: Name of the new DNS connection.
    • --description: Connection description. This is an optional setting.
    • --labels: List of labels. This is an optional setting. You can specify one or more labels separated by commas in <key1>=<value1>,<key2>=<value2> format.
    • --network-id: ID of the Yandex Virtual Private Cloud network the inbound DNS connection will be created in.
    • --address-id: Previously saved ID of the reserved IP address that will be used for the inbound DNS connection.
    • --deletion-protection: Enables protection of the new inbound DNS connection from accidental deletion. This is an optional setting.

    Result:

    id: dns80efu32ve********
    folder_id: b1gt6g8ht345********
    created_at: "2026-07-05T13:32:36.880Z"
    name: my-inbound-endpoint
    network_id: enpcfncr6uld********
    address: 192.168.3.3
    address_id: fl8not0e596n********
    status: AVAILABLE
    

    For more information about the yc dns inbound-endpoint create command, see the CLI reference.

  4. Optionally, after you create an inbound DNS connection, test FQDN resolution through that connection. To do it, run the dig command by specifying the IP address of the inbound DNS connection and the FQDN of the resource in Yandex Cloud.

    Here is an example:

    dig @192.168.3.3 my-sample-vm.ru-central1.internal
    

    Result:

    ; <<>> DiG 9.18.39-0ubuntu0.24.04.5-Ubuntu <<>> @192.168.3.3 my-sample-vm.ru-central1.internal
    ; (1 server found)
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 26971
    ;; flags: qr aa rd ra; MBZ: 0x4; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
    
    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1232
    ; COOKIE: 5628ffd26cc7ebc0 (echoed)
    ;; QUESTION SECTION:
    ;my-sample-vm.ru-central1.internal. IN A
    
    ;; ANSWER SECTION:
    my-sample-vm.ru-central1.internal. 600 IN A 192.168.2.22
    
    ;; Query time: 2 msec
    ;; SERVER: 192.168.3.3#53(192.168.3.3) (UDP)
    ;; WHEN: Sun Jul 05 13:39:52 UTC 2026
    ;; MSG SIZE  rcvd: 153
    

With Terraform, you can quickly create a cloud infrastructure in Yandex Cloud and manage it using configuration files. These files store the infrastructure description written in HashiCorp Configuration Language (HCL). If you change the configuration files, Terraform automatically detects which part of your configuration is already deployed, and what should be added or removed.

Terraform is distributed under the Business Source License. The Yandex Cloud provider for Terraform is distributed under the MPL-2.0 license.

For more information about the provider resources, see the guides on the Terraform website or its mirror.

If you do not have Terraform yet, install it and configure the Yandex Cloud provider.

To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.

  1. In the configuration file, specify the properties of the resources you want to create:

    resource "yandex_vpc_network" "my_net" {}
    
    resource "yandex_vpc_subnet" "subnet1" {
      network_id     = yandex_vpc_network.my_net.id
      v4_cidr_blocks = ["192.168.3.0/24"]
    }
    
    resource "yandex_vpc_address" "dns_address" {
      name        = "my-address"
      description = "inbound endpoint address"
    
      internal_ipv4_address {
        subnet_id = yandex_vpc_subnet.subnet1.id
        address   = "192.168.3.3"
      }
      deletion_protection = false
    }
    
    resource "yandex_dns_inbound_endpoint" "dns_connection" {
      name        = "my-inbound-endpoint"
      description = "DNS Inbound Endpoint"
    
      network_id  = yandex_vpc_network.my_net.id
      address_id  = yandex_vpc_address.dns_address.id
    
      deletion_protection = false
    }
    

    Where:

    • name: Name of the new DNS connection.
    • description: Connection description. This is an optional setting.
    • network_id: ID of the Virtual Private Cloud network the inbound DNS connection will be created in.
    • address_id: ID of the reserved private IP address that will be used for the inbound DNS connection.
    • deletion_protection: Enables protection of the new inbound DNS connection from accidental deletion. This is an optional setting.
  2. Create the resources:

    1. In the terminal, navigate to the configuration file directory.

    2. Make sure the configuration is correct using this command:

      terraform validate
      

      If the configuration is valid, you will get this message:

      Success! The configuration is valid.
      
    3. Run this command:

      terraform plan
      

      You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.

    4. Apply the configuration changes:

      terraform apply
      
    5. Type yes and press Enter to confirm the changes.

    Terraform will create all the required resources. You can check the new resources using the management console or this CLI command:

    yc dns inbound-endpoint get <DNS_connection_name>
    

To reserve a static IP address, use the create REST API method for the Address resource or the AddressService/Create gRPC API call.

To create an inbound DNS connection, use the create REST API method for the DnsInboundEndpoint resource or the DnsInboundEndpointService/Create gRPC API call.

Useful linksUseful links

  • DNS connections
  • Resolving cloud DNS names in a corporate network

The naming requirements are as follows:

  • Length: between 3 and 63 characters.
  • It can only contain lowercase Latin letters, numbers, and hyphens.
  • It must start with a letter and cannot end with a hyphen.

Was the article helpful?

Previous
Creating a filter
Next
Updating an inbound DNS connection
© 2026 Direct Cursus Technology L.L.C.