Creating an inbound DNS connection
Note
You can only create one inbound DNS connection per Virtual Private Cloud cloud network.
To create an inbound DNS connection:
-
In the management console
, navigate to the folder where you want to create an inbound DNS connection. -
Navigate to Cloud DNS.
-
In the left-hand panel, select
Inbound endpoints and click Create endpoint. In the window that opens:-
In the Name field, specify a name for the new DNS connection.
-
Optionally, provide any description in the Description field.
-
Optionally, set labels for the new resource in the Labels field.
-
Optionally, enable Deletion protection to protect the new DNS connection from accidental deletion.
-
Under Network settings, in the Network field, select the Yandex Virtual Private Cloud cloud network in which to create the inbound DNS connection.
-
In the IP address field, select a reserved private IP address for the inbound DNS connection.
The IP address can belong to any of the subnets in the cloud network selected in the previous step.
If you have no reserved private IP address or want to reserve a new one, click Reserve and in the window that opens:
-
In the Name field, enter a name for the IP address.
-
In the Subnet field, select a subnet to reserve the address in.
-
In the Internal IPv4 address field, specify the IP address to reserve.
This IP address must belong to the IP address range of the subnet you selected. You cannot specify IP addresses already used by Yandex Cloud resources.
-
Optionally, enable Deletion protection to protect the address from accidental deletion.
-
Click Create to reserve the address.
-
-
Click Create to create an inbound DNS connection.
-
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
See the CLI command description for creating an inbound DNS connection:
yc dns inbound-endpoint create --help -
Reserve an IP address for the inbound DNS connection in the required subnet:
yc vpc address create \ --name <name_of_address_to_reserve> \ --description '<address_description>' \ --internal-ipv4 subnet=<subnet_ID>,address=<IP_address>Where:
-
--name: Name of the private IP address to reserve. -
--description: Description of the IP address to reserve. This is an optional setting. -
--internal-ipv4: Attribute block for reserving a private IP address:subnet: ID of the subnet the IP address will be reserved in.address: IPv4 address to reserve. This IP address must belong to the IP address range of the subnet you selected. You cannot specify IP addresses already used by Yandex Cloud resources.
Result:
id: fl8not0e596n******** folder_id: b1gt6g8ht345******** created_at: "2026-07-05T13:21:12Z" name: my-address description: inbound endpoint address internal_ipv4_address: address: 192.168.3.3 subnet_id: fl8dmq91iruu******** reserved: true type: INTERNAL ip_version: IPV4Save the ID (
idfield value) of the reserved address to create a DNS connection later.For more information about the
yc vpc address createcommand, see the CLI reference. -
-
Create an inbound DNS connection:
yc dns inbound-endpoint create \ --name <incoming_connection_name> \ --description '<connection_description>' \ --labels <key>=<value>[,<key>=<value>] \ --network-id <network_ID> \ --address-id <address_ID> \ --deletion-protectionWhere:
--name: Name of the new DNS connection.--description: Connection description. This is an optional setting.--labels: List of labels. This is an optional setting. You can specify one or more labels separated by commas in<key1>=<value1>,<key2>=<value2>format.--network-id: ID of the Yandex Virtual Private Cloud network the inbound DNS connection will be created in.--address-id: Previously saved ID of the reserved IP address that will be used for the inbound DNS connection.--deletion-protection: Enables protection of the new inbound DNS connection from accidental deletion. This is an optional setting.
Result:
id: dns80efu32ve******** folder_id: b1gt6g8ht345******** created_at: "2026-07-05T13:32:36.880Z" name: my-inbound-endpoint network_id: enpcfncr6uld******** address: 192.168.3.3 address_id: fl8not0e596n******** status: AVAILABLEFor more information about the
yc dns inbound-endpoint createcommand, see the CLI reference. -
Optionally, after you create an inbound DNS connection, test FQDN resolution through that connection. To do it, run the
digcommand by specifying the IP address of the inbound DNS connection and the FQDN of the resource in Yandex Cloud.Here is an example:
dig @192.168.3.3 my-sample-vm.ru-central1.internalResult:
; <<>> DiG 9.18.39-0ubuntu0.24.04.5-Ubuntu <<>> @192.168.3.3 my-sample-vm.ru-central1.internal ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 26971 ;; flags: qr aa rd ra; MBZ: 0x4; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ; COOKIE: 5628ffd26cc7ebc0 (echoed) ;; QUESTION SECTION: ;my-sample-vm.ru-central1.internal. IN A ;; ANSWER SECTION: my-sample-vm.ru-central1.internal. 600 IN A 192.168.2.22 ;; Query time: 2 msec ;; SERVER: 192.168.3.3#53(192.168.3.3) (UDP) ;; WHEN: Sun Jul 05 13:39:52 UTC 2026 ;; MSG SIZE rcvd: 153
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
-
In the configuration file, specify the properties of the resources you want to create:
resource "yandex_vpc_network" "my_net" {} resource "yandex_vpc_subnet" "subnet1" { network_id = yandex_vpc_network.my_net.id v4_cidr_blocks = ["192.168.3.0/24"] } resource "yandex_vpc_address" "dns_address" { name = "my-address" description = "inbound endpoint address" internal_ipv4_address { subnet_id = yandex_vpc_subnet.subnet1.id address = "192.168.3.3" } deletion_protection = false } resource "yandex_dns_inbound_endpoint" "dns_connection" { name = "my-inbound-endpoint" description = "DNS Inbound Endpoint" network_id = yandex_vpc_network.my_net.id address_id = yandex_vpc_address.dns_address.id deletion_protection = false }Where:
name: Name of the new DNS connection.description: Connection description. This is an optional setting.network_id: ID of the Virtual Private Cloud network the inbound DNS connection will be created in.address_id: ID of the reserved private IP address that will be used for the inbound DNS connection.deletion_protection: Enables protection of the new inbound DNS connection from accidental deletion. This is an optional setting.
-
Create the resources:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
Terraform will create all the required resources. You can check the new resources using the management console
or this CLI command:yc dns inbound-endpoint get <DNS_connection_name> -
To reserve a static IP address, use the create REST API method for the Address resource or the AddressService/Create gRPC API call.
To create an inbound DNS connection, use the create REST API method for the DnsInboundEndpoint resource or the DnsInboundEndpointService/Create gRPC API call.
Useful links
The naming requirements are as follows:
- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.