zones
Creates, updates, deletes, gets or lists a zones resource.
Overview​
| Name | zones |
| Type | Resource |
| Id | oci.dns.zones |
Fields​
The following fields are returned by SELECT queries:
- get
- list
A response containing a single zone object.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the zone. |
name | string | The name of the zone. |
compartmentId | string | The OCID of the compartment containing the zone. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
dnssecConfig | object | DNSSEC configuration data. A zone may have a maximum of 10 DnssecKeyVersions, regardless of signing key type. |
dnssecState | string | The state of DNSSEC on the zone. For DNSSEC to function, every parent zone in the DNS tree up to the top-level domain (or an independent trust anchor) must also have DNSSEC correctly set up. After enabling DNSSEC, you must add a DS record to the zone's parent zone containing the KskDnssecKeyVersion data. You can find the DS data in the dsData attribute of the KskDnssecKeyVersion. Then, use the PromoteZoneDnssecKeyVersion operation to promote the KskDnssecKeyVersion. New KskDnssecKeyVersions are generated annually, a week before the existing KskDnssecKeyVersion's expiration. To rollover a KskDnssecKeyVersion, you must replace the parent zone's DS record containing the old KskDnssecKeyVersion data with the data from the new KskDnssecKeyVersion. To remove the old DS record without causing service disruption, wait until the old DS record's TTL has expired, and the new DS record has propagated. After the DS replacement has been completed, then the PromoteZoneDnssecKeyVersion operation must be called. Metrics are emitted in the oci_dns namespace daily for each KskDnssecKeyVersion indicating how many days are left until expiration. We recommend that you set up alarms and notifications for KskDnssecKeyVersion expiration so that the necessary parent zone updates can be made and the PromoteZoneDnssecKeyVersion operation can be called. Enabling DNSSEC results in additional records in DNS responses which increases their size and can cause higher response latency. For more information, see [DNSSEC](/iaas/Content/DNS/Concepts/dnssec.htm). (ENABLED, DISABLED) (default: DISABLED, x-obmcs-top-level-enum: #/definitions/ZoneDnssecState) |
externalDownstreams | array | External secondary servers for the zone. This field is currently not supported when zoneType is SECONDARY or scope is PRIVATE. |
externalMasters | array | External master servers for the zone. externalMasters becomes a required parameter when the zoneType value is SECONDARY. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
isProtected | boolean | A Boolean flag indicating whether or not parts of the resource are unable to be explicitly managed. |
lifecycleState | string | The current state of the zone resource. (ACTIVE, CREATING, DELETED, DELETING, FAILED, UPDATING) |
nameservers | array | The authoritative nameservers for the zone. |
resolutionMode | string | The resolution mode of a zone defines behavior related to how query responses can be handled. See [Private DNS Zone Transparency](/Content/DNS/Tasks/privatedns.htm#use-cases__resolution) for more information. (STATIC, TRANSPARENT, RTYPE_TRANSPARENT) (default: STATIC, x-obmcs-top-level-enum: #/definitions/ZoneResolutionMode) |
scope | string | The scope of the zone. (GLOBAL, PRIVATE) (x-obmcs-top-level-enum: #/definitions/Scope) |
self | string (url) | The canonical absolute URL of the resource. |
serial | integer (int64) | The current serial of the zone. As seen in the zone's SOA record. |
timeCreated | string (date-time) | The date and time the resource was created in "YYYY-MM-ddThh:mm:ssZ" format with a Z offset, as defined by RFC 3339. Example: 2016-07-22T17:23:59:60Z |
version | string | Version is the never-repeating, totally-orderable, version of the zone, from which the serial field of the zone's SOA record is derived. |
viewId | string | The OCID of the private view containing the zone. This value will be null for zones in the global DNS, which are publicly resolvable and not part of a private view. |
zoneTransferServers | array | The OCI nameservers that transfer the zone data with external nameservers. |
zoneType | string | The type of the zone. Must be either PRIMARY or SECONDARY. SECONDARY is only supported for GLOBAL zones. (PRIMARY, SECONDARY) |
A DNS zone.<br /><br />Warning: Oracle recommends that you avoid using any confidential information when you supply string values using the API.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the zone. |
name | string | The name of the zone. |
compartmentId | string | The OCID of the compartment containing the zone. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
dnssecConfig | object | DNSSEC configuration data. A zone may have a maximum of 10 DnssecKeyVersions, regardless of signing key type. |
dnssecState | string | The state of DNSSEC on the zone. For DNSSEC to function, every parent zone in the DNS tree up to the top-level domain (or an independent trust anchor) must also have DNSSEC correctly set up. After enabling DNSSEC, you must add a DS record to the zone's parent zone containing the KskDnssecKeyVersion data. You can find the DS data in the dsData attribute of the KskDnssecKeyVersion. Then, use the PromoteZoneDnssecKeyVersion operation to promote the KskDnssecKeyVersion. New KskDnssecKeyVersions are generated annually, a week before the existing KskDnssecKeyVersion's expiration. To rollover a KskDnssecKeyVersion, you must replace the parent zone's DS record containing the old KskDnssecKeyVersion data with the data from the new KskDnssecKeyVersion. To remove the old DS record without causing service disruption, wait until the old DS record's TTL has expired, and the new DS record has propagated. After the DS replacement has been completed, then the PromoteZoneDnssecKeyVersion operation must be called. Metrics are emitted in the oci_dns namespace daily for each KskDnssecKeyVersion indicating how many days are left until expiration. We recommend that you set up alarms and notifications for KskDnssecKeyVersion expiration so that the necessary parent zone updates can be made and the PromoteZoneDnssecKeyVersion operation can be called. Enabling DNSSEC results in additional records in DNS responses which increases their size and can cause higher response latency. For more information, see [DNSSEC](/iaas/Content/DNS/Concepts/dnssec.htm). (ENABLED, DISABLED) (default: DISABLED, x-obmcs-top-level-enum: #/definitions/ZoneDnssecState) |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
isProtected | boolean | A Boolean flag indicating whether or not parts of the resource are unable to be explicitly managed. |
lifecycleState | string | The current state of the zone resource. (ACTIVE, CREATING, DELETED, DELETING, FAILED, UPDATING) |
resolutionMode | string | The resolution mode of a zone defines behavior related to how query responses can be handled. See [Private DNS Zone Transparency](/Content/DNS/Tasks/privatedns.htm#use-cases__resolution) for more information. (STATIC, TRANSPARENT, RTYPE_TRANSPARENT) (default: STATIC, x-obmcs-top-level-enum: #/definitions/ZoneResolutionMode) |
scope | string | The scope of the zone. (GLOBAL, PRIVATE) (x-obmcs-top-level-enum: #/definitions/Scope) |
self | string (url) | The canonical absolute URL of the resource. |
serial | integer (int64) | The current serial of the zone. As seen in the zone's SOA record. |
timeCreated | string (date-time) | The date and time the resource was created in "YYYY-MM-ddThh:mm:ssZ" format with a Z offset, as defined by RFC 3339. Example: 2016-07-22T17:23:59:60Z |
version | string | Version is the never-repeating, totally-orderable, version of the zone, from which the serial field of the zone's SOA record is derived. |
viewId | string | The OCID of the private view containing the zone. This value will be null for zones in the global DNS, which are publicly resolvable and not part of a private view. |
zoneType | string | The type of the zone. Must be either PRIMARY or SECONDARY. SECONDARY is only supported for GLOBAL zones. (PRIMARY, SECONDARY) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | zoneNameOrId, region | If-None-Match, If-Modified-Since, opc-request-id, scope, viewId, compartmentId | Gets information about the specified zone, including its creation date, zone type, and serial.<br /><br />When the zone name is provided as a path parameter and PRIVATE is used for the scope query<br />parameter then the viewId query parameter is required.<br /> |
list | select | compartmentId, region | opc-request-id, limit, page, name, nameContains, zoneType, timeCreatedGreaterThanOrEqualTo, timeCreatedLessThan, lifecycleState, sortBy, sortOrder, scope, viewId, tsigKeyId, dnssecState | Gets a list of all zones in the specified compartment.<br /><br />The collection can be filtered by name, time created, scope, associated view, and zone type.<br />Filtering by view is only supported for private zones.<br /> |
create | insert | region, name, compartmentId | opc-request-id, opc-retry-token, compartmentId, scope, viewId | Creates a new zone in the specified compartment.<br /><br />Private zones must have a zone type of PRIMARY. Creating a private zone at or under oraclevcn.com<br />within the default protected view of a VCN-dedicated resolver is not permitted.<br /> |
update | update | zoneNameOrId, region | If-Match, If-Unmodified-Since, opc-request-id, scope, viewId, compartmentId | Updates the zone with the specified information.<br /><br />Global secondary zones may have their external masters updated. For more information about secondary<br />zones, see [Manage DNS Service Zone](/iaas/Content/DNS/Tasks/managingdnszones.htm). When the zone name<br />is provided as a path parameter and PRIVATE is used for the scope query parameter then the viewId<br />query parameter is required.<br /> |
delete | delete | zoneNameOrId, region | If-Match, If-Unmodified-Since, opc-request-id, scope, viewId, compartmentId | Deletes the specified zone and all its steering policy attachments.<br /><br />A 204 response indicates that the zone has been successfully deleted. Protected zones cannot be deleted.<br />When the zone name is provided as a path parameter and PRIVATE is used for the scope query parameter<br />then the viewId query parameter is required.<br /> |
change_compartment | exec | zoneId, region, compartmentId | If-Match, opc-retry-token, opc-request-id, scope | Moves a zone into a different compartment.<br /><br />Protected zones cannot have their compartment changed. When the zone name is provided as a path<br />parameter and PRIVATE is used for the scope query parameter then the viewId query parameter is<br />required.<br /><br />Note: All SteeringPolicyAttachment objects associated with this zone will also be moved into<br />the provided compartment.<br /> |
promote_zone_dnssec_key_version | exec | zoneId, region, dnssecKeyVersionUuid | If-Match, If-Unmodified-Since, opc-retry-token, opc-request-id, scope | Promotes a specified DnssecKeyVersion on the zone.<br /><br />If the DnssecKeyVersion identified in the request body is a key signing key (KSK) that is replacing<br />another DnssecKeyVersion, then the old DnssecKeyVersion is scheduled for removal from the zone.<br /><br />For key signing keys (KSKs), you must create the DS record with the new key information before promoting<br />the new key to establish a chain of trust. To avoid a service disruption, remove the old DS record as soon<br />as its TTL (time to live) expires.<br /><br />For more information, see [DNSSEC](/iaas/Content/DNS/Concepts/dnssec.htm).<br /> |
stage_zone_dnssec_key_version | exec | zoneId, region, predecessorDnssecKeyVersionUuid | If-Match, If-Unmodified-Since, opc-retry-token, opc-request-id, scope | Stages a new DnssecKeyVersion on the zone. Staging is a process that generates a new "successor" key version<br />that replaces an existing "predecessor" key version.<br />Note: A new key-signing key (KSK) version is inert until you update the parent zone DS records.<br /><br />For more information, see the [DNSSEC](/iaas/Content/DNS/Concepts/dnssec.htm) documentation.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The OCID of the compartment the resource belongs to. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
zoneId | string | The OCID of the target zone. |
zoneNameOrId | string | The name or OCID of the target zone. |
If-Match | string | The If-Match header field makes the request method conditional on the existence of at least one current representation of the target resource, when the field-value is *, or having a current representation of the target resource that has an entity-tag matching a member of the list of entity-tags provided in the field-value. |
If-Modified-Since | string | The If-Modified-Since header field makes a GET or HEAD request method conditional on the selected representation's modification date being more recent than the date provided in the field-value. Transfer of the selected representation's data is avoided if that data has not changed. |
If-None-Match | string | The If-None-Match header field makes the request method conditional on the absence of any current representation of the target resource, when the field-value is *, or having a selected representation with an entity-tag that does not match any of those listed in the field-value. |
If-Unmodified-Since | string | The If-Unmodified-Since header field makes the request method conditional on the selected representation's last modification date being earlier than or equal to the date provided in the field-value. This field accomplishes the same purpose as If-Match for cases where the user agent does not have an entity-tag for the representation. |
compartmentId | string | The OCID of the compartment the zone belongs to. This parameter is deprecated and should be omitted. |
dnssecState | string | Search for zones that have the given DnssecState. |
lifecycleState | string | The state of a resource. |
limit | integer (int64) | The maximum number of items to return in a page of the collection. |
name | string | A case-sensitive filter for zone names. Will match any zone with a name that equals the provided value. |
nameContains | string | Search by zone name. Will match any zone whose name (case-insensitive) contains the provided value. |
opc-request-id | string | Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
scope | string | Specifies to operate only on resources that have a matching DNS scope. |
sortBy | string | The field by which to sort zones. |
sortOrder | string | The order to sort the resources. |
timeCreatedGreaterThanOrEqualTo | string (date-time) | An [RFC 3339](https:​//www.ietf.org/rfc/rfc3339.txt) timestamp that states all returned resources were created on or after the indicated time. |
timeCreatedLessThan | string (date-time) | An [RFC 3339](https:​//www.ietf.org/rfc/rfc3339.txt) timestamp that states all returned resources were created before the indicated time. |
tsigKeyId | string | Search for zones that are associated with a TSIG key. |
viewId | string | The OCID of the view the zone is associated with. Required when accessing a private zone by name. |
zoneType | string | Search by zone type, PRIMARY or SECONDARY. Will match any zone whose type equals the provided value. |
SELECT examples​
- get
- list
Gets information about the specified zone, including its creation date, zone type, and serial.<br /><br />When the zone name is provided as a path parameter and PRIVATE is used for the scope query<br />parameter then the viewId query parameter is required.<br />
SELECT
id,
name,
compartmentId,
definedTags,
dnssecConfig,
dnssecState,
externalDownstreams,
externalMasters,
freeformTags,
isProtected,
lifecycleState,
nameservers,
resolutionMode,
scope,
self,
serial,
timeCreated,
version,
viewId,
zoneTransferServers,
zoneType
FROM oci.dns.zones
WHERE zoneNameOrId = '{{ zoneNameOrId }}' -- required
AND region = '{{ region }}' -- required
AND If-None-Match = '{{ If-None-Match }}'
AND If-Modified-Since = '{{ If-Modified-Since }}'
AND opc-request-id = '{{ opc-request-id }}'
AND scope = '{{ scope }}'
AND viewId = '{{ viewId }}'
AND compartmentId = '{{ compartmentId }}'
;
Gets a list of all zones in the specified compartment.<br /><br />The collection can be filtered by name, time created, scope, associated view, and zone type.<br />Filtering by view is only supported for private zones.<br />
SELECT
id,
name,
compartmentId,
definedTags,
dnssecConfig,
dnssecState,
freeformTags,
isProtected,
lifecycleState,
resolutionMode,
scope,
self,
serial,
timeCreated,
version,
viewId,
zoneType
FROM oci.dns.zones
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND opc-request-id = '{{ opc-request-id }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND name = '{{ name }}'
AND nameContains = '{{ nameContains }}'
AND zoneType = '{{ zoneType }}'
AND timeCreatedGreaterThanOrEqualTo = '{{ timeCreatedGreaterThanOrEqualTo }}'
AND timeCreatedLessThan = '{{ timeCreatedLessThan }}'
AND lifecycleState = '{{ lifecycleState }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND scope = '{{ scope }}'
AND viewId = '{{ viewId }}'
AND tsigKeyId = '{{ tsigKeyId }}'
AND dnssecState = '{{ dnssecState }}'
;
INSERT examples​
- create
- Manifest
Creates a new zone in the specified compartment.<br /><br />Private zones must have a zone type of PRIMARY. Creating a private zone at or under oraclevcn.com<br />within the default protected view of a VCN-dedicated resolver is not permitted.<br />
INSERT INTO oci.dns.zones (
compartmentId,
definedTags,
freeformTags,
migrationSource,
name,
region,
opc-request-id,
opc-retry-token,
compartmentId,
scope,
viewId
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ freeformTags }}',
'{{ migrationSource }}',
'{{ name }}' /* required */,
'{{ region }}',
'{{ opc-request-id }}',
'{{ opc-retry-token }}',
'{{ compartmentId }}' /* required */,
'{{ scope }}',
'{{ viewId }}'
RETURNING
id,
name,
compartmentId,
definedTags,
dnssecConfig,
dnssecState,
externalDownstreams,
externalMasters,
freeformTags,
isProtected,
lifecycleState,
nameservers,
resolutionMode,
scope,
self,
serial,
timeCreated,
version,
viewId,
zoneTransferServers,
zoneType
;
# Description fields are for documentation purposes
- name: zones
props:
- name: region
value: "{{ region }}"
description: Required parameter for the zones resource.
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The OCID of the compartment containing the zone.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
**Example:** `{"Operations": {"CostCenter": "42"}}`
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
**Example:** `{"Department": "Finance"}`
- name: migrationSource
value: "{{ migrationSource }}"
description: |
Discriminator that is used to determine whether to create a new zone (NONE) or to migrate an existing DynECT zone (DYNECT).
valid_values: ['NONE', 'DYNECT']
default: NONE
- name: name
value: "{{ name }}"
description: |
The name of the zone.
Global zone names must be unique across all other zones within the realm. Private zone names must be unique
within their view.
Unicode characters will be converted into punycode, see [RFC 3492](https://tools.ietf.org/html/rfc3492).
- name: opc-request-id
value: "{{ opc-request-id }}"
description: Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
description: Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
- name: compartmentId
value: "{{ compartmentId }}"
description: The OCID of the compartment the zone belongs to. This parameter is deprecated and should be omitted.
description: The OCID of the compartment the zone belongs to. This parameter is deprecated and should be omitted.
- name: scope
value: "{{ scope }}"
description: Specifies to operate only on resources that have a matching DNS scope.
description: Specifies to operate only on resources that have a matching DNS scope.
- name: viewId
value: "{{ viewId }}"
description: The OCID of the view the resource is associated with.
description: The OCID of the view the resource is associated with.
UPDATE examples​
- update
Updates the zone with the specified information.<br /><br />Global secondary zones may have their external masters updated. For more information about secondary<br />zones, see [Manage DNS Service Zone](/iaas/Content/DNS/Tasks/managingdnszones.htm). When the zone name<br />is provided as a path parameter and PRIVATE is used for the scope query parameter then the viewId<br />query parameter is required.<br />
UPDATE oci.dns.zones
SET
definedTags = '{{ definedTags }}',
dnssecState = '{{ dnssecState }}',
externalDownstreams = '{{ externalDownstreams }}',
externalMasters = '{{ externalMasters }}',
freeformTags = '{{ freeformTags }}',
resolutionMode = '{{ resolutionMode }}'
WHERE
zoneNameOrId = '{{ zoneNameOrId }}' --required
AND region = '{{ region }}' --required
AND If-Match = '{{ If-Match}}'
AND If-Unmodified-Since = '{{ If-Unmodified-Since}}'
AND opc-request-id = '{{ opc-request-id}}'
AND scope = '{{ scope}}'
AND viewId = '{{ viewId}}'
AND compartmentId = '{{ compartmentId}}'
RETURNING
id,
name,
compartmentId,
definedTags,
dnssecConfig,
dnssecState,
externalDownstreams,
externalMasters,
freeformTags,
isProtected,
lifecycleState,
nameservers,
resolutionMode,
scope,
self,
serial,
timeCreated,
version,
viewId,
zoneTransferServers,
zoneType;
DELETE examples​
- delete
Deletes the specified zone and all its steering policy attachments.<br /><br />A 204 response indicates that the zone has been successfully deleted. Protected zones cannot be deleted.<br />When the zone name is provided as a path parameter and PRIVATE is used for the scope query parameter<br />then the viewId query parameter is required.<br />
DELETE FROM oci.dns.zones
WHERE zoneNameOrId = '{{ zoneNameOrId }}' --required
AND region = '{{ region }}' --required
AND If-Match = '{{ If-Match }}'
AND If-Unmodified-Since = '{{ If-Unmodified-Since }}'
AND opc-request-id = '{{ opc-request-id }}'
AND scope = '{{ scope }}'
AND viewId = '{{ viewId }}'
AND compartmentId = '{{ compartmentId }}'
;
Lifecycle Methods​
- change_compartment
- promote_zone_dnssec_key_version
- stage_zone_dnssec_key_version
Moves a zone into a different compartment.<br /><br />Protected zones cannot have their compartment changed. When the zone name is provided as a path<br />parameter and PRIVATE is used for the scope query parameter then the viewId query parameter is<br />required.<br /><br />Note: All SteeringPolicyAttachment objects associated with this zone will also be moved into<br />the provided compartment.<br />
EXEC oci.dns.zones.change_compartment
@zoneId='{{ zoneId }}' --required,
@region='{{ region }}' --required,
@If-Match='{{ If-Match }}',
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@scope='{{ scope }}'
@@json=
'{
"compartmentId": "{{ compartmentId }}"
}'
;
Promotes a specified DnssecKeyVersion on the zone.<br /><br />If the DnssecKeyVersion identified in the request body is a key signing key (KSK) that is replacing<br />another DnssecKeyVersion, then the old DnssecKeyVersion is scheduled for removal from the zone.<br /><br />For key signing keys (KSKs), you must create the DS record with the new key information before promoting<br />the new key to establish a chain of trust. To avoid a service disruption, remove the old DS record as soon<br />as its TTL (time to live) expires.<br /><br />For more information, see [DNSSEC](/iaas/Content/DNS/Concepts/dnssec.htm).<br />
EXEC oci.dns.zones.promote_zone_dnssec_key_version
@zoneId='{{ zoneId }}' --required,
@region='{{ region }}' --required,
@If-Match='{{ If-Match }}',
@If-Unmodified-Since='{{ If-Unmodified-Since }}',
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@scope='{{ scope }}'
@@json=
'{
"dnssecKeyVersionUuid": "{{ dnssecKeyVersionUuid }}"
}'
;
Stages a new DnssecKeyVersion on the zone. Staging is a process that generates a new "successor" key version<br />that replaces an existing "predecessor" key version.<br />Note: A new key-signing key (KSK) version is inert until you update the parent zone DS records.<br /><br />For more information, see the [DNSSEC](/iaas/Content/DNS/Concepts/dnssec.htm) documentation.<br />
EXEC oci.dns.zones.stage_zone_dnssec_key_version
@zoneId='{{ zoneId }}' --required,
@region='{{ region }}' --required,
@If-Match='{{ If-Match }}',
@If-Unmodified-Since='{{ If-Unmodified-Since }}',
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@scope='{{ scope }}'
@@json=
'{
"predecessorDnssecKeyVersionUuid": "{{ predecessorDnssecKeyVersionUuid }}"
}'
;