Automating Global Edge Ingress with Cloud DNS and Google-Managed TLS
Enterprise web architectures require global edge termination, automated SSL certificate renewal, and clean multi-subdomain routing. For AustinSS, our apex domain austinss.com routes to corporate marketing, while blogs.austinss.com and dev.blogs.austinss.com power our publishing workloads.
1. Delegating Apex Domain to Cloud DNS
- In Google Cloud DNS, create an authoritative public managed zone:
resource "google_dns_managed_zone" "primary" { name = "austinss-com-zone" dns_name = "austinss.com." description = "Authoritative public DNS zone for austinss.com" } - Retrieve the 4 assigned Google name servers (e.g.,
ns-cloud-a1.googledomains.com). - In GoDaddy (or registrar of record), update domain NS records to point to Google Cloud DNS.
2. Dual-Environment Routing Pattern
We enforce a distinct routing topology for development and production environments:
- DEV (
dev.blogs.austinss.com): Points via CNAME toghs.googlehosted.com.using Cloud Run native custom domain mapping. This ensures zero load balancer costs in development while providing free automated 90-day GTS SSL certificates. - PROD (
blogs.austinss.com): Points to a dedicated Global External HTTPS Application Load Balancer static IP (34.x.x.x), backed by Cloud CDN and Serverless NEGs for DDoS protection, HTTP/3 QUIC acceleration, and sub-10ms edge caching.
3. Zero-Downtime Rollback Runbook
If a production container deployment fails, routing must recover instantly without waiting for a 10-minute CI/CD rebuild:
# Shift 100% traffic back to previous healthy revision at GFE edge
gcloud run services update-traffic austinss-blog \
--to-revisions=austinss-blog-00004-abc=100 \
--region=us-central1 \
--project=austinss-web-prod
Mean Time to Recovery (MTTR) is less than 15 seconds.