Empty values in an AWS Route 53 record

A regular DNS record is missing its required target values

Description

A non-alias Route 53 record needs records values appropriate to its type. An empty array cannot specify a valid DNS target. AWS alias records use an alias target instead of records.

Potential impact

Applying the DNS configuration may fail, leaving a service unreachable through its expected name.

Remediation

Supply values suitable for the record type, such as A, CNAME or NS, and reject empty module inputs. For an alias record, specify the correct alias target and hosted zone.

Examples

These examples fill an empty NS record with the hosted zone’s name servers. Set the hosted zone and record name to match the actual DNS configuration.

Before

hcl
resource "aws_route53_record" "service_record" {
  allow_overwrite = true
  name            = "test.example.com"
  ttl             = 30
  type            = "NS"
  zone_id         = aws_route53_zone.example.zone_id

  records = []
}

After

hcl
resource "aws_route53_record" "service_record" {
  allow_overwrite = true
  name            = "test.example.com"
  ttl             = 30
  type            = "NS"
  zone_id         = aws_route53_zone.example.zone_id

  records = [
    aws_route53_zone.example.name_servers[0],
    aws_route53_zone.example.name_servers[1],
    aws_route53_zone.example.name_servers[2],
    aws_route53_zone.example.name_servers[3],
  ]
}

References