This document includes the best practices and guidelines for Cloud DNS when running generative AI workloads on Google Cloud. Use Cloud DNS with Vertex AI to register, manage, and serve your domain.
Required Cloud DNS controls
The following controls are strongly recommended when using Cloud DNS.
Enable DNS Security Extensions
| Google control ID | DNS-CO-6.1 |
|---|---|
| Category | Required |
| Description | The Domain Name System Security Extensions (DNSSEC) is a feature of the Domain Name System (DNS) that authenticates responses to domain name lookups. It doesn't provide privacy protections for those lookups, but prevents attackers from manipulating or poisoning the responses to DNS requests. Within Cloud DNS, enable DNSSEC in the following places:
|
| Applicable products |
|
| Related NIST-800-53 controls |
|
| Related CRI profile controls |
|
| Related information |
Optional Cloud DNS controls
We recommend that you implement the following security controls in folders that contain generative AI workloads.
Use zonal DNS
| Google control ID | DNS-CO-4.1 |
|---|---|
| Category | Optional |
| Description | The |
| Applicable products |
|
| Path | constraints/compute.setNewProjectDefaultToZonalDNSOnly |
| Operator | = |
| Value |
|
| Type | Boolean |
| Related NIST-800-53 controls |
|
| Related CRI profile controls |
|
| Related information |
What's next
Review Cloud Identity controls.
See more Google Cloud security best practices and guidelines for generative AI workloads.