Skip to main content

Private zones

A zone is public or private, fixed at creation.
A private zone answers only inside the VPCs associated with it, and needs at least one at creation. Attach or detach more later through the vpc-associations endpoints.
The console’s Create Zone form has a Visibility card with a private switch and the VPC list. Visibility is fixed at creation either way, so a zone made public stays public.VPCs are regional and DNS is global: the create form offers the region you are currently in. Attach VPCs from other regions afterwards, from the zone’s Settings tab.
The two mismatches are rejected rather than quietly corrected: a private zone with no vpc_ids, and a public zone that carries them, both answer 400.