Azion CLI dnssec
Azion CLI commands that describe and update the DNSSEC setting of an Edge DNS zone, with every flag, its type, and its default.
The Azion CLI dnssec commands describe and update the DNSSEC setting of an Edge DNS zone: whether DNSSEC is on, its status, and the delegation signer (DS) values of the zone. DNSSEC belongs to a zone, so the CLI has no command that creates, lists, or deletes it. The options every command accepts, such as --format, --out, and -y, are on Global options.
Describe
azion describe dnssec prints the DNSSEC setting of one DNS zone:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--zone-id | — | int | — | Required. ID of the DNS zone to describe. |
This command describes the DNSSEC setting of a zone where DNSSEC has never been turned on:
The command prints whether DNSSEC is on and its status:
With --format json, the command prints the full object: delegation_signer, enabled, and status. The delegation_signer object holds the DS values, algorithm_type, digest, digest_type, and key_tag, and is null while DNSSEC is off. This command prints the object of the same zone after DNSSEC is turned on:
The command prints the DS values of the zone:
With --out, the command writes the same JSON to a file and prints File successfully written to: followed by the path. For what each status means and where the DS values go, refer to DNSSEC.
A zone ID that matches no zone of your account fails with this error:
Update
azion update dnssec turns DNSSEC on or off for a DNS zone:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--enabled | — | — | — | Required unless --file is set. Turns DNSSEC on (true) or off (false) for the zone. Without it, the command asks Enter whether DNSSEC should be enabled (true/false). |
--file | — | string | — | Path to a JSON file with the DNSSEC setting. Use - to read the JSON from standard input. |
--zone-id | — | int | — | Required. ID of the DNS zone to update. |
Write the --enabled value with an equals sign, as in --enabled=false: --enabled false, with a space, prints the success line and leaves DNSSEC on.
This command turns DNSSEC off for the zone with ID 1234:
The command confirms the update:
After this update, azion describe dnssec --zone-id 1234 --format json reads "enabled": false and "status": "ready".
Use a JSON file
azion update dnssec reads the DNSSEC setting from a JSON file with --file. The command reads enabled from the file, and --zone-id stays on the command line.
This file turns DNSSEC on:
Pass the file to the update command:
The command confirms the update:
After this update, azion describe dnssec --zone-id 1234 --format json reads "enabled": true and "status": "ready".