Details
| ID | AWS - Route53 |
|---|---|
| Provider | Amazon |
| Category | IT Services |
| From Version | 5.0.0 |
| Docker Image | demisto/boto3py3:1.0.0.10221838 |
| Supported Modules | Agentix XSIAM |
README
Amazon Web Services Managed Cloud DNS Service.
Configure AWS - Route53 in Cortex
| Parameter | Required |
|---|---|
| Role Arn | False |
| Role Session Name | False |
| Role Session Duration | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
aws-route53-create-record
Creates a resource record set. Creates a resource record set that has the specified values.
Base Command
aws-route53-create-record
Input
| Argument Name | Description | Required |
|---|---|---|
| source | The name of the domain you want to Create. i.e. www.example.com. | Required |
| target | The DNS record value. | Required |
| ttl | The resource record cache time to live (TTL), in seconds. | Required |
| hostedZoneId | Specify the hosted zone ID. | Required |
| type | The type of the record to create. Possible values are: A, AAAA, CAA, CNAME, MX, NAPTR, NS, PTR, SOA, SPF, SRV, TX. | Required |
| comment | Any comments you want to include. | Optional |
| roleArn | The Amazon Resource Name (ARN) of the role to assume. | Optional |
| roleSessionName | An identifier for the assumed role session. | Optional |
| roleSessionDuration | The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| AWS.Route53.RecordSetsChange.Id | string | The ID of the request. |
| AWS.Route53.RecordSetsChange.Status | string | The current state of the request. PENDING indicates that this request has not yet been applied to all Amazon Route 53 DNS servers. |
| AWS.Route53.RecordSetsChange.Comment | string | A complex type that describes change information about changes made to your hosted zone. |
Command Example
!aws-route53-create-record hostedZoneId=Z33ASF9#22MSFA6R6M5G9 source=test.example.com target=192.168.1.1 ttl=300 type=A comment="test record"
aws-route53-delete-record
Deletes a resource record set. Deletes an existing resource record set that has the specified values.
Base Command
aws-route53-delete-record
Input
| Argument Name | Description | Required |
|---|---|---|
| source | The name of the domain you want to Create. i.e. www.example.com. | Required |
| target | The DNS record value. | Required |
| ttl | The resource record cache time to live (TTL), in seconds. | Required |
| hostedZoneId | Specify the hosted zone ID. | Required |
| type | The type of the record to create. Possible values are: A, AAAA, CAA, CNAME, MX, NAPTR, NS, PTR, SOA, SPF, SRV, TX. | Required |
| roleArn | The Amazon Resource Name (ARN) of the role to assume. | Optional |
| roleSessionName | An identifier for the assumed role session. | Optional |
| roleSessionDuration | The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| AWS.Route53.RecordSetsChange.Id | string | The ID of the request. |
| AWS.Route53.RecordSetsChange.Status | string | The current state of the request. PENDING indicates that this request has not yet been applied to all Amazon Route 53 DNS servers. |
| AWS.Route53.RecordSetsChange.Comment | string | A complex type that describes change information about changes made to your hosted zone. |
Command Example
!aws-route53-delete-record hostedZoneId=Z33935452MA6RDSFDSG6M5G9 source=test.example.com target=192.168.1.1 type=A ttl=300
aws-route53-list-hosted-zones
Retrieves a list of the public and private hosted zones that are associated with the current AWS account.
Base Command
aws-route53-list-hosted-zones
Input
| Argument Name | Description | Required |
|---|---|---|
| roleArn | The Amazon Resource Name (ARN) of the role to assume. | Optional |
| roleSessionName | An identifier for the assumed role session. | Optional |
| roleSessionDuration | The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| AWS.Route53.HostedZones.Id | string | The ID that Amazon Route 53 assigned to the hosted zone when you created it. |
| AWS.Route53.HostedZones.Name | string | The name of the domain. |
| AWS.Route53.HostedZones.CallerReference | string | The value that you specified for CallerReference when you created the hosted zone. |
| AWS.Route53.HostedZones.Config.Comment | string | Any comments that you want to include about the hosted zone. |
| AWS.Route53.HostedZones.Config.PrivateZone | string | A value that indicates whether this is a private hosted zone. |
| AWS.Route53.HostedZones.ResourceRecordSetCount | number | The number of resource record sets in the hosted zone. |
| AWS.Route53.HostedZones.LinkedService.ServicePrincipal | string | If the health check or hosted zone was created by another service, the service that created the resource. |
| AWS.Route53.HostedZones.LinkedService.Description | string | If the health check or hosted zone was created by another service, an optional description that can be provided by the other service. |
Command Example
!aws-route53-list-hosted-zones
aws-route53-list-resource-record-sets
Lists the resource record sets in a specified hosted zone.
Base Command
aws-route53-list-resource-record-sets
Input
| Argument Name | Description | Required |
|---|---|---|
| hostedZoneId | The ID of the hosted zone that contains the resource record sets that you want to list. | Required |
| startRecordName | The first name in the lexicographic ordering of resource record sets that you want to list. | Optional |
| startRecordType | The type of resource record set to begin the record listing from. Possible values are: SOA, A, TXT, NS, CNAME, MX, NAPTR, PTR, SRV, SPF, AAAA, CAA. | Optional |
| startRecordIdentifier | Weighted resource record sets only. | Optional |
| roleArn | The Amazon Resource Name (ARN) of the role to assume. | Optional |
| roleSessionName | An identifier for the assumed role session. | Optional |
| roleSessionDuration | The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| AWS.Route53.RecordSets.Name | string | The name of the domain. |
| AWS.Route53.RecordSets.Type | string | The DNS record type. |
| AWS.Route53.RecordSets.SetIdentifier | string | An identifier that differentiates among multiple resource record sets that have the same combination of DNS name and type. |
| AWS.Route53.RecordSets.Weight | number | Weighted resource record sets only. |
| AWS.Route53.RecordSets.Region | string | Latency-based resource record sets only |
| AWS.Route53.RecordSets.GeoLocation.ContinentCode | string | The two-letter code for the continent. |
| AWS.Route53.RecordSets.GeoLocation.CountryCode | string | The two-letter code for the country. |
| AWS.Route53.RecordSets.GeoLocation.SubdivisionCode | string | The code for the subdivision, for example, a state in the United States or a province in Canada. |
| AWS.Route53.RecordSets.Failover | string | Failover resource record sets only |
| AWS.Route53.RecordSets.MultiValueAnswer | string | Multivalue answer resource record sets only |
| AWS.Route53.RecordSets.TTL | string | The resource record cache time to live (TTL), in seconds. |
| AWS.Route53.RecordSets.ResourceRecords.Value | string | The current record value. |
| AWS.Route53.RecordSets.AliasTarget.HostedZoneId | string | Alias resource record sets only |
| AWS.Route53.RecordSets.AliasTarget.DNSName | string | Alias resource record sets only |
| AWS.Route53.RecordSets.AliasTarget.EvaluateTargetHealth | string | Alias resource record sets only |
| AWS.Route53.RecordSets.HealthCheckId | string | ID of the applicable health check. |
| AWS.Route53.RecordSets.TrafficPolicyInstanceId | string | the ID of the traffic policy instance that Amazon Route 53 created this resource record set for. |
Command Example
!aws-route53-list-resource-record-sets hostedZoneId=Z33DFSDDFSDF6R6MDF5G9
aws-route53-waiter-resource-record-sets-changed
A waiter function that waits until record set change is successful
Base Command
aws-route53-waiter-resource-record-sets-changed
Input
| Argument Name | Description | Required |
|---|---|---|
| id | The ID of the change. | Required |
| waiterDelay | The amount of time in seconds to wait between attempts. Default: 30. | Optional |
| waiterMaxAttempts | The maximum number of attempts to be made. Default: 60. | Optional |
Context Output
There is no context output for this command.
Command Example
!aws-route53-waiter-resource-record-sets-changed id=CM3UDCRD3ZYDSAF41
aws-route53-test-dns-answer
Gets the value that Amazon Route 53 returns in response to a DNS request for a specified record name and type. You can optionally specify the IP address of a DNS resolver, an EDNS0 client subnet IP address, and a subnet mask.
Base Command
aws-route53-test-dns-answer
Input
| Argument Name | Description | Required |
|---|---|---|
| hostedZoneId | The ID of the hosted zone that you want Amazon Route 53 to simulate a query for. | Required |
| recordName | The name of the resource record set that you want Amazon Route 53 to simulate a query for. | Required |
| recordType | The type of the resource record set. Possible values are: SOA, A, TXT, NS, CNAME, MX, NAPTR, PTR, SRV, SPF, AAAA, CAA. | Required |
| resolverIP | If you want to simulate a request from a specific DNS resolver, specify the IP address for that resolver. If you omit this value, TestDnsAnswer uses the IP address of a DNS resolver in the AWS US East (N. Virginia) Region (us-east-1 ). | Optional |
| roleArn | The Amazon Resource Name (ARN) of the role to assume. | Optional |
| roleSessionName | An identifier for the assumed role session. | Optional |
| roleSessionDuration | The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| AWS.Route53.TestDNSAnswer.Nameserver | string | The Amazon Route 53 name server used to respond to the request. |
| AWS.Route53.TestDNSAnswer.RecordName | string | The name of the resource record set that you submitted a request for. |
| AWS.Route53.TestDNSAnswer.RecordType | string | The type of the resource record set that you submitted a request for. |
| AWS.Route53.TestDNSAnswer.ResponseCode | string | A list that contains values that Amazon Route 53 returned for this resource record set. |
| AWS.Route53.TestDNSAnswer.Protocol | string | A code that indicates whether the request is valid or not. |
| AWS.Route53.TestDNSAnswer.RecordData | string | The protocol that Amazon Route 53 used to respond to the request, either UDP or TCP . |
Command Example
!aws-route53-test-dns-answer hostedZoneId=Z339SDF2MA6R6ADFSM5G9 recordName=testing2.example.com recordType=A
aws-route53-upsert-record
Upsert a resource record set. If a resource record set does not already exist, AWS creates it. If a resource set does exist, Amazon Route 53 updates it with the values in the request.
Base Command
aws-route53-upsert-record
Input
| Argument Name | Description | Required |
|---|---|---|
| source | The name of the domain you want to Create. i.e. www.example.com. | Required |
| target | The DNS record value. | Required |
| ttl | The resource record cache time to live (TTL), in seconds. | Required |
| hostedZoneId | Specify the hosted zone ID. | Required |
| type | The type of the record to create. Possible values are: A, AAAA, CAA, CNAME, MX, NAPTR, NS, PTR, SOA, SPF, SRV, TX. | Required |
| comment | Any comments you want to include. | Optional |
| roleArn | The Amazon Resource Name (ARN) of the role to assume. | Optional |
| roleSessionName | An identifier for the assumed role session. | Optional |
| roleSessionDuration | The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| AWS.Route53.RecordSetsChange.Id | string | The ID of the request. |
| AWS.Route53.RecordSetsChange.Status | string | The current state of the request. PENDING indicates that this request has not yet been applied to all Amazon Route 53 DNS servers. |
| AWS.Route53.RecordSetsChange.Comment | string | A complex type that describes change information about changes made to your hosted zone. |
Command Example
!aws-route53-upsert-record hostedZoneId=Z33ASF9#22MSFA6R6M5G9 source=test.example.com target=192.168.1.2 ttl=300 type=A comment="test record"
Configuration parameters
roleArn— Role ArnroleSessionName— Role Session NamesessionDuration— Role Session Durationcredentials— Access Keyaccess_key— Access Keysecret_key— Secret Keytimeout— Timeoutretries— Retriessts_regional_endpoint— AWS STS Regional Endpointsinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (7)
-
aws-route53-create-recordCreates a resource record set. Creates a resource record set that has the specified values.
-
aws-route53-delete-recordDeletes a resource record set. Deletes an existing resource record set that has the specified values.
-
aws-route53-list-hosted-zonesRetrieves a list of the public and private hosted zones that are associated with the current AWS account.
-
aws-route53-list-resource-record-setsLists the resource record sets in a specified hosted zone.
-
aws-route53-test-dns-answerGets the value that Amazon Route 53 returns in response to a DNS request for a specified record name and type. You can optionally specify the IP address of a DNS resolver, an EDNS0 client subnet IP address, and a subnet mask.
-
aws-route53-upsert-recordUpsert a resource record set. If a resource record set does not already exist, AWS creates it. If a resource set does exist, Amazon Route 53 updates it with the values in the request.
-
aws-route53-waiter-resource-record-sets-changedA waiter function that waits until record set change is successful.
import importlib AWS_ROUTE53 = importlib.import_module("AWSRoute53") TEST_PARAMS = {"roleArn": "test_arn", "roleSessionName": "test_role_session", "roleSessionDuration": "test_role_session_duration"} class AWSClient: # pragma: no cover def aws_session(self): pass class AWSRoute53ClientWaiter: # pragma: no cover def wait(self, **kwargs): pass class AWSRoute53Client: # pragma: no cover def list_hosted_zones(self): pass def change_resource_record_sets(self, **kwargs): pass def list_resource_record_sets(self, **kwargs): pass def get_waiter(self, *args): # noqa return AWSRoute53ClientWaiter() def test_dns_answer(self, **kwargs): pass def test_create_record(mocker): """ Given: - A DNS record. When: - Calling create_record method. Then: - Ensure that the DNS record was successfully created. """ from CommonServerPython import tableToMarkdown args = TEST_PARAMS args.update( { "hostedZoneId": "test-domain.com", "source": "foo.test-domain.com", "type": "CNAME", "ttl": 300, "target": "google.com", "comment": "redirect to google.com", } ) response = { "ChangeInfo": { "Id": "__mock_id__", "Status": "changed", } } mocker.patch.object(AWSRoute53Client, "change_resource_record_sets", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.create_record(args, session) data = { "Id": "__mock_id__", "Status": "changed", } assert tableToMarkdown("AWS Route53 record created", data) == res.readable_output def test_delete_record(mocker): """ Given: - A DNS record. When: - Calling delete_record method. Then: - Ensure that the DNS record was successfully deleted. """ from CommonServerPython import tableToMarkdown args = TEST_PARAMS args.update( { "hostedZoneId": "test-domain.com", "source": "foo.test-domain.com", "type": "CNAME", "ttl": 300, } ) response = { "ChangeInfo": { "Id": "__mock_id__", "Status": "deleted", } } mocker.patch.object(AWSRoute53Client, "change_resource_record_sets", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.delete_record(args, session) data = { "Id": "__mock_id__", "Status": "deleted", } assert tableToMarkdown("AWS Route53 record deleted", data) == res.readable_output def test_upsert_record(mocker): """ Given: - A DNS record. When: - Calling upsert_record method. Then: - Ensure that the DNS record was successfully updated. """ from CommonServerPython import tableToMarkdown args = TEST_PARAMS args.update( { "hostedZoneId": "test-domain.com", "source": "foo.test-domain.com", "type": "CNAME", "ttl": 300, "target": "palo.com", "comment": "redirect to palo.com", } ) response = { "ChangeInfo": { "Id": "__mock_id__", "Status": "updated", } } mocker.patch.object(AWSRoute53Client, "change_resource_record_sets", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.upsert_record(args, session) data = { "Id": "__mock_id__", "Status": "updated", } assert tableToMarkdown("AWS Route53 record Upsert", data) == res.readable_output def test_list_hosted_zones(mocker): """ Given: - A Hosted Zone. When: - Calling list_hosted_zones method. Then: - Ensure we get the list of hosted zones. """ from CommonServerPython import tableToMarkdown response = { "HostedZones": [ { "Name": "test-domain.com", "Id": "xxx", "ResourceRecordSetCount": 5, } ] } mocker.patch.object(AWSRoute53Client, "list_hosted_zones", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.list_hosted_zones(session) data = { "Name": "test-domain.com", "Id": "xxx", "ResourceRecordSetCount": 5, } assert tableToMarkdown("AWS Route53 Hosted Zones", data) == res.readable_output def test_list_resource_record_sets(mocker): """ Given: - A Hosted Zone. When: - Calling list_resource_record_sets method. Then: - Ensure we get the list of record sets from the hosted zones. """ from CommonServerPython import tableToMarkdown args = TEST_PARAMS args.update( { "HostedZoneId": "__x__", "startRecordName": "aaa", "startRecordType": "CNAME", "startRecordIdentifier": "a", } ) response = { "ResourceRecordSets": [ { "Name": "a.test-domain.com", "Type": "A", "TTL": 555, "ResourceRecords": [{"Value": "test-domain.com"}], } ] } mocker.patch.object(AWSRoute53Client, "list_resource_record_sets", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.list_resource_record_sets(args, session) data = [ { "Name": "a.test-domain.com", "Type": "A", "TTL": 555, "ResourceRecords": "test-domain.com", } ] assert tableToMarkdown("AWS Route53 Record Sets", data) == res.readable_output def test_list_resource_record_sets_no_ttl(mocker): """ Given: - A Hosted Zone. When: - Calling list_resource_record_sets method. - api returns records without TTLs Then: - Ensure we get the list of record sets from the hosted zones. - Ensure parsing is made properly """ from CommonServerPython import tableToMarkdown args = TEST_PARAMS args.update( { "HostedZoneId": "__x__", "startRecordName": "aaa", "startRecordType": "CNAME", "startRecordIdentifier": "a", } ) response = { "ResourceRecordSets": [ { "Name": "a.test-domain.com", "Type": "A", "ResourceRecords": [{"Value": "test-domain.com"}], } ] } mocker.patch.object(AWSRoute53Client, "list_resource_record_sets", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.list_resource_record_sets(args, session) data = [ { "Name": "a.test-domain.com", "Type": "A", "ResourceRecords": "test-domain.com", } ] assert tableToMarkdown("AWS Route53 Record Sets", data) == res.readable_output assert res.outputs == [{"Name": "a.test-domain.com", "Type": "A", "ResourceRecords": [{"Value": "test-domain.com"}]}] def test_waiter_resource_record_sets_changed(mocker): """ Given: - A Hosted Zone. When: - Calling waiter_resource_record_sets_changed method. Then: - Ensure we call the wait record changed method. """ args = TEST_PARAMS args.update( { "id": "__x__", "waiterDelay": 60, "waiterMaxAttempts": 3, } ) mocker.patch.object(AWSRoute53ClientWaiter, "wait", return_value={}) session = AWSRoute53Client() res = AWS_ROUTE53.waiter_resource_record_sets_changed(args, session) assert res.readable_output == "success" def test_test_dns_answer(mocker): """ Given: - A Hosted Zone. When: - Calling test_dns_answer method. Then: - Ensure we test the DNS answer. """ from CommonServerPython import tableToMarkdown args = TEST_PARAMS args.update( { "HostedZoneId": "__x__", "RecordName": "a.test-domain.com", "RecordType": "CNAME", "resolverIP": "8.8.8.8", } ) response = { "Nameserver": "__Nameserver__", "RecordName": "__RecordName__", "RecordType": "__RecordType__", "ResponseCode": "__ResponseCode__", "Protocol": "__Protocol__", } mocker.patch.object(AWSRoute53Client, "test_dns_answer", return_value=response) session = AWSRoute53Client() res = AWS_ROUTE53.test_dns_answer(args, session) data = { "Nameserver": "__Nameserver__", "RecordName": "__RecordName__", "RecordType": "__RecordType__", "ResponseCode": "__ResponseCode__", "Protocol": "__Protocol__", } assert tableToMarkdown("AWS Route53 Test DNS Answer", data) == res.readable_output