- Support
- Integrations
- DNS
DNS
Oracle Cloud integration · 54 node(s).
00Overview
Run Oracle Cloud DNS from a flow — create and delete public and private zones, read and rewrite the records inside them, and import or export a whole zone as a BIND file in a single step. Steer live traffic with failover, load-balancing and geo, ASN or IP routing policies, and manage the private-DNS side too: views, resolvers, resolver endpoints and the TSIG keys that authenticate zone transfers. Record reads and writes are synchronous, so a flow can look up a record and act on the answer in the same run.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting DNS
- Every DNS node opens with an Authentication dropdown offering two methods: Connect Oracle Cloud (recommended), which points the node at a managed Oracle Cloud connection, and API signing key (advanced), which lets you enter raw signing-key credentials directly on the node.
- With Connect Oracle Cloud, pick a connected Oracle Cloud account in each node's Oracle Cloud connection field — choosing one auto-fills the signing credentials, so the node needs nothing further to authenticate.
- For API signing key (advanced), sign in to the OCI Console, open the profile menu → My profile → API keys → Add API key, and let Oracle generate the key pair; the confirmation dialog shows a configuration snippet with your Tenancy OCID, User OCID, Region and Key Fingerprint — copy each into the matching node field. A freshly added key can take a minute or two to become active in OCI, so let an initial test retry before treating a failure as real.
- Set the Compartment OCID (required) to the compartment that holds — or should hold — the zones you are automating; you can copy it from Identity & Security → Compartments in the console, or use the tenancy OCID for the root compartment.
- Never paste the private key inline — store the Private Key (PEM) (and any Private Key Passphrase) as a Flomation environment secret (e.g.
dns_secret) and select it in the node's matching field.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Domain
OCI DNS: Delete Domain Records
oracle/dns/domain_records_delete · Action
Delete ALL records at a domain (FQDN) within an Oracle Cloud DNS zone. Synchronous — every record type at that domain is removed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Domain (FQDN) | string | Required | The FQDN whose records to delete, e.g. www.example.com — ALL record types are removed |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, id, domain, success, error
OCI DNS: Get Domain Records
oracle/dns/domain_records_get · Action
List all Oracle Cloud DNS records at a single domain (FQDN) within a zone, optionally filtered by record type and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Domain (FQDN) | string | Required | The fully-qualified domain within the zone (e.g. www.example.com) |
| Record Type | string | Only records of this type, e.g. A, AAAA, CNAME, MX, TXT (optional) | |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, records, count, truncated, success, error
OCI DNS: Patch Domain Records
oracle/dns/domain_records_patch · Action
Apply a list of add/remove/precondition operations to the records at one domain (across all record types) in a zone — a targeted alternative to replacing a whole RRSet. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Domain | string | Required | The fully-qualified record name, e.g. www.example.com |
| Operations (JSON array) | text | Required | [{"operation":"ADD","rtype":"A","rdata":"10.0.0.5","ttl":300}] — each item: operation (REQUIRE/PROHIBIT/ADD/REMOVE) + rtype/rdata/ttl |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, success, error
OCI DNS: Update Domain Records
oracle/dns/domain_records_update · Action
Replace ALL records at one domain of a zone — every record type — with a supplied set. This rewrites the whole domain: any record type not present in the supplied set is deleted. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Domain | string | Required | The fully-qualified record name, e.g. www.example.com |
| Records (JSON array) | text | Required | [{"rtype":"A","rdata":"10.0.0.5","ttl":300}] — rtype + rdata + ttl per record; domain defaults to the one above (REPLACES EVERY record at the domain, all types) |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, success, error
03Resolver
OCI DNS: Change Resolver Compartment
oracle/dns/resolver_change_compartment · Action
Move an Oracle Cloud private-DNS resolver, along with its protected default view and endpoints, into a different compartment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dns-resolver.oc1..aaaa… |
| Target Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — the compartment to move the resolver into |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Create Resolver Endpoint
oracle/dns/resolver_endpoint_create · Action
Create a VNIC resolver endpoint under a private-DNS resolver — a forwarding and/or listening address in a subnet of the resolver's VCN. Returns the endpoint immediately plus a work-request id; poll Get Resolver Endpoint until it is ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dnsresolver.oc1..aaaa… — the parent resolver |
| Endpoint Name | string | Required | Unique name within the resolver, e.g. forwarder-1 |
| Subnet OCID | string | Required | ocid1.subnet.oc1..aaaa… — must be in the resolver's VCN |
| Is Forwarding | boolean | Endpoint forwards outbound queries | |
| Is Listening | boolean | Endpoint listens for inbound queries | |
| Forwarding Address | string | IP to send forwarded queries from — auto-assigned if blank (optional) | |
| Listening Address | string | IP to listen for queries on — auto-assigned if blank (optional) | |
| Network Security Group OCIDs | string | Comma-separated NSG OCIDs in the same VCN (optional) | |
| Scope | string | GLOBAL or PRIVATE — resolver endpoints are private DNS — choices: Global (public), Private |
Returns: tool_result, resolver_endpoint, name, work_request_id, success, error
OCI DNS: Delete Resolver Endpoint
oracle/dns/resolver_endpoint_delete · Action
Permanently delete an Oracle Cloud DNS resolver endpoint by its parent resolver OCID and endpoint name. Asynchronous — returns a work-request id.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dnsresolver.oc1..aaaa… — the parent resolver |
| Endpoint Name | string | Required | The resolver endpoint name to delete |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private resolvers — choices: Global (public), Private |
Returns: tool_result, name, work_request_id, success, error
OCI DNS: Get Resolver Endpoint
oracle/dns/resolver_endpoint_get · Action
Fetch a single Oracle Cloud private-DNS resolver endpoint by its parent resolver OCID and endpoint name — its addresses, forwarding/listening role and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dns-resolver.oc1..aaaa… |
| Endpoint Name | string | Required | The resolver endpoint name (e.g. my-forwarding-endpoint) |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, resolver_endpoint, resolver_id, success, error
OCI DNS: List Resolver Endpoints
oracle/dns/resolver_endpoint_list · Action
List the endpoints of an Oracle Cloud DNS resolver, optionally filtered by name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dnsresolver.oc1..aaaa… — the resolver whose endpoints to list |
| Name | string | Only the endpoint with this exact name (optional) | |
| Scope | string | GLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, resolver_endpoints, count, truncated, success, error
OCI DNS: Update Resolver Endpoint
oracle/dns/resolver_endpoint_update · Action
Update an Oracle Cloud DNS resolver endpoint's network security groups, preserving its existing tags and configuration.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dnsresolver.oc1..aaaa… — the parent resolver |
| Endpoint Name | string | Required | The resolver endpoint's name |
| Network Security Group OCIDs | string | Comma-separated NSG OCIDs (leave blank to keep the current set) | |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private resolvers — choices: Global (public), Private |
Returns: tool_result, endpoint, name, resolver_id, lifecycle_state, work_request_id, success, error
OCI DNS: Get Resolver
oracle/dns/resolver_get · Action
Fetch a single Oracle Cloud private-DNS resolver by OCID — the resolver that answers DNS for a VCN, with its rules and endpoints.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dns-resolver.oc1..aaaa… |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, resolver, id, success, error
OCI DNS: List Resolvers
oracle/dns/resolver_list · Action
List the Oracle Cloud DNS resolvers in a compartment, optionally filtered by display name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name | string | Only resolvers with this exact display name (optional) | |
| Scope | string | GLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, resolvers, count, truncated, success, error
OCI DNS: Update Resolver
oracle/dns/resolver_update · Action
Update a private-DNS resolver's display name, freeform tags, attached views and forwarding rules. Reads the resolver first and RE-SENDS its current attached views and rules so they are preserved — the update is a full-replace PUT. Attached views/rules are only changed when you supply attached_views_json/rules_json; everything else is left blank to keep the current value.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the resolver picker) | |
| Resolver OCID | string | Required | ocid1.dns-resolver.oc1..aaaa… |
| Display Name | string | New display name — leave blank to keep the current one | |
| Freeform Tags (JSON) | text | {"env":"prod"} — REPLACES the resolver's freeform tags; leave blank to keep the current ones | |
| Attached Views (JSON array) | text | [{"viewId":"ocid1.dnsview.oc1..aaaa…"}] — REPLACES the attached views; leave blank to keep the current ones | |
| Rules (JSON array) | text | [{"action":"FORWARD","destinationAddresses":["10.0.0.2"],"sourceEndpointName":"ep1","qnameCoverConditions":["internal.example.com"]}] — REPLACES the forwarding rules; leave blank to keep the current ones | |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, resolver, id, work_request_id, success, error
04Rrset
OCI DNS: Delete RRSet
oracle/dns/rrset_delete · Action
Delete every record of one type (RRSet) at a domain within an Oracle Cloud DNS zone. Synchronous — the RRSet is gone once it returns.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Domain | string | Required | The FQDN within the zone, e.g. www.example.com |
| Record Type | string | Required | e.g. A, AAAA, CNAME, MX, TXT |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, id, domain, rtype, success, error
OCI DNS: Get RRSet
oracle/dns/rrset_get · Action
Read all records of one RRSet — the records at a given domain of a given type, e.g. the A records for www.example.com.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Domain | string | Required | The fully-qualified record name, e.g. www.example.com |
| Record Type | string | Required | A, AAAA, CNAME, MX, TXT, NS, SRV, … |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, truncated, success, error
OCI DNS: Patch RRSet
oracle/dns/rrset_patch · Action
Add or remove individual records within one RRSet (the records at a domain of a given type) without replacing the whole set — the surgical alternative to Update RRSet. Each operation names an ADD/REMOVE (or REQUIRE/PROHIBIT precondition). Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Domain | string | Required | The fully-qualified record name, e.g. www.example.com |
| Record Type | string | Required | A, AAAA, CNAME, MX, TXT, NS, … |
| Operations (JSON array) | text | Required | [{"operation":"ADD","rdata":"10.0.0.5","ttl":300},{"operation":"REMOVE","rdata":"10.0.0.4"}] — operation is ADD/REMOVE (or REQUIRE/PROHIBIT precondition); domain/rtype default to the ones above |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, success, error
OCI DNS: Update RRSet
oracle/dns/rrset_update · Action
Replace all records of one RRSet (the records at a domain of a given type) with a supplied set — the primary way to set a record, e.g. point www.example.com at a new IP. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Domain | string | Required | The fully-qualified record name, e.g. www.example.com |
| Record Type | string | Required | A, AAAA, CNAME, MX, TXT, NS, … |
| Records (JSON array) | text | Required | [{"rdata":"10.0.0.5","ttl":300}] — rdata + ttl; domain/rtype default to the ones above (REPLACES the whole RRSet) |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, success, error
05Steering
OCI DNS: Create Steering Policy Attachment
oracle/dns/steering_policy_attachment_create · Action
Attach a steering policy to a domain within a public zone, so DNS queries for that domain are answered by the policy's traffic-management logic. Returns a work-request id when provisioning is asynchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Steering Policy OCID | string | Required | ocid1.dns-steering-policy.oc1..aaaa… — the policy to attach |
| Zone OCID | string | Required | ocid1.dns-zone.oc1..aaaa… — must be a public zone |
| Domain Name | string | Required | The domain within the zone, e.g. www.example.com |
| Display Name | string | Friendly name for the attachment (optional) |
Returns: tool_result, attachment, id, work_request_id, success, error
OCI DNS: Delete Steering Policy Attachment
oracle/dns/steering_policy_attachment_delete · Action
Detach a steering policy from a domain by deleting its attachment (by OCID). Synchronous — the attachment is gone once this succeeds.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the attachment picker) | |
| Steering Policy Attachment OCID | string | Required | ocid1.dnssteeringpolicyattachment.oc1..aaaa… |
Returns: tool_result, id, success, error
OCI DNS: Get Steering Policy Attachment
oracle/dns/steering_policy_attachment_get · Action
Fetch a single Oracle Cloud DNS steering policy attachment by OCID — the policy it binds, the zone and domain it serves, and its lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the attachment picker) | |
| Steering Policy Attachment OCID | string | Required | ocid1.dns-steering-policy-attachment.oc1..aaaa… |
Returns: tool_result, attachment, id, success, error
OCI DNS: List Steering Policy Attachments
oracle/dns/steering_policy_attachment_list · Action
List the Oracle Cloud DNS steering-policy attachments in a compartment, optionally filtered by steering policy, zone or domain. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Steering Policy OCID | string | Only attachments of this steering policy (optional) | |
| Zone OCID | string | Only attachments on this zone (optional) | |
| Domain | string | Only the attachment on this exact domain, e.g. www.example.com (optional) |
Returns: tool_result, attachments, count, truncated, success, error
OCI DNS: Update Steering Policy Attachment
oracle/dns/steering_policy_attachment_update · Action
Update an Oracle Cloud DNS steering policy attachment's friendly display name, leaving its policy, zone and domain binding untouched.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the attachment picker) | |
| Steering Policy Attachment OCID | string | Required | ocid1.dnssteeringpolicyattachment.oc1..aaaa… |
| Display Name | string | New friendly name (leave blank to keep the current name) |
Returns: tool_result, attachment, id, lifecycle_state, success, error
OCI DNS: Change Steering Policy Compartment
oracle/dns/steering_policy_change_compartment · Action
Move an Oracle Cloud DNS steering policy into a different compartment by its OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the steering-policy picker) | |
| Steering Policy OCID | string | Required | ocid1.dns-steering-policy.oc1..aaaa… |
| Target Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — the compartment to move the policy into |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Create Steering Policy
oracle/dns/steering_policy_create · Action
Create a traffic-management steering policy (failover, load-balance, or geo/ASN/IP routing) in a compartment. Attach it to a domain with Create Steering Policy Attachment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name | string | Required | Friendly name for the policy |
| Template | string | Required | The policy behaviour — choices: Failover, Load Balance, Route by Geo, Route by ASN, Route by IP, Custom |
| TTL (seconds) | string | The record TTL the policy serves, e.g. 30 (optional) | |
| Answers (JSON array) | text | [{"name":"web-1","rtype":"A","rdata":"10.0.0.5","pool":"primary"}] — the candidate records (optional) | |
| Rules (JSON array) | text | The template's rules in order, e.g. [{"ruleType":"FILTER",…},{"ruleType":"WEIGHTED",…},{"ruleType":"LIMIT","defaultCount":1}] — required for templated policies (FAILOVER/LOAD_BALANCE/ROUTE_BY_*); optional for CUSTOM |
Returns: tool_result, steering_policy, id, success, error
OCI DNS: Delete Steering Policy
oracle/dns/steering_policy_delete · Action
Permanently delete an Oracle Cloud DNS steering policy by its OCID. Synchronous — succeeds once the policy is removed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the steering-policy picker) | |
| Steering Policy OCID | string | Required | ocid1.dnssteeringpolicy.oc1..aaaa… |
Returns: tool_result, id, success, error
OCI DNS: Get Steering Policy
oracle/dns/steering_policy_get · Action
Fetch a single Oracle Cloud DNS steering policy by OCID — its template, TTL and rules.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the steering-policy picker) | |
| Steering Policy OCID | string | Required | ocid1.dns-steering-policy.oc1..aaaa… |
Returns: tool_result, steering_policy, id, success, error
OCI DNS: List Steering Policies
oracle/dns/steering_policy_list · Action
List the Oracle Cloud DNS steering policies in a compartment, optionally filtered by display-name text and template. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Contains | string | Only policies whose display name contains this text (optional) | |
| Template | string | Only policies of this template, e.g. LOAD_BALANCE, FAILOVER, ROUTE_BY_GEO (optional) |
Returns: tool_result, steering_policies, count, truncated, success, error
OCI DNS: Update Steering Policy
oracle/dns/steering_policy_update · Action
Update a traffic-management steering policy. Reads the policy first and re-sends its current display name, TTL, template, answers and rules, overwriting only the fields you supply — the answers/rules collections are preserved when their JSON inputs are left blank (UpdateSteeringPolicy is a full-replace PUT).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the steering-policy picker) | |
| Steering Policy OCID | string | Required | ocid1.dnssteeringpolicy.oc1..aaaa… |
| Display Name | string | New friendly name (optional — kept if blank) | |
| TTL (seconds) | string | New record TTL, e.g. 30 (optional — kept if blank) | |
| Template | string | New policy behaviour (optional — kept if blank) — choices: Failover, Load Balance, Route by Geo, Route by ASN, Route by IP, Custom | |
| Answers (JSON array) | text | [{"name":"web-1","rtype":"A","rdata":"10.0.0.5","pool":"primary","isDisabled":false}] — REPLACES every answer; leave blank to keep the current ones | |
| Rules (JSON array) | text | [{"ruleType":"FILTER","defaultAnswerData":[{"shouldKeep":true,"answerCondition":"answer.isDisabled != true"}]},{"ruleType":"LIMIT","defaultCount":1}] — each rule needs ruleType; REPLACES every rule; leave blank to keep the current ones |
Returns: tool_result, steering_policy, id, success, error
06Tsig
OCI DNS: Change TSIG Key Compartment
oracle/dns/tsig_key_change_compartment · Action
Move an Oracle Cloud DNS TSIG key into a different compartment by its OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the TSIG-key picker) | |
| TSIG Key OCID | string | Required | ocid1.dns-tsig-key.oc1..aaaa… |
| Target Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — the compartment to move the key into |
Returns: tool_result, id, success, error
OCI DNS: Create TSIG Key
oracle/dns/tsig_key_create · Action
Create a TSIG key in a compartment, used to authenticate zone transfers to/from external DNS servers.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| TSIG Key Name | string | Required | The key name, e.g. transfer-key |
| Algorithm | string | Required | The TSIG algorithm, e.g. hmac-sha256 |
| Secret | secret | The base64-encoded shared secret (kept as a secret) |
Returns: tool_result, tsig_key, id, success, error
OCI DNS: Delete TSIG Key
oracle/dns/tsig_key_delete · Action
Permanently delete an Oracle Cloud DNS TSIG key by its OCID. Synchronous — succeeds once the key is removed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the TSIG-key picker) | |
| TSIG Key OCID | string | Required | ocid1.dns-tsig-key.oc1..aaaa… |
Returns: tool_result, id, success, error
OCI DNS: Get TSIG Key
oracle/dns/tsig_key_get · Action
Fetch a single Oracle Cloud DNS TSIG key by OCID — its name, algorithm and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the TSIG-key picker) | |
| TSIG Key OCID | string | Required | ocid1.dns-tsig-key.oc1..aaaa… |
Returns: tool_result, tsig_key, id, success, error
OCI DNS: List TSIG Keys
oracle/dns/tsig_key_list · Action
List the Oracle Cloud DNS TSIG keys in a compartment, optionally filtered by exact name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Name | string | Only the TSIG key with this exact name (optional) |
Returns: tool_result, tsig_keys, count, truncated, success, error
OCI DNS: Update TSIG Key
oracle/dns/tsig_key_update · Action
Update the free-form tags on an existing Oracle Cloud DNS TSIG key. Tags left blank are preserved.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the TSIG key picker) | |
| TSIG Key OCID | string | Required | ocid1.dns-tsig-key.oc1..aaaa… — the key to update |
| Free-form Tags (JSON) | string | JSON object, e.g. {"env":"prod"} — leave blank to keep the current tags |
Returns: tool_result, tsig_key, id, success, error
07View
OCI DNS: Change View Compartment
oracle/dns/view_change_compartment · Action
Move an Oracle Cloud private-DNS view into a different compartment. Asynchronous — returns a work-request id; poll Get View to confirm the new compartment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the view picker) | |
| View OCID | string | Required | ocid1.dnsview.oc1..aaaa… — the view to move |
| Target Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — the compartment to move the view into |
| Scope | string | GLOBAL (public) or PRIVATE — views are private DNS — choices: Global (public), Private |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Create View
oracle/dns/view_create · Action
Create a private-DNS view in a compartment — the container that holds private zones. Private DNS only (PRIVATE scope).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name | string | Required | Friendly name for the view |
Returns: tool_result, view, id, success, error
OCI DNS: Delete View
oracle/dns/view_delete · Action
Permanently delete an Oracle Cloud DNS view by its OCID. Asynchronous — returns a work-request id; poll Get View (it will 404 once gone).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the view picker) | |
| View OCID | string | Required | ocid1.dnsview.oc1..aaaa… — the view to delete |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private views — choices: Global (public), Private |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Get View
oracle/dns/view_get · Action
Fetch a single Oracle Cloud private-DNS view by OCID — the namespace of zones a resolver serves, with its lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the view picker) | |
| View OCID | string | Required | ocid1.dns-view.oc1..aaaa… |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, view, id, success, error
OCI DNS: List Views
oracle/dns/view_list · Action
List the Oracle Cloud DNS views in a compartment, optionally filtered by display name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name | string | Only views with this exact display name (optional) | |
| Scope | string | GLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, views, count, truncated, success, error
OCI DNS: Update View
oracle/dns/view_update · Action
Rename an Oracle Cloud private-DNS view and/or replace its free-form tags. Reads the current view first so unset fields are preserved.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the view picker) | |
| View OCID | string | Required | ocid1.dnsview.oc1..aaaa… — the view to update |
| Display Name | string | New friendly name (leave blank to keep the current name) | |
| Free-form Tags (JSON) | string | {"env":"prod"} — replaces all free-form tags; leave blank to keep the current ones | |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private views — choices: Global (public), Private |
Returns: tool_result, view, id, success, error
08Zone
OCI DNS: Change Zone Compartment
oracle/dns/zone_change_compartment · Action
Move an Oracle Cloud DNS zone into a different compartment. Asynchronous — returns a work-request id; poll Get Zone to confirm the new compartment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Target Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — the compartment to move the zone into |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Create Zone
oracle/dns/zone_create · Action
Create an Oracle Cloud DNS zone in a compartment — a public (GLOBAL) or private zone. Returns the zone's OCID immediately plus a work-request id; poll Get Zone until it is ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Zone Name | string | Required | The fully-qualified zone name, e.g. example.com |
| Zone Type | string | PRIMARY (default) or SECONDARY — choices: Primary, Secondary | |
| External Masters (JSON array) | text | [{"address":"192.0.2.1","port":53,"tsigKeyId":"ocid1.dnstsigkey.oc1..aaaa…"}] — REQUIRED for a SECONDARY zone (the masters it transfers from); ignored for PRIMARY | |
| Scope | string | GLOBAL (public, default) or PRIVATE — choices: Global (public), Private | |
| View OCID | string | Required for a PRIVATE zone — the view it belongs to (optional) | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, zone, id, lifecycle_state, work_request_id, success, error
OCI DNS: Create Zone from Zone File
oracle/dns/zone_create_from_file · Action
Create an Oracle Cloud DNS zone by importing a raw BIND-format zone file — provisioning the zone and every record it declares in one call. Returns the zone's OCID immediately plus a work-request id; poll Get Zone until it is ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Zone File (BIND format) | text | Required | The full BIND-format zone file text, e.g. $ORIGIN example.com. @ IN SOA … |
| Scope | string | GLOBAL (public, default) or PRIVATE — choices: Global (public), Private | |
| View OCID | string | Required for a PRIVATE zone — the view it belongs to (optional) |
Returns: tool_result, zone, id, lifecycle_state, work_request_id, success, error
OCI DNS: Delete Zone
oracle/dns/zone_delete · Action
Permanently delete an Oracle Cloud DNS zone by name or OCID. Asynchronous — returns a work-request id; poll Get Zone (it will 404 once gone).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Promote Zone DNSSEC Key Version
oracle/dns/zone_dnssec_promote_key_version · Action
Promote a staged DNSSEC key version on an Oracle Cloud DNS zone, making it the active key. Runs asynchronously and returns a work-request id.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone OCID | string | Required | The OCID of the zone whose DNSSEC key version to promote |
| DNSSEC Key Version UUID | string | Required | The UUID of the staged DnssecKeyVersion to promote |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, work_request_id, id, success, error
OCI DNS: Stage Zone DNSSEC Key Version
oracle/dns/zone_dnssec_stage_key_version · Action
Stage a new successor DNSSEC key version on an Oracle Cloud DNS zone, given the UUID of the key version it succeeds. Asynchronous — returns a work-request id.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone OCID | string | Required | ocid1.dns-zone.oc1..aaaa… (the OCID of the target zone) |
| Predecessor Key Version UUID | string | Required | UUID of the DNSSEC key version to generate a successor for |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, id, work_request_id, success, error
OCI DNS: Get Zone
oracle/dns/zone_get · Action
Fetch a single Oracle Cloud DNS zone by its name or OCID — its type, scope, serial and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, zone, id, lifecycle_state, success, error
OCI DNS: Get Zone Content
oracle/dns/zone_get_content · Action
Export an Oracle Cloud DNS zone as BIND zone-file text — the full set of records for the zone, ready to inspect or migrate.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private | |
| View OCID | string | ocid1.dns-view.oc1..aaaa… — required when accessing a private zone by name (optional) |
Returns: tool_result, content, success, error
OCI DNS: List Zones
oracle/dns/zone_list · Action
List the Oracle Cloud DNS zones in a compartment, optionally filtered by name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Name Contains | string | Only zones whose name contains this text (optional) | |
| Scope | string | GLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, zones, count, truncated, success, error
OCI DNS: List Zone Transfer Servers
oracle/dns/zone_list_transfer_servers · Action
List the Oracle Cloud nameservers that transfer zone data with external nameservers in a compartment, with each server's transfer source/destination role, optionally filtered by GLOBAL/PRIVATE scope.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Scope | string | GLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, servers, count, truncated, success, error
OCI DNS: Get Zone Records
oracle/dns/zone_records_get · Action
Read every record in an Oracle Cloud DNS zone (by name or OCID), optionally filtered by domain and record type. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| Domain Filter | string | Only records at this exact domain, e.g. www.example.com (optional) | |
| Record Type Filter | string | Only records of this type, e.g. A, AAAA, CNAME, MX, TXT (optional) | |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, records, count, truncated, success, error
OCI DNS: Patch Zone Records
oracle/dns/zone_records_patch · Action
Apply a set of record operations (ADD/REMOVE, with optional REQUIRE/PROHIBIT preconditions) to a zone's records in one atomic PATCH — the surgical alternative to replacing a whole RRSet. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Operations (JSON array) | text | Required | [{"domain":"www.example.com","rtype":"A","rdata":"10.0.0.5","ttl":300,"operation":"ADD"},{"domain":"old.example.com","rtype":"A","rdata":"10.0.0.4","operation":"REMOVE"}] — each item: domain, rtype, rdata, ttl, recordHash, operation (ADD/REMOVE/REQUIRE/PROHIBIT) |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, success, error
OCI DNS: Update Zone Records
oracle/dns/zone_records_update · Action
Replace EVERY record in a DNS zone with a supplied set. This is a whole-zone overwrite: any record not in the list you provide is deleted, and the zone ends up holding exactly the records you supply. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN or its OCID |
| Records (JSON array) | text | Required | REPLACES THE WHOLE ZONE. Full record list, e.g. [{"domain":"www.example.com","rtype":"A","rdata":"10.0.0.5","ttl":300}] — every record needs domain, rtype, rdata and ttl. Anything omitted is deleted. |
| Scope | string | GLOBAL or PRIVATE (optional) — choices: Global (public), Private |
Returns: tool_result, records, count, success, error
OCI DNS: Update Zone
oracle/dns/zone_update · Action
Update a DNS zone's external master servers and freeform tags. Reads the zone first and re-sends its current external masters/tags/config, overwriting only the fields you supply — a SECONDARY zone's external masters are preserved when left blank. Returns a work-request id.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the zone picker) | |
| Zone Name or OCID | string | Required | The zone FQDN (e.g. example.com) or its OCID |
| External Masters (JSON array) | text | [{"address":"192.0.2.1","port":53,"tsigKeyId":"ocid1.dnstsigkey.oc1..aaaa…"}] — REPLACES the zone's external masters; leave blank to keep the current ones | |
| Freeform Tags (JSON) | text | {"env":"prod"} — REPLACES the zone's freeform tags; leave blank to keep the current ones | |
| Scope | string | GLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private |
Returns: tool_result, zone, id, work_request_id, success, error
09Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Creating a zone or resolver endpoint, deleting a zone, view or resolver endpoint, staging or promoting a DNSSEC key version, and moving a zone, view, resolver or steering policy between compartments all run asynchronously and return a work-request id, so before a later step depends on the outcome, poll the matching Get action until it settles — a create until the resource reads ACTIVE, a delete until Get reports the resource is gone.
- The whole-zone and whole-domain record Update actions overwrite their entire target — any record you leave out of the supplied set is deleted — so use the Patch actions when you only want to add or remove individual records without disturbing the rest.
- Steering policies, their attachments and TSIG keys carry no Global/Private scope selector, unlike zones, records, views, resolvers and resolver endpoints, and a steering policy can only be attached to a public zone.
- Only a CUSTOM steering policy can be created empty; a templated policy — failover, load-balance, or geo, ASN or IP routing — is rejected unless you supply its answers and rules.
- Private-DNS resolvers are created automatically, one per virtual cloud network, and cannot be provisioned or deleted from a flow — you can list, read, update and move them between compartments, but not create new ones.