1. Support
  2. Integrations
  3. DNS
Oracle Cloud 54 nodes

DNS

Oracle Cloud integration · 54 node(s).

00Overview

Run Oracle Cloud DNS from a flow — create and delete public and private zones, read and rewrite the records inside them, and import or export a whole zone as a BIND file in a single step. Steer live traffic with failover, load-balancing and geo, ASN or IP routing policies, and manage the private-DNS side too: views, resolvers, resolver endpoints and the TSIG keys that authenticate zone transfers. Record reads and writes are synchronous, so a flow can look up a record and act on the answer in the same run.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting DNS

  1. Every DNS node opens with an Authentication dropdown offering two methods: Connect Oracle Cloud (recommended), which points the node at a managed Oracle Cloud connection, and API signing key (advanced), which lets you enter raw signing-key credentials directly on the node.
  2. With Connect Oracle Cloud, pick a connected Oracle Cloud account in each node's Oracle Cloud connection field — choosing one auto-fills the signing credentials, so the node needs nothing further to authenticate.
  3. For API signing key (advanced), sign in to the OCI Console, open the profile menu → My profile → API keys → Add API key, and let Oracle generate the key pair; the confirmation dialog shows a configuration snippet with your Tenancy OCID, User OCID, Region and Key Fingerprint — copy each into the matching node field. A freshly added key can take a minute or two to become active in OCI, so let an initial test retry before treating a failure as real.
  4. Set the Compartment OCID (required) to the compartment that holds — or should hold — the zones you are automating; you can copy it from Identity & Security → Compartments in the console, or use the tenancy OCID for the root compartment.
  5. Never paste the private key inline — store the Private Key (PEM) (and any Private Key Passphrase) as a Flomation environment secret (e.g. dns_secret) and select it in the node's matching field.
FieldTypeDetails
AuthenticationstringConnect Oracle Cloud, API signing key (advanced)
Oracle Cloud connectioncredentialPick a connected Oracle Cloud account
Regionstringe.g. uk-london-1
Private Key (PEM)secretThe API signing private key — full PEM, incl. BEGIN/END lines
Private Key PassphrasesecretOnly if the key is encrypted (optional)
Tenancy OCIDstringocid1.tenancy.oc1..aaaa…
User OCIDstringocid1.user.oc1..aaaa…
Key Fingerprintstringaa:bb:cc:… fingerprint of the uploaded API key
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Domain

OCI DNS: Delete Domain Records

oracle/dns/domain_records_delete · Action

Delete ALL records at a domain (FQDN) within an Oracle Cloud DNS zone. Synchronous — every record type at that domain is removed.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
Domain (FQDN)stringRequiredThe FQDN whose records to delete, e.g. www.example.com — ALL record types are removed
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, id, domain, success, error

OCI DNS: Get Domain Records

oracle/dns/domain_records_get · Action

List all Oracle Cloud DNS records at a single domain (FQDN) within a zone, optionally filtered by record type and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
Domain (FQDN)stringRequiredThe fully-qualified domain within the zone (e.g. www.example.com)
Record TypestringOnly records of this type, e.g. A, AAAA, CNAME, MX, TXT (optional)
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, records, count, truncated, success, error

OCI DNS: Patch Domain Records

oracle/dns/domain_records_patch · Action

Apply a list of add/remove/precondition operations to the records at one domain (across all record types) in a zone — a targeted alternative to replacing a whole RRSet. Synchronous.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
DomainstringRequiredThe fully-qualified record name, e.g. www.example.com
Operations (JSON array)textRequired[{"operation":"ADD","rtype":"A","rdata":"10.0.0.5","ttl":300}] — each item: operation (REQUIRE/PROHIBIT/ADD/REMOVE) + rtype/rdata/ttl
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, success, error

OCI DNS: Update Domain Records

oracle/dns/domain_records_update · Action

Replace ALL records at one domain of a zone — every record type — with a supplied set. This rewrites the whole domain: any record type not present in the supplied set is deleted. Synchronous.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
DomainstringRequiredThe fully-qualified record name, e.g. www.example.com
Records (JSON array)textRequired[{"rtype":"A","rdata":"10.0.0.5","ttl":300}] — rtype + rdata + ttl per record; domain defaults to the one above (REPLACES EVERY record at the domain, all types)
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, success, error

03Resolver

OCI DNS: Change Resolver Compartment

oracle/dns/resolver_change_compartment · Action

Move an Oracle Cloud private-DNS resolver, along with its protected default view and endpoints, into a different compartment.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dns-resolver.oc1..aaaa…
Target Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — the compartment to move the resolver into
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Create Resolver Endpoint

oracle/dns/resolver_endpoint_create · Action

Create a VNIC resolver endpoint under a private-DNS resolver — a forwarding and/or listening address in a subnet of the resolver's VCN. Returns the endpoint immediately plus a work-request id; poll Get Resolver Endpoint until it is ACTIVE.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dnsresolver.oc1..aaaa… — the parent resolver
Endpoint NamestringRequiredUnique name within the resolver, e.g. forwarder-1
Subnet OCIDstringRequiredocid1.subnet.oc1..aaaa… — must be in the resolver's VCN
Is ForwardingbooleanEndpoint forwards outbound queries
Is ListeningbooleanEndpoint listens for inbound queries
Forwarding AddressstringIP to send forwarded queries from — auto-assigned if blank (optional)
Listening AddressstringIP to listen for queries on — auto-assigned if blank (optional)
Network Security Group OCIDsstringComma-separated NSG OCIDs in the same VCN (optional)
ScopestringGLOBAL or PRIVATE — resolver endpoints are private DNS — choices: Global (public), Private

Returns: tool_result, resolver_endpoint, name, work_request_id, success, error

OCI DNS: Delete Resolver Endpoint

oracle/dns/resolver_endpoint_delete · Action

Permanently delete an Oracle Cloud DNS resolver endpoint by its parent resolver OCID and endpoint name. Asynchronous — returns a work-request id.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dnsresolver.oc1..aaaa… — the parent resolver
Endpoint NamestringRequiredThe resolver endpoint name to delete
ScopestringGLOBAL (public) or PRIVATE — only needed for private resolvers — choices: Global (public), Private

Returns: tool_result, name, work_request_id, success, error

OCI DNS: Get Resolver Endpoint

oracle/dns/resolver_endpoint_get · Action

Fetch a single Oracle Cloud private-DNS resolver endpoint by its parent resolver OCID and endpoint name — its addresses, forwarding/listening role and lifecycle state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dns-resolver.oc1..aaaa…
Endpoint NamestringRequiredThe resolver endpoint name (e.g. my-forwarding-endpoint)
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, resolver_endpoint, resolver_id, success, error

OCI DNS: List Resolver Endpoints

oracle/dns/resolver_endpoint_list · Action

List the endpoints of an Oracle Cloud DNS resolver, optionally filtered by name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dnsresolver.oc1..aaaa… — the resolver whose endpoints to list
NamestringOnly the endpoint with this exact name (optional)
ScopestringGLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, resolver_endpoints, count, truncated, success, error

OCI DNS: Update Resolver Endpoint

oracle/dns/resolver_endpoint_update · Action

Update an Oracle Cloud DNS resolver endpoint's network security groups, preserving its existing tags and configuration.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dnsresolver.oc1..aaaa… — the parent resolver
Endpoint NamestringRequiredThe resolver endpoint's name
Network Security Group OCIDsstringComma-separated NSG OCIDs (leave blank to keep the current set)
ScopestringGLOBAL (public) or PRIVATE — only needed for private resolvers — choices: Global (public), Private

Returns: tool_result, endpoint, name, resolver_id, lifecycle_state, work_request_id, success, error

OCI DNS: Get Resolver

oracle/dns/resolver_get · Action

Fetch a single Oracle Cloud private-DNS resolver by OCID — the resolver that answers DNS for a VCN, with its rules and endpoints.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dns-resolver.oc1..aaaa…
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, resolver, id, success, error

OCI DNS: List Resolvers

oracle/dns/resolver_list · Action

List the Oracle Cloud DNS resolvers in a compartment, optionally filtered by display name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display NamestringOnly resolvers with this exact display name (optional)
ScopestringGLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, resolvers, count, truncated, success, error

OCI DNS: Update Resolver

oracle/dns/resolver_update · Action

Update a private-DNS resolver's display name, freeform tags, attached views and forwarding rules. Reads the resolver first and RE-SENDS its current attached views and rules so they are preserved — the update is a full-replace PUT. Attached views/rules are only changed when you supply attached_views_json/rules_json; everything else is left blank to keep the current value.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the resolver picker)
Resolver OCIDstringRequiredocid1.dns-resolver.oc1..aaaa…
Display NamestringNew display name — leave blank to keep the current one
Freeform Tags (JSON)text{"env":"prod"} — REPLACES the resolver's freeform tags; leave blank to keep the current ones
Attached Views (JSON array)text[{"viewId":"ocid1.dnsview.oc1..aaaa…"}] — REPLACES the attached views; leave blank to keep the current ones
Rules (JSON array)text[{"action":"FORWARD","destinationAddresses":["10.0.0.2"],"sourceEndpointName":"ep1","qnameCoverConditions":["internal.example.com"]}] — REPLACES the forwarding rules; leave blank to keep the current ones
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, resolver, id, work_request_id, success, error

04Rrset

OCI DNS: Delete RRSet

oracle/dns/rrset_delete · Action

Delete every record of one type (RRSet) at a domain within an Oracle Cloud DNS zone. Synchronous — the RRSet is gone once it returns.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
DomainstringRequiredThe FQDN within the zone, e.g. www.example.com
Record TypestringRequirede.g. A, AAAA, CNAME, MX, TXT
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, id, domain, rtype, success, error

OCI DNS: Get RRSet

oracle/dns/rrset_get · Action

Read all records of one RRSet — the records at a given domain of a given type, e.g. the A records for www.example.com.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
DomainstringRequiredThe fully-qualified record name, e.g. www.example.com
Record TypestringRequiredA, AAAA, CNAME, MX, TXT, NS, SRV, …
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, truncated, success, error

OCI DNS: Patch RRSet

oracle/dns/rrset_patch · Action

Add or remove individual records within one RRSet (the records at a domain of a given type) without replacing the whole set — the surgical alternative to Update RRSet. Each operation names an ADD/REMOVE (or REQUIRE/PROHIBIT precondition). Synchronous.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
DomainstringRequiredThe fully-qualified record name, e.g. www.example.com
Record TypestringRequiredA, AAAA, CNAME, MX, TXT, NS, …
Operations (JSON array)textRequired[{"operation":"ADD","rdata":"10.0.0.5","ttl":300},{"operation":"REMOVE","rdata":"10.0.0.4"}] — operation is ADD/REMOVE (or REQUIRE/PROHIBIT precondition); domain/rtype default to the ones above
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, success, error

OCI DNS: Update RRSet

oracle/dns/rrset_update · Action

Replace all records of one RRSet (the records at a domain of a given type) with a supplied set — the primary way to set a record, e.g. point www.example.com at a new IP. Synchronous.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
DomainstringRequiredThe fully-qualified record name, e.g. www.example.com
Record TypestringRequiredA, AAAA, CNAME, MX, TXT, NS, …
Records (JSON array)textRequired[{"rdata":"10.0.0.5","ttl":300}] — rdata + ttl; domain/rtype default to the ones above (REPLACES the whole RRSet)
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, success, error

05Steering

OCI DNS: Create Steering Policy Attachment

oracle/dns/steering_policy_attachment_create · Action

Attach a steering policy to a domain within a public zone, so DNS queries for that domain are answered by the policy's traffic-management logic. Returns a work-request id when provisioning is asynchronous.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Steering Policy OCIDstringRequiredocid1.dns-steering-policy.oc1..aaaa… — the policy to attach
Zone OCIDstringRequiredocid1.dns-zone.oc1..aaaa… — must be a public zone
Domain NamestringRequiredThe domain within the zone, e.g. www.example.com
Display NamestringFriendly name for the attachment (optional)

Returns: tool_result, attachment, id, work_request_id, success, error

OCI DNS: Delete Steering Policy Attachment

oracle/dns/steering_policy_attachment_delete · Action

Detach a steering policy from a domain by deleting its attachment (by OCID). Synchronous — the attachment is gone once this succeeds.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the attachment picker)
Steering Policy Attachment OCIDstringRequiredocid1.dnssteeringpolicyattachment.oc1..aaaa…

Returns: tool_result, id, success, error

OCI DNS: Get Steering Policy Attachment

oracle/dns/steering_policy_attachment_get · Action

Fetch a single Oracle Cloud DNS steering policy attachment by OCID — the policy it binds, the zone and domain it serves, and its lifecycle state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the attachment picker)
Steering Policy Attachment OCIDstringRequiredocid1.dns-steering-policy-attachment.oc1..aaaa…

Returns: tool_result, attachment, id, success, error

OCI DNS: List Steering Policy Attachments

oracle/dns/steering_policy_attachment_list · Action

List the Oracle Cloud DNS steering-policy attachments in a compartment, optionally filtered by steering policy, zone or domain. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Steering Policy OCIDstringOnly attachments of this steering policy (optional)
Zone OCIDstringOnly attachments on this zone (optional)
DomainstringOnly the attachment on this exact domain, e.g. www.example.com (optional)

Returns: tool_result, attachments, count, truncated, success, error

OCI DNS: Update Steering Policy Attachment

oracle/dns/steering_policy_attachment_update · Action

Update an Oracle Cloud DNS steering policy attachment's friendly display name, leaving its policy, zone and domain binding untouched.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the attachment picker)
Steering Policy Attachment OCIDstringRequiredocid1.dnssteeringpolicyattachment.oc1..aaaa…
Display NamestringNew friendly name (leave blank to keep the current name)

Returns: tool_result, attachment, id, lifecycle_state, success, error

OCI DNS: Change Steering Policy Compartment

oracle/dns/steering_policy_change_compartment · Action

Move an Oracle Cloud DNS steering policy into a different compartment by its OCID.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the steering-policy picker)
Steering Policy OCIDstringRequiredocid1.dns-steering-policy.oc1..aaaa…
Target Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — the compartment to move the policy into

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Create Steering Policy

oracle/dns/steering_policy_create · Action

Create a traffic-management steering policy (failover, load-balance, or geo/ASN/IP routing) in a compartment. Attach it to a domain with Create Steering Policy Attachment.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display NamestringRequiredFriendly name for the policy
TemplatestringRequiredThe policy behaviour — choices: Failover, Load Balance, Route by Geo, Route by ASN, Route by IP, Custom
TTL (seconds)stringThe record TTL the policy serves, e.g. 30 (optional)
Answers (JSON array)text[{"name":"web-1","rtype":"A","rdata":"10.0.0.5","pool":"primary"}] — the candidate records (optional)
Rules (JSON array)textThe template's rules in order, e.g. [{"ruleType":"FILTER",…},{"ruleType":"WEIGHTED",…},{"ruleType":"LIMIT","defaultCount":1}] — required for templated policies (FAILOVER/LOAD_BALANCE/ROUTE_BY_*); optional for CUSTOM

Returns: tool_result, steering_policy, id, success, error

OCI DNS: Delete Steering Policy

oracle/dns/steering_policy_delete · Action

Permanently delete an Oracle Cloud DNS steering policy by its OCID. Synchronous — succeeds once the policy is removed.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the steering-policy picker)
Steering Policy OCIDstringRequiredocid1.dnssteeringpolicy.oc1..aaaa…

Returns: tool_result, id, success, error

OCI DNS: Get Steering Policy

oracle/dns/steering_policy_get · Action

Fetch a single Oracle Cloud DNS steering policy by OCID — its template, TTL and rules.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the steering-policy picker)
Steering Policy OCIDstringRequiredocid1.dns-steering-policy.oc1..aaaa…

Returns: tool_result, steering_policy, id, success, error

OCI DNS: List Steering Policies

oracle/dns/steering_policy_list · Action

List the Oracle Cloud DNS steering policies in a compartment, optionally filtered by display-name text and template. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display Name ContainsstringOnly policies whose display name contains this text (optional)
TemplatestringOnly policies of this template, e.g. LOAD_BALANCE, FAILOVER, ROUTE_BY_GEO (optional)

Returns: tool_result, steering_policies, count, truncated, success, error

OCI DNS: Update Steering Policy

oracle/dns/steering_policy_update · Action

Update a traffic-management steering policy. Reads the policy first and re-sends its current display name, TTL, template, answers and rules, overwriting only the fields you supply — the answers/rules collections are preserved when their JSON inputs are left blank (UpdateSteeringPolicy is a full-replace PUT).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the steering-policy picker)
Steering Policy OCIDstringRequiredocid1.dnssteeringpolicy.oc1..aaaa…
Display NamestringNew friendly name (optional — kept if blank)
TTL (seconds)stringNew record TTL, e.g. 30 (optional — kept if blank)
TemplatestringNew policy behaviour (optional — kept if blank) — choices: Failover, Load Balance, Route by Geo, Route by ASN, Route by IP, Custom
Answers (JSON array)text[{"name":"web-1","rtype":"A","rdata":"10.0.0.5","pool":"primary","isDisabled":false}] — REPLACES every answer; leave blank to keep the current ones
Rules (JSON array)text[{"ruleType":"FILTER","defaultAnswerData":[{"shouldKeep":true,"answerCondition":"answer.isDisabled != true"}]},{"ruleType":"LIMIT","defaultCount":1}] — each rule needs ruleType; REPLACES every rule; leave blank to keep the current ones

Returns: tool_result, steering_policy, id, success, error

06Tsig

OCI DNS: Change TSIG Key Compartment

oracle/dns/tsig_key_change_compartment · Action

Move an Oracle Cloud DNS TSIG key into a different compartment by its OCID.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the TSIG-key picker)
TSIG Key OCIDstringRequiredocid1.dns-tsig-key.oc1..aaaa…
Target Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — the compartment to move the key into

Returns: tool_result, id, success, error

OCI DNS: Create TSIG Key

oracle/dns/tsig_key_create · Action

Create a TSIG key in a compartment, used to authenticate zone transfers to/from external DNS servers.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
TSIG Key NamestringRequiredThe key name, e.g. transfer-key
AlgorithmstringRequiredThe TSIG algorithm, e.g. hmac-sha256
SecretsecretThe base64-encoded shared secret (kept as a secret)

Returns: tool_result, tsig_key, id, success, error

OCI DNS: Delete TSIG Key

oracle/dns/tsig_key_delete · Action

Permanently delete an Oracle Cloud DNS TSIG key by its OCID. Synchronous — succeeds once the key is removed.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the TSIG-key picker)
TSIG Key OCIDstringRequiredocid1.dns-tsig-key.oc1..aaaa…

Returns: tool_result, id, success, error

OCI DNS: Get TSIG Key

oracle/dns/tsig_key_get · Action

Fetch a single Oracle Cloud DNS TSIG key by OCID — its name, algorithm and lifecycle state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the TSIG-key picker)
TSIG Key OCIDstringRequiredocid1.dns-tsig-key.oc1..aaaa…

Returns: tool_result, tsig_key, id, success, error

OCI DNS: List TSIG Keys

oracle/dns/tsig_key_list · Action

List the Oracle Cloud DNS TSIG keys in a compartment, optionally filtered by exact name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
NamestringOnly the TSIG key with this exact name (optional)

Returns: tool_result, tsig_keys, count, truncated, success, error

OCI DNS: Update TSIG Key

oracle/dns/tsig_key_update · Action

Update the free-form tags on an existing Oracle Cloud DNS TSIG key. Tags left blank are preserved.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the TSIG key picker)
TSIG Key OCIDstringRequiredocid1.dns-tsig-key.oc1..aaaa… — the key to update
Free-form Tags (JSON)stringJSON object, e.g. {"env":"prod"} — leave blank to keep the current tags

Returns: tool_result, tsig_key, id, success, error

07View

OCI DNS: Change View Compartment

oracle/dns/view_change_compartment · Action

Move an Oracle Cloud private-DNS view into a different compartment. Asynchronous — returns a work-request id; poll Get View to confirm the new compartment.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the view picker)
View OCIDstringRequiredocid1.dnsview.oc1..aaaa… — the view to move
Target Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — the compartment to move the view into
ScopestringGLOBAL (public) or PRIVATE — views are private DNS — choices: Global (public), Private

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Create View

oracle/dns/view_create · Action

Create a private-DNS view in a compartment — the container that holds private zones. Private DNS only (PRIVATE scope).

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display NamestringRequiredFriendly name for the view

Returns: tool_result, view, id, success, error

OCI DNS: Delete View

oracle/dns/view_delete · Action

Permanently delete an Oracle Cloud DNS view by its OCID. Asynchronous — returns a work-request id; poll Get View (it will 404 once gone).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the view picker)
View OCIDstringRequiredocid1.dnsview.oc1..aaaa… — the view to delete
ScopestringGLOBAL (public) or PRIVATE — only needed for private views — choices: Global (public), Private

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Get View

oracle/dns/view_get · Action

Fetch a single Oracle Cloud private-DNS view by OCID — the namespace of zones a resolver serves, with its lifecycle state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the view picker)
View OCIDstringRequiredocid1.dns-view.oc1..aaaa…
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, view, id, success, error

OCI DNS: List Views

oracle/dns/view_list · Action

List the Oracle Cloud DNS views in a compartment, optionally filtered by display name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display NamestringOnly views with this exact display name (optional)
ScopestringGLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, views, count, truncated, success, error

OCI DNS: Update View

oracle/dns/view_update · Action

Rename an Oracle Cloud private-DNS view and/or replace its free-form tags. Reads the current view first so unset fields are preserved.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the view picker)
View OCIDstringRequiredocid1.dnsview.oc1..aaaa… — the view to update
Display NamestringNew friendly name (leave blank to keep the current name)
Free-form Tags (JSON)string{"env":"prod"} — replaces all free-form tags; leave blank to keep the current ones
ScopestringGLOBAL (public) or PRIVATE — only needed for private views — choices: Global (public), Private

Returns: tool_result, view, id, success, error

08Zone

OCI DNS: Change Zone Compartment

oracle/dns/zone_change_compartment · Action

Move an Oracle Cloud DNS zone into a different compartment. Asynchronous — returns a work-request id; poll Get Zone to confirm the new compartment.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
Target Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — the compartment to move the zone into
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Create Zone

oracle/dns/zone_create · Action

Create an Oracle Cloud DNS zone in a compartment — a public (GLOBAL) or private zone. Returns the zone's OCID immediately plus a work-request id; poll Get Zone until it is ACTIVE.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Zone NamestringRequiredThe fully-qualified zone name, e.g. example.com
Zone TypestringPRIMARY (default) or SECONDARY — choices: Primary, Secondary
External Masters (JSON array)text[{"address":"192.0.2.1","port":53,"tsigKeyId":"ocid1.dnstsigkey.oc1..aaaa…"}] — REQUIRED for a SECONDARY zone (the masters it transfers from); ignored for PRIMARY
ScopestringGLOBAL (public, default) or PRIVATE — choices: Global (public), Private
View OCIDstringRequired for a PRIVATE zone — the view it belongs to (optional)
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, zone, id, lifecycle_state, work_request_id, success, error

OCI DNS: Create Zone from Zone File

oracle/dns/zone_create_from_file · Action

Create an Oracle Cloud DNS zone by importing a raw BIND-format zone file — provisioning the zone and every record it declares in one call. Returns the zone's OCID immediately plus a work-request id; poll Get Zone until it is ACTIVE.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Zone File (BIND format)textRequiredThe full BIND-format zone file text, e.g. $ORIGIN example.com. @ IN SOA …
ScopestringGLOBAL (public, default) or PRIVATE — choices: Global (public), Private
View OCIDstringRequired for a PRIVATE zone — the view it belongs to (optional)

Returns: tool_result, zone, id, lifecycle_state, work_request_id, success, error

OCI DNS: Delete Zone

oracle/dns/zone_delete · Action

Permanently delete an Oracle Cloud DNS zone by name or OCID. Asynchronous — returns a work-request id; poll Get Zone (it will 404 once gone).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Promote Zone DNSSEC Key Version

oracle/dns/zone_dnssec_promote_key_version · Action

Promote a staged DNSSEC key version on an Oracle Cloud DNS zone, making it the active key. Runs asynchronously and returns a work-request id.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone OCIDstringRequiredThe OCID of the zone whose DNSSEC key version to promote
DNSSEC Key Version UUIDstringRequiredThe UUID of the staged DnssecKeyVersion to promote
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, work_request_id, id, success, error

OCI DNS: Stage Zone DNSSEC Key Version

oracle/dns/zone_dnssec_stage_key_version · Action

Stage a new successor DNSSEC key version on an Oracle Cloud DNS zone, given the UUID of the key version it succeeds. Asynchronous — returns a work-request id.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone OCIDstringRequiredocid1.dns-zone.oc1..aaaa… (the OCID of the target zone)
Predecessor Key Version UUIDstringRequiredUUID of the DNSSEC key version to generate a successor for
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, id, work_request_id, success, error

OCI DNS: Get Zone

oracle/dns/zone_get · Action

Fetch a single Oracle Cloud DNS zone by its name or OCID — its type, scope, serial and lifecycle state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, zone, id, lifecycle_state, success, error

OCI DNS: Get Zone Content

oracle/dns/zone_get_content · Action

Export an Oracle Cloud DNS zone as BIND zone-file text — the full set of records for the zone, ready to inspect or migrate.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private
View OCIDstringocid1.dns-view.oc1..aaaa… — required when accessing a private zone by name (optional)

Returns: tool_result, content, success, error

OCI DNS: List Zones

oracle/dns/zone_list · Action

List the Oracle Cloud DNS zones in a compartment, optionally filtered by name and GLOBAL/PRIVATE scope. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Name ContainsstringOnly zones whose name contains this text (optional)
ScopestringGLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, zones, count, truncated, success, error

OCI DNS: List Zone Transfer Servers

oracle/dns/zone_list_transfer_servers · Action

List the Oracle Cloud nameservers that transfer zone data with external nameservers in a compartment, with each server's transfer source/destination role, optionally filtered by GLOBAL/PRIVATE scope.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
ScopestringGLOBAL (public) or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, servers, count, truncated, success, error

OCI DNS: Get Zone Records

oracle/dns/zone_records_get · Action

Read every record in an Oracle Cloud DNS zone (by name or OCID), optionally filtered by domain and record type. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
Domain FilterstringOnly records at this exact domain, e.g. www.example.com (optional)
Record Type FilterstringOnly records of this type, e.g. A, AAAA, CNAME, MX, TXT (optional)
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, records, count, truncated, success, error

OCI DNS: Patch Zone Records

oracle/dns/zone_records_patch · Action

Apply a set of record operations (ADD/REMOVE, with optional REQUIRE/PROHIBIT preconditions) to a zone's records in one atomic PATCH — the surgical alternative to replacing a whole RRSet. Synchronous.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
Operations (JSON array)textRequired[{"domain":"www.example.com","rtype":"A","rdata":"10.0.0.5","ttl":300,"operation":"ADD"},{"domain":"old.example.com","rtype":"A","rdata":"10.0.0.4","operation":"REMOVE"}] — each item: domain, rtype, rdata, ttl, recordHash, operation (ADD/REMOVE/REQUIRE/PROHIBIT)
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, success, error

OCI DNS: Update Zone Records

oracle/dns/zone_records_update · Action

Replace EVERY record in a DNS zone with a supplied set. This is a whole-zone overwrite: any record not in the list you provide is deleted, and the zone ends up holding exactly the records you supply. Synchronous.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN or its OCID
Records (JSON array)textRequiredREPLACES THE WHOLE ZONE. Full record list, e.g. [{"domain":"www.example.com","rtype":"A","rdata":"10.0.0.5","ttl":300}] — every record needs domain, rtype, rdata and ttl. Anything omitted is deleted.
ScopestringGLOBAL or PRIVATE (optional) — choices: Global (public), Private

Returns: tool_result, records, count, success, error

OCI DNS: Update Zone

oracle/dns/zone_update · Action

Update a DNS zone's external master servers and freeform tags. Reads the zone first and re-sends its current external masters/tags/config, overwriting only the fields you supply — a SECONDARY zone's external masters are preserved when left blank. Returns a work-request id.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the zone picker)
Zone Name or OCIDstringRequiredThe zone FQDN (e.g. example.com) or its OCID
External Masters (JSON array)text[{"address":"192.0.2.1","port":53,"tsigKeyId":"ocid1.dnstsigkey.oc1..aaaa…"}] — REPLACES the zone's external masters; leave blank to keep the current ones
Freeform Tags (JSON)text{"env":"prod"} — REPLACES the zone's freeform tags; leave blank to keep the current ones
ScopestringGLOBAL (public) or PRIVATE — only needed for private zones — choices: Global (public), Private

Returns: tool_result, zone, id, work_request_id, success, error

09Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Creating a zone or resolver endpoint, deleting a zone, view or resolver endpoint, staging or promoting a DNSSEC key version, and moving a zone, view, resolver or steering policy between compartments all run asynchronously and return a work-request id, so before a later step depends on the outcome, poll the matching Get action until it settles — a create until the resource reads ACTIVE, a delete until Get reports the resource is gone.
  • The whole-zone and whole-domain record Update actions overwrite their entire target — any record you leave out of the supplied set is deleted — so use the Patch actions when you only want to add or remove individual records without disturbing the rest.
  • Steering policies, their attachments and TSIG keys carry no Global/Private scope selector, unlike zones, records, views, resolvers and resolver endpoints, and a steering policy can only be attached to a public zone.
  • Only a CUSTOM steering policy can be created empty; a templated policy — failover, load-balance, or geo, ASN or IP routing — is rejected unless you supply its answers and rules.
  • Private-DNS resolvers are created automatically, one per virtual cloud network, and cannot be provisioned or deleted from a flow — you can list, read, update and move them between compartments, but not create new ones.