1. Support
  2. Integrations
  3. Route 53
AWS 39 nodes

Route 53

AWS integration · 39 node(s) including 1 trigger.

00Overview

Manage your AWS DNS from a flow — create public and private hosted zones, add, update and delete records of every common type, and steer traffic with weighted, latency, failover and alias routing supplied as record-set JSON. Monitor endpoints with health checks, switch on DNSSEC signing and query logging, associate VPCs with private zones, and confirm a change has propagated before the flow moves on. You can even simulate a lookup to check Route 53 returns the answer you expect before going live.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting Route 53

  1. Pick how the node signs in with the Authentication dropdown: Access Keys uses an IAM user's own key pair, Assume Role (cross-account) lets Flomation's own identity assume a role you create in your account, and Managed Role (Credential) reuses an AWS role credential already stored in Flomation.
  2. For Access Keys, sign in to the AWS IAM console → Users, open or create a user that has the Route 53 permissions you need, then under Security credentials choose Create access key. Copy the Access key ID and Secret access key into the node's AWS Access Key and AWS Secret Key fields, and fill in Session Token only when you are using temporary credentials.
  3. For Assume Role (cross-account), create an IAM role in your account whose trust policy allows Flomation's principal to assume it and whose permissions cover Route 53, then paste its ARN into Role ARN to Assume. If the trust policy sets an External ID, enter the exact same value in Assume Role External ID.
  4. Set Region to any valid region such as eu-west-2 — it is required on every node even though Route 53 is global — but use us-east-1 when working with DNSSEC KMS keys or query-logging log groups, which must live in that region.
  5. Store the secret half of your credentials as a Flomation environment secret (e.g. route53_secret) and select it in the node's matching AWS Secret Key field, so the value is never written into the flow itself.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Activate

AWS Route 53 Activate Key Signing Key

aws/route53/activate_key_signing_key · Action

Activate a DNSSEC key-signing key (KSK) in a hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
Key Signing Key NamestringRequiredmy_ksk

Returns: tool_result, change_id

03Associate

AWS Route 53 Associate VPC With Hosted Zone

aws/route53/associate_vpc_with_hosted_zone · Action

Associate an Amazon VPC with a private Route 53 hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ
VPC IDstringRequiredvpc-0abc123
VPC RegionstringRequiredeu-west-2
CommentstringOptional

Returns: tool_result, change_id

04Change

AWS Route 53 Change Records

aws/route53/change_resource_record_sets · Action

Create/delete/upsert DNS records; record_set JSON enables alias/weighted routing.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
ActionstringRequiredchoices: Create, Delete, Upsert (create or update)
Record NamestringRequiredwww.example.com
Record Typestringchoices: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA, PTR, SOA
TTL (seconds)integer300
Values (comma-separated)string192.0.2.1, 192.0.2.2
Comment (optional)string
Record Set JSON (override for alias/weighted/latency/failover routing)string{"Name":"www.example.com","Type":"A","AliasTarget":{...}}

Returns: tool_result, change_id, status

AWS Route 53 Change Tags

aws/route53/change_tags_for_resource · Action

Add, edit or remove tags on a Route 53 hosted zone or health check.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource TypestringRequiredchoices: Hosted Zone, Health Check
Resource IDstringRequired
Tags to Add/Editkey_value_array
Tag Keys to Remove (comma-separated)string

Returns: tool_result

05Create

AWS Route 53 Create Health Check

aws/route53/create_health_check · Action

Create a Route 53 health check monitoring an endpoint, domain or alarm.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Caller ReferencestringOptional — unique idempotency token (auto-generated if blank)
TypestringRequiredchoices: HTTP, HTTPS, HTTP String Match, HTTPS String Match, TCP, Calculated, CloudWatch Metric
IP AddressstringOptional — 192.0.2.44
Fully Qualified Domain NamestringOptional — www.example.com
PortintegerOptional — 443
Resource PathstringOptional — /health
Request Interval (seconds)integerOptional — 10 or 30
Failure ThresholdintegerOptional — e.g. 3
Search StringstringOptional — required for *_STR_MATCH types

Returns: tool_result, health_check_id

AWS Route 53 Create Hosted Zone

aws/route53/create_hosted_zone · Action

Create a public or private Route 53 hosted zone for a domain.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Domain NamestringRequiredexample.com
Caller ReferencestringOptional — a unique idempotency token
CommentstringOptional
Private Zoneboolean
VPC ID (private zone)stringvpc-0abc123
VPC Region (private zone)stringeu-west-2

Returns: tool_result, hosted_zone_id, name, name_servers

AWS Route 53 Create Key Signing Key

aws/route53/create_key_signing_key · Action

Create a DNSSEC key-signing key (KSK) for a hosted zone using a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
KMS Key ARNstringRequiredarn:aws:kms:us-east-1:111122223333:key/...
Key Signing Key NamestringRequiredmy_ksk
Initial StatusstringRequiredchoices: Active, Inactive
Caller ReferencestringOptional — a unique idempotency token

Returns: tool_result, key_signing_key, change_id

AWS Route 53 Create Query Logging

aws/route53/create_query_logging_config · Action

Enable DNS query logging to CloudWatch for a public hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
CloudWatch Logs Log Group ARNstringRequiredarn:aws:logs:us-east-1:123456789012:log-group:/route53/example

Returns: tool_result, query_logging_config_id

AWS Route 53 Create VPC Association Authorization

aws/route53/create_vpc_association_authorization · Action

Authorise a VPC in another account to associate with a private hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ
VPC IDstringRequiredvpc-0abc123
VPC RegionstringRequiredeu-west-2

Returns: tool_result, hosted_zone_id, vpc_id

06Deactivate

AWS Route 53 Deactivate Key Signing Key

aws/route53/deactivate_key_signing_key · Action

Deactivate a DNSSEC key-signing key (KSK) in a hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
Key Signing Key NamestringRequiredmy_ksk

Returns: tool_result, change_id

07Delete

AWS Route 53 Delete Health Check

aws/route53/delete_health_check · Action

Delete a Route 53 health check by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Health Check IDstringRequired

Returns: tool_result

AWS Route 53 Delete Hosted Zone

aws/route53/delete_hosted_zone · Action

Delete a Route 53 hosted zone by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ

Returns: tool_result, change_id

AWS Route 53 Delete Key Signing Key

aws/route53/delete_key_signing_key · Action

Delete a DNSSEC key-signing key (KSK) from a hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
Key Signing Key NamestringRequiredmy_ksk

Returns: tool_result, change_id

AWS Route 53 Delete Query Logging

aws/route53/delete_query_logging_config · Action

Disable a Route 53 DNS query logging configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Query Logging Config IDstringRequired

Returns: tool_result

AWS Route 53 Delete VPC Association Authorization

aws/route53/delete_vpc_association_authorization · Action

Remove authorisation for a cross-account VPC to associate with a private hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ
VPC IDstringRequiredvpc-0abc123
VPC RegionstringRequiredeu-west-2

Returns: tool_result, hosted_zone_id, vpc_id

08Disable

AWS Route 53 Disable Hosted Zone DNSSEC

aws/route53/disable_hosted_zone_dnssec · Action

Disable DNSSEC signing for a Route 53 hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC

Returns: tool_result, change_id

09Disassociate

AWS Route 53 Disassociate VPC From Hosted Zone

aws/route53/disassociate_vpc_from_hosted_zone · Action

Remove an Amazon VPC from a private Route 53 hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ
VPC IDstringRequiredvpc-0abc123
VPC RegionstringRequiredeu-west-2

Returns: tool_result, change_id

10Enable

AWS Route 53 Enable Hosted Zone DNSSEC

aws/route53/enable_hosted_zone_dnssec · Action

Enable DNSSEC signing for a Route 53 hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC

Returns: tool_result, change_id

11Get

AWS Route 53 Get Change

aws/route53/get_change · Action

Check a Route 53 change's propagation status (PENDING/INSYNC).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Change IDstringRequired/change/C1234567890ABC

Returns: tool_result, status, submitted_at

AWS Route 53 Get DNSSEC

aws/route53/get_dnssec · Action

Get the DNSSEC signing status and key-signing keys for a hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC

Returns: tool_result, status, key_signing_keys

AWS Route 53 Get Health Check

aws/route53/get_health_check · Action

Fetch the configuration of a Route 53 health check by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Health Check IDstringRequired

Returns: tool_result, type, fully_qualified_domain_name, ip_address, port, resource_path

AWS Route 53 Get Health Check Count

aws/route53/get_health_check_count · Action

Get the total number of Route 53 health checks in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, count

AWS Route 53 Get Health Check Last Failure Reason

aws/route53/get_health_check_last_failure_reason · Action

Retrieve the last failure reason reported by each Route 53 health checker.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Health Check IDstringRequiredabcdef11-2222-3333-4444-555555fedcba

Returns: tool_result, observations, count

AWS Route 53 Get Health Check Status

aws/route53/get_health_check_status · Action

Get per-region status observations for a Route 53 health check.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Health Check IDstringRequired

Returns: tool_result, observations, count

AWS Route 53 Get Hosted Zone

aws/route53/get_hosted_zone · Action

Fetch details of a Route 53 hosted zone by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ

Returns: tool_result, name, record_count, private_zone, name_servers

AWS Route 53 Get Hosted Zone Count

aws/route53/get_hosted_zone_count · Action

Return the number of Route 53 hosted zones in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, count

AWS Route 53 Get Query Logging Config

aws/route53/get_query_logging_config · Action

Retrieve a Route 53 DNS query logging configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Query Logging Config IDstringRequired0123456789abcdef

Returns: tool_result, hosted_zone_id, cloud_watch_logs_log_group_arn

12List

AWS Route 53 List Health Checks

aws/route53/list_health_checks · Action

List all Route 53 health checks in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, health_checks, count

AWS Route 53 List Hosted Zones

aws/route53/list_hosted_zones · Action

List all Route 53 hosted zones in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, count, hosted_zones

AWS Route 53 List Hosted Zones By Name

aws/route53/list_hosted_zones_by_name · Action

List Route 53 hosted zones ordered by name, optionally filtered by DNS name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
DNS Name Filterstringexample.com (optional prefix)
Max ItemsintegerOptional

Returns: tool_result, count, hosted_zones

AWS Route 53 List Hosted Zones By VPC

aws/route53/list_hosted_zones_by_vpc · Action

List private hosted zones that a specified VPC is associated with.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc123
VPC RegionstringRequiredeu-west-2

Returns: tool_result, hosted_zone_summaries, count

AWS Route 53 List Query Logging

aws/route53/list_query_logging_configs · Action

List Route 53 DNS query logging configurations, optionally filtered by zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone ID (optional filter)string

Returns: tool_result, configs, count

AWS Route 53 List Records

aws/route53/list_resource_record_sets · Action

List the DNS records in a Route 53 hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
Start Record Name (optional)string
Start Record Type (optional)string
Max Items (optional)integer

Returns: tool_result, records, count

AWS Route 53 List Tags

aws/route53/list_tags_for_resource · Action

List the tags on a Route 53 hosted zone or health check.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource TypestringRequiredchoices: Hosted Zone, Health Check
Resource IDstringRequired

Returns: tool_result, tags

AWS Route 53 List VPC Association Authorizations

aws/route53/list_vpc_association_authorizations · Action

List VPCs authorised to associate with a private hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ

Returns: tool_result, vpcs, count

13Test

AWS Route 53 Test DNS Answer

aws/route53/test_dns_answer · Action

Simulate a DNS query and see what Route 53 would return for a record.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ1234567890ABC
Record NamestringRequiredwww.example.com
Record TypestringRequiredchoices: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA, PTR, SOA
Resolver IP (optional)string8.8.8.8

Returns: tool_result, record_data, response_code

14Update

AWS Route 53 Update Health Check

aws/route53/update_health_check · Action

Update the settings of an existing Route 53 health check.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Health Check IDstringRequired
IP AddressstringOptional — 192.0.2.44
Fully Qualified Domain NamestringOptional — www.example.com
PortintegerOptional — 443
Resource PathstringOptional — /health
Failure ThresholdintegerOptional — e.g. 3
Search StringstringOptional — for *_STR_MATCH types

Returns: tool_result, health_check_id

AWS Route 53 Update Hosted Zone Comment

aws/route53/update_hosted_zone_comment · Action

Update the comment on a Route 53 hosted zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Hosted Zone IDstringRequiredZ0123456789ABCDEFGHIJ
CommentstringThe new comment

Returns: tool_result, hosted_zone_id, name

15Triggers

Route 53 Health Check Trigger

trigger/route53_health_check · Trigger

Triggers a flow when a Route 53 health check goes unhealthy (or recovers). Polls GetHealthCheckStatus.

FieldTypeDetails
Regionstringeu-west-2 (ignored — Route 53 is global)
Health Check IDstringRequired
Fire OnstringUnhealthy — choices: Becomes unhealthy, Becomes healthy, Any change
Poll Intervalstringe.g. 60s, 5m

Returns: health_check_id, status, previous_status, healthy_count, unhealthy_count, triggered_at

16Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Route 53 is a global service, so hosted zones and records are not tied to the Region field, which is required only to sign the request and does not change where your DNS data lives.
  • Record changes are applied asynchronously: the node returns a change with a PENDING status that only becomes INSYNC once the update has propagated across all Route 53 name servers, which you can poll with the Get Change action.
  • Deleting a record requires the name, type, TTL and every value to match the existing record set exactly, so supply the same TTL and values it was created with rather than relying on the default TTL of 300 seconds.
  • DNSSEC key-signing keys must reference a customer-managed KMS key located in the us-east-1 region, whatever Region is set on the node.
  • Query logging can only stream to a CloudWatch Logs log group in the us-east-1 region, and that log group's resource policy must grant Route 53 permission to write to it.
  • Leaving Caller Reference blank makes the node derive a stable token from the domain name, so re-running a Create Hosted Zone step returns an already-exists error instead of silently creating a duplicate zone.