Enabling DNS split authority with OctoDNS
githubengineering.com
githubengineering.com
It also doesn't help with managing the records in the primary provider, requiring either working in a UI or writing using software like OctoDNS to manage it. It's definitely a good option for simpler and stable setups, neither of which is the case for us or many of the people I've talked to. If it fits a situation you have it's worth exploring.
There's an article on ZDnet, http://www.zdnet.com/article/github-open-sources-octodns-new... that does a good job of covering some of the reasons for it that is probably relivant to this.
Terraform is able to manage resources from dyn, route53 and other DNS providers fairly easily.
Terraform requires creating a resource for each record and provider pair. It's good for orchestrating a single provider especially when you're otherwise creating associated resources with Terraform.
The custom DSL for each provider varies thought and I wasn't happy with my attempts at trying to abstract away which provider(s) things were going to using modules. The result wasn't simple enough that anyone at the company, not just engineers, could submit a PR for.
I wish that the terraform language was flexible enough to allow building such abstractions on top of it.
I believe OctoDNS abstracts multiple providers so you just define a single DNS record.
There is a PowerDNS provider, https://github.com/github/octodns/blob/master/octodns/provid... which we use for some internal DNS purposes. We actually plan to talk about that in a future post to compliment this one's focus on our external DNS setup.
A lot of thought was put into making it relatively easy to add new ones. Writing the tests is generally the most involved part. There's a plan to add a doc on creating a new provider which I/we will hopefully get to soon.
In order to make it possible for anyone at the company to make PRs, not just SRE team members, we had to minimize or eliminate the learning curve and YAML was the best option for that we could think of. In the past those 75 PRs would have instead been issues asking an engineer on the infrastructure team to make the changes. It's been a huge and positive shift.