back

by LinuxBender·9y ago·view on hn ↗
CNAME discussions in this article are specific to their site. In general, you can load balance just as well with A or CNAME, apex or sub-domain. It's only when you get into artificial technical limitations set up by a hosting provider or CDN, that things get messy.

CNAME's guarentee the end users will always do at least 2 DNS lookups. Depending on their resolver config, this will mean they will likely hit 2 or more resolvers. This increases their chances of hitting a bad one and the DNS not resolving.

A records can be load balanced, have full fault tolerance and much more. The modern way to accomplish this is Anycast. Instead of relying on DNS for failover or load balancing, your IP is advertised in different parts of the internet and the traffic is sent to different datacenters, that each may have their own load balancers, caching devices, WAN accelerators, DDoS mitigation and more. In fact, nearly all major DNS providers are doing this today. While you may have 3 or 4 IP's in your zone, those IP's actually route to different places depending on the requestors location.

TL;DR: Summary, just use an A record for Apex or sub-domain, set a really high TTL so a DDoS of your DNS is less relevant and use Anycast to optimize your traffic routing, load balancing, latency to the end user and availability.

1 comments
How accessible is anycast for most people? AFAIK, if you're ok with a third party seeing all your traffic, you can get behind Cloudflare's anycast or Google cloud load balancer (which does seem to offer TCP, so you don't have to let Google decrypt content); but I haven't seen this from many other providers.

It's not really something you can do yourself either, unless you have assigned IP space and BGP in multiple locations.

For non-commercial folks, there are a couple of VPS providers that provide Anycast support. I personally have not used them, so I can not speak to how easy they have made it to configure.

I agree with your concerns around letting a CDN see traffic. In my workplace, we are not allowed to pass dynamic traffic through CDN's for that very concern that our customers share with you.