Vintner
Plant a Vine

DNS & WAF

Domain configuration, managed certificates, and Web Application Firewall options.

DNS & WAF

The DNS section is optional (controlled by a master toggle). When enabled, it configures domain management, SSL/TLS certificates, and web application firewall protection.

Fields

FieldTypeDescription
EnabledToggleMaster switch for DNS configuration
Zone IDSelect or textExisting DNS hosted zone
Domain NameText inputAuto-filled from zone, or manually entered
Managed CertificateToggleAuto-provision SSL/TLS certificate
WAF OptionsTogglesProvider-specific WAF configuration

DNS Zones

The zone selector shows existing DNS zones discovered by the resource refresh job:

Route 53 hosted zones (public only). Zone ID format: Z1234567890ABC.

Cloud DNS managed zones. Zone name format: my-zone.

Azure DNS zones. Zone name format: example.com.

DNS zones are provider-specific. When duplicating a vine across providers, the zone ID and domain are cleared and must be re-configured. See Multi-Cloud Conversion.

Managed Certificates

When enabled, the platform provisions a TLS certificate automatically:

ProviderServiceValidation
AWSACM (AWS Certificate Manager)DNS validation via Route 53
GCPGoogle-managed certificateDNS validation via Cloud DNS
AzureApp Service CertificateDNS validation via Azure DNS

Certificates are renewed automatically before expiration.

Web Application Firewall

WAF protects web applications from common attacks (SQL injection, XSS, bot traffic).

Two WAF options (can enable both):

OptionProtectsCost
CloudFront WAFCDN-level protection~$5/mo base
Application WAF (ALB)Load balancer level~$5/mo base

AWS WAFv2 with managed rule groups (AWS Managed Rules, Bot Control).

Cloud Armor — DDoS and application-layer protection at the load balancer.

Azure WAF — protection via Application Gateway or Front Door.

WAF costs are reflected in the cost sidebar immediately when toggled.

On this page