In the scenario of allowing starting EC2 instances with a script to add/remove record set of a domain programmatically, but limit the access to specific record safely without harming example.com.
Create another public hosted zone (without purchasing another domain from anyone), just use
a subdomain like delegate.example.com. Copy the name server assigned to delegate.example.com by AWS like:
ns-1143.awsdns-14.org.
ns-1686.awsdns-18.co.uk.
ns-133.awsdns-16.com.
ns-965.awsdns-56.net.
And for example, the created zone is ZONEABCD
The goal of created domain will be instance-xxx.delegate.example.com without harming
example.com
Create a record set of NS Type in the hosted zone under your root example.com.
and paste the 4 name servers copied from delegate.example.com.
The you can create a IAM user (copy the accesskey/secretkey for script) with the following policy attached. Limit resource to the created arn:aws:route53:::hostedzone/{ZONEABCD}.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"route53:ChangeResourceRecordSets"
],
"Resource": [
"arn:aws:route53:::hostedzone/{ZONEABCD}"
]
},
{
"Effect": "Allow",
"Action": [
"route53:ListHostedZonesByName"
],
"Resource": [
"*"
]
}
]}
Launch a VM with name instance-xxx and run script with aws-cli
$aws route53 change-resource-record-sets --cli-input-json '{
"HostedZoneId": "ZONEABCD",
"ChangeBatch": {
"Comment": "This is a test and may be deleted.",
"Changes": [
{
"Action": "CREATE",
"ResourceRecordSet": {
"Name": "instance-xxx.delegate.example.com",
"Type": "A",
"TTL": 600,
"ResourceRecords": [
{
"Value": "some.ip.v4.address"
}
]
}
}
]
}}'
$nslookup instance-xxx.delegate.example.com
Returning {some.ip.v4.address} for instance-xxx.delegate.example.com proves the above is working.