Skip to main content

Migration runbook

1

Inventory the source zone

Export the zone when possible and capture dynamic or provider-managed records separately. Record DNSSEC, ALIAS/flattening, traffic policies, and health checks that may not transfer as plain records.
2

Reduce application TTLs

Several TTL periods before the cutover, lower records that may need rollback. Do not reduce them so far that query load becomes unacceptable.
3

Create and populate the Aptranet zone

Recreate record sets and convert provider-specific routing into Aptranet picker and metadata structures.
4

Validate directly

Query every important name and type against both Aptranet nameservers. Check negative answers and wildcard behavior as well as successful records.
5

Handle DNSSEC deliberately

Coordinate DS records with the signing state of the new provider. A mismatched DS record can make the entire zone appear unavailable to validating resolvers.
6

Change parent delegation

Update registrar nameservers and monitor public resolvers, application health, mail, certificate issuance, and query analytics.
7

Retire the old provider

Keep the old zone consistent until its delegation is no longer observed. Raise lowered TTLs after the system is stable.

Rollback

Retain registrar access, the old zone, and its provider account. If you must restore the old nameservers, remember that parent and resolver caches can create another mixed-authority period.