How to Configure DNS for Google Cloud Storage Custom Static Websites
Configuring DNS for a custom static website hosted on Google Cloud Storage (GCS) requires mapping your domain name to an external HTTP(S) load balancer linked to your storage bucket. Because GCS buckets cannot directly serve custom domains over naked root domains or HTTPS without an intermediary load balancer, you must set up specific DNS records pointing to a global static IP address. Before making any modifications to your name servers, it is always a good idea to check your existing records using the DNS Lookup tool to ensure a clean starting state and verify propagation later.
Understanding the GCS Custom Domain Architecture
Hosting a static website on Google Cloud Storage involves more than just creating a public bucket. While GCS allows you to name your bucket after your domain (e.g., www.example.com), it does not natively provision SSL certificates or handle root domain traffic redirection without a Global External Application Load Balancer.
To serve your static site securely via HTTPS, the standard architecture consists of:
- A GCS bucket configured for public website hosting.
- A Global External HTTP(S) Load Balancer.
- A reserved global static IP address attached to the load balancer.
- An SSL certificate managed by Google Cloud or uploaded manually.
- DNS records at your domain registrar pointing to the load balancer's IP address.
Root Domains vs. Subdomains
When planning your DNS strategy, you must decide between a subdomain (like www.example.com or app.example.com) and a root apex domain (like example.com). Subdomains use standard CNAME records, which are straightforward to manage. Root domains require pointing to an IP address because standard DNS protocols do not allow a CNAME record at the root apex.
Step-by-Step DNS Configuration Guide
Follow these steps to configure your DNS records once your Google Cloud load balancer and bucket are provisioned.
Step 1: Reserve a Global Static IP Address
Before configuring DNS, ensure your Google Cloud project has a reserved global static IPv4 and IPv6 address assigned to your load balancer.
- Open the Google Cloud Console and navigate to VPC network > IP addresses.
- Click Reserve static address.
- Name your address, set the IP version to IPv4 (and optionally IPv6), and set the type to Global.
- Note down the generated IP address (for example,
192.0.2.1).
Step 2: Configure DNS Records at Your Registrar
Log in to your domain registrar or DNS hosting provider (such as Cloudflare, AWS Route 53, GoDaddy, or Google Cloud DNS). Note that provider-specific menu paths may vary slightly depending on your vendor.
Create the following records based on whether you are using a subdomain or a root domain:
| Record Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
A |
www |
192.0.2.1 |
300 | Points the www subdomain to your load balancer |
AAAA |
www |
2001:db8::1 |
300 | Points IPv6 traffic to your load balancer |
A |
@ (Root) |
192.0.2.1 |
300 | Points root apex domain to your load balancer |
TXT |
_acme-challenge |
Managed by GCP | 300 | Used for automated SSL certificate validation (if applicable) |
Step 3: Verify DNS Propagation
Once you save your DNS records, use command-line utilities or online tools to verify that they are resolving correctly across global nameservers.
Open your terminal and run a dig query to check your A record:
dig +short A www.example.com
Sample output:
192.0.2.1
You can also use nslookup on Windows PowerShell:
nslookup www.example.com
Sample output:
Server: UnKnown
Address: 192.0.2.1
Name: www.example.com
Address: 192.0.2.1
Testing Your Custom Domain Setup
After your DNS changes have fully propagated, test both HTTP and HTTPS access to your storage bucket using curl to ensure headers and redirects are working properly.
curl -I https://www.example.com
Expected response output:
HTTP/2 200
content-type: text/html; charset=utf-8
server: ESF
If you see a 301 Moved Permanently or 404 Not Found, check your URL map settings in the Google Cloud Console to ensure the bucket backend service is properly attached.
Common Mistakes and How to Fix Them
- Using CNAME records for the root domain: Attempting to create a
CNAMErecord forexample.comwill break standard DNS compliance. Use anArecord pointing directly to the global static IP, or use a DNS provider that offers CNAME flattening at the root. - Forgetting IPv6 Records: If you provisioned an IPv6 address for your load balancer but forgot to create the corresponding
AAAArecord, users on IPv6-only mobile networks may experience connection timeouts. - SSL Certificate Provisioning Delays: Google-managed SSL certificates can take anywhere from 10 minutes to several hours to provision. Ensure your DNS records are fully propagated before troubleshooting SSL handshake errors.
- Bucket Permissions Misconfigured: If your DNS resolves correctly and your load balancer is active, but you receive a
403 Forbiddenerror, verify that theallUsersprincipal has theStorage Object Viewerrole on your GCS bucket.
Configuration Checklist
- GCS bucket created and configured for static website hosting.
- Global External HTTP(S) Load Balancer provisioned.
- Global static IPv4 (and IPv6) address reserved and attached.
- DNS
AandAAAArecords added at your domain registrar. - Google-managed SSL certificate active and bound to the frontend.
- DNS propagation verified using command-line tools.