To depool a site prior to maintenance or during an outage, it's currently required to send a Gerrit patch in the DNS repo.
This has both the inconvenients of being slow and error prone.
Instead, there should be a cookbook with safeguards (eg. check that not too many sites are depooled, if eqiad/codfw check that the local appservers are not depooled, etc) and abstracts the depool for SREs.