Traditionally, when a project is created, in wmfkeystone hook we create a number of DNS zones for that new project. These zones are considered part of the basic 'Cloud VPS' service offering. This is per our DNS policy at https://wikitech.wikimedia.org/wiki/Portal:Cloud_VPS/Admin/DNS
For example, in eqiad1:
- <project>.eqiad1.wmcloud.org
- <project>.wmcloud.org
- svc.<project>.eqiad1.wikimedia.cloud
We could instead create and track the zones using tofu-infra, along with the core DNS records (NS, MX, etc), leaving the rest of the records outside of tofu-infra for local project admins to manage in whatever way they want.