Sorry for asking a question here, but your solution may have solved a big problem of ours.
We setup a Hub/Spoke topology with Private DNS, but it only supports a single AMPLS in the hub due to DNS dependencies.
This is limitation at scale, and we would prefer to use a Log Analytics Cluster in the spoke for security reasons.
I was simply wondering if the Decentralized DNS solution you proposed would allow an AMPLS per spoke?