Hetzner Cloud
Use the installed hcloud CLI and its --help/JSON output for current
resource types, locations, flags and pricing. This covers Cloud/DNS/Storage
Box APIs supported by that CLI; dedicated servers/auctions use Hetzner Robot.
Authentication and discovery
Use the authorized project's existing context or HCLOUD_TOKEN. A token in
an env file is not automatically exported. Creating a context normally
prompts; hcloud context create --token-from-env <name> uses the process
token without prompting. Keep tokens out of command arguments/logs.
Confirm project/context before writes. Discover server types, system images,
architecture, location/network zone and price through current CLI/API data
(hcloud server-type list, hcloud location list,
hcloud image list --type system --architecture arm, hcloud all list for the
whole project). Do not quote a remembered server specification or price.
Dependencies and verification
Referenced SSH keys/firewalls/networks must exist before server creation.
Inspect a proposed firewall change against the current rules and retain a
working management path. firewall replace-rules --rules-file replaces the
set, so omitted rules disappear. zone import-zonefile --zonefile likewise
replaces all Zone RRSets; omitted records disappear.
Treat server state, network reachability and application health as separate checks. Read the API action result and resource state back after changes; verify the intended service from its actual caller.
Gotchas worth retaining
- A recycled IP can trigger SSH's changed-host-key warning. Authenticate the
new fingerprint through a trusted console/channel before updating
known_hosts;
ssh-keyscanalone does not establish identity. - Servers and Primary IPs lost their
datacenterrequest/response property on 2026-07-01. The CLI'sserver create --datacenteris removed; use--locationand inspect the server type's per-location availability and prices withhcloud server-type describe <type> -o json. - Volumes are location-pinned; a server in another location cannot attach them. Private networks span locations within one network zone, not across zones.
- DNS zones do not take effect until the registrar delegates to the correct nameservers. Inspect delegation before debugging records.
- Deletion is immediate. Confirm resource IDs and the requested destructive scope; establish recoverable data first. Server snapshots/backups exclude attached Volumes, which need their own backup. See snapshot scope. Assigned Primary/Floating IPs cannot be deleted; unassign them first.
status: runningdoes not prove reachability. Inspecthcloud server describe <srv> -o json | jq '.public_net | {v4:.ipv4.blocked, v6:.ipv6.blocked}'for a provider block (abuse report or unpaid invoice) when several otherwise-open ports time out, SSH open to0.0.0.0/0included, or every server on the account fails at once. Such symptoms alone do not prove a block; a provider-level block needs Hetzner support, not an app firewall fix.- Firewall JSON must match the API schema.
source_ipsis an array of strings; PowerShell serialization needs sufficient JSON depth. A shape error (cannot unmarshal object into Go struct field FirewallRule.source_ips of type []string) rejects the whole file and leaves the previous rules in place; verify the returned/live rules. - Storage Box/DNS subcommands and API boundaries can evolve. Use installed command help and the official changelog rather than treating an older Cloud-only feature list as current.
Sources
- API changelog for renames and removals
- API reference
- Product documentation
- CLI manual/source