Hetzner Infrastructure-as-Code modules

7 verified ansible / terraform modules for Hetzner, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 7 Hetzner modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 6 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Hetzner modules

Static validatedLive test pending

hetzner-firewall

A firewall applied to no server protects nothing; SSH from everywhere is the default suggestion; and once one outbound rule exists Hetzner drops every other outbound packet, DNS included. Servers or a label selector expected, port 22 from everywhere refused unless accepted, a DNS and HTTPS baseline added once outbound is restricted, and an output that says the private network is not filtered.

View module
Static validatedLive test pending

hetzner-snapshot

A Hetzner snapshot of a server, which is Hetzner's custom image, labelled by role and build so hcloud_image data sources can select the newest (unlabelled has to be accepted by name). The snapshot is the server at that moment, secrets and all: build the source clean and power it off first.

View module
Static validatedLive test pending

hetzner-volume

delete_protection defaults to off, a deleted volume is gone at once with no soft delete and nothing to restore from, and server snapshots do not include volumes. Protection on and off only by name, a filesystem so automount works, exactly one of server or location, and an output that says volume snapshots do not exist.

View module
Live-tested

ansible-hcloud-cli

hcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Hetzner's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a context stops at 'no active context or token'. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

hetzner-lb-web-tier

Managed LB with health checks, cert, and label-selected server targets.

View module
Static validatedLive test pending

hetzner-private-network

Private network with subnets, routes, and a NAT gateway server for egress-only fleets.

View module
Static validatedLive test pending

hetzner-server-fleet

N-server fleet with placement group, firewall, primary IPs, and cloud-init - Hetzner's price/perf with guardrails.

View module

Compare across clouds

All solutions →

See how the services Hetzner covers here compare on other providers.

Other providers