Hetzner Infrastructure-as-Code modules
7 verified ansible / terraform modules for Hetzner, spanning Alt & Specialty Clouds, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 7 Hetzner modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 6 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Hetzner modules
hetzner-firewall
A firewall applied to no server protects nothing; SSH from everywhere is the default suggestion; and once one outbound rule exists Hetzner drops every other outbound packet, DNS included. Servers or a label selector expected, port 22 from everywhere refused unless accepted, a DNS and HTTPS baseline added once outbound is restricted, and an output that says the private network is not filtered.
hetzner-snapshot
A Hetzner snapshot of a server, which is Hetzner's custom image, labelled by role and build so hcloud_image data sources can select the newest (unlabelled has to be accepted by name). The snapshot is the server at that moment, secrets and all: build the source clean and power it off first.
hetzner-volume
delete_protection defaults to off, a deleted volume is gone at once with no soft delete and nothing to restore from, and server snapshots do not include volumes. Protection on and off only by name, a filesystem so automount works, exactly one of server or location, and an output that says volume snapshots do not exist.
ansible-hcloud-cli
hcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Hetzner's checksums.txt, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a context stops at 'no active context or token'. Original role, live-tested on Rocky Linux 10.
hetzner-lb-web-tier
Managed LB with health checks, cert, and label-selected server targets.
hetzner-private-network
Private network with subnets, routes, and a NAT gateway server for egress-only fleets.
hetzner-server-fleet
N-server fleet with placement group, firewall, primary IPs, and cloud-init - Hetzner's price/perf with guardrails.
Compare across clouds
All solutions →See how the services Hetzner covers here compare on other providers.