Hetzner Cloud integration for self-hosted deployments — built and ready to contribute

The public integrations catalog lists Hetzner (2 checks), but the check DSL is intentionally excluded from the catalog sync and there is no code manifest — so self-hosted deployments get the catalog entry without the integration.

We run Comp self-hosted (EU company, all production infra on Hetzner) and built the integration as a validated dynamic-integration JSON: 9 checks against the hcloud API with a read-only token — firewall attached per server, no management ports open to 0.0.0.0/0, backups enabled + recent, delete protection, LB https + health checks, certificate expiry, labeled-inventory evidence, SSH-key allowlist — each mapped to ISO 27001 / SOC 2 via taskMappings, with Spanish names/remediations (but we can provide an engilish version too). It runs daily against our real infrastructure and already surfaced a genuine finding on day one.

We'd like to contribute it upstream so every self-hosted user gets Hetzner out of the box. Two possible paths — maintainers' choice:

  1. Code manifest under packages/integration-platform/src/manifests/hetzner/ (PR to dev per the writing-integrations docs). Caveat: code manifests take precedence over dynamic slugs, so this would shadow the production dynamic hetzner — happy to coordinate merging the two check sets.

  2. We donate the validated dynamic JSON so it lands in the production catalog for cloud and self-hosted alike.

While building it we found and reported two runtime bugs with proposed fixes (GitHub issues: page pagination breaks on envelope APIs; buildUrl drops baseUrl path segments) plus a UX papercut (post-connect redirect goes to /cloud-tests, which is hardcoded to aws/gcp/azure and can never show the provider just connected).

Happy to open the draft PR or hand over the JSON — whichever the team prefers.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Feature Request

Date

20 days ago

Author

Eudald Arranz

Subscribe to post

Get notified by email when there are changes.