The public integrations catalog lists Hetzner (2 checks), but the check DSL is intentionally excluded from the catalog sync and there is no code manifest — so self-hosted deployments get the catalog entry without the integration.
We run Comp self-hosted (EU company, all production infra on Hetzner) and built the integration as a validated dynamic-integration JSON: 9 checks against the hcloud API with a read-only token — firewall attached per server, no management ports open to 0.0.0.0/0, backups enabled + recent, delete protection, LB https + health checks, certificate expiry, labeled-inventory evidence, SSH-key allowlist — each mapped to ISO 27001 / SOC 2 via taskMappings, with Spanish names/remediations (but we can provide an engilish version too). It runs daily against our real infrastructure and already surfaced a genuine finding on day one.
We'd like to contribute it upstream so every self-hosted user gets Hetzner out of the box. Two possible paths — maintainers' choice:
Code manifest under packages/integration-platform/src/manifests/hetzner/ (PR to dev per the writing-integrations docs). Caveat: code manifests take precedence over dynamic slugs, so this would shadow the production dynamic hetzner — happy to coordinate merging the two check sets.
We donate the validated dynamic JSON so it lands in the production catalog for cloud and self-hosted alike.
While building it we found and reported two runtime bugs with proposed fixes (GitHub issues: page pagination breaks on envelope APIs; buildUrl drops baseUrl path segments) plus a UX papercut (post-connect redirect goes to /cloud-tests, which is hardcoded to aws/gcp/azure and can never show the provider just connected).
Happy to open the draft PR or hand over the JSON — whichever the team prefers.
Please authenticate to join the conversation.
In Review
Feature Request
20 days ago

Eudald Arranz
Get notified by email when there are changes.
In Review
Feature Request
20 days ago

Eudald Arranz
Get notified by email when there are changes.