Independent comparison · no paid rankings
Home / Blog / Guide / Getting started on Hetzner Cloud without underestimating administration

Getting started on Hetzner Cloud without underestimating administration

Hetzner Cloud offers excellent price-performance — provided you accept firewall, snapshots, updates and no managed support by default.

Hébergeurs.eu Editorial Team 3 min read Updated Jul 19, 2026

A freelance developer launches an MVP SaaS on Hetzner Cloud: €4/month, Ubuntu, deployed in fifteen minutes. The tweet goes out. Forty-eight hours later, a mass scan tries SSH on every IP in the /24. Fortunately, the firewall was configured. Often, it is not.

Hetzner Cloud attracts with price and performance — not hand-holding. Getting started means accepting that you are the administrator.

What Hetzner Cloud promises — and what it does not

Hetzner offers per-minute instances, private networks, load balancers, volumes and snapshots. Datacenters in Germany and Finland. Price score 9.5/10 in our directory.

What you do not buy by default:

  • OS patch management
  • WAF or advanced application anti-DDoS
  • Support that debugs your nginx
  • Automatic geo-redundant backups
  • Turnkey compliance (HDS, SecNumCloud)
BlockYour responsibilityHetzner tool
OS updatesYou
FirewallYouCloud Firewall
BackupsYouSnapshots + external
TLSYouCertbot / Traefik
MonitoringYouExternal or self-hosted

Hetzner sells efficient infrastructure. The attack surface is your job.

First 48 hours checklist

1. Cloud Firewall — SSH restricted to your IP or bastion; 80/443 public only if web. See Hetzner Cloud firewall.

2. SSH keys — Disable password auth in sshd_config.

3. Non-root user — sudo for deploy; no daily work as root.

4. Updatesunattended-upgrades or documented process.

5. Snapshots — Before any major change; not a substitute for off-site backup.

6. DNS & TTL — Lower TTL before production migration.

7. DPA — Read Hetzner DPA sub-processing if EU personal data.

Common startup mistakes

  • Port 22 open to the world without fail2ban or keys.
  • Database listening on 0.0.0.0 "for debug".
  • Snapshots only — accidental deletion or ransomware = loss.
  • Undersized instance without disk/RAM alerts.
  • Forgetting egress to S3 or external APIs in budget.

When to move up a level

Upgrade instance (more CPU/RAM), add load balancer, separate staging/prod on distinct projects, or migrate to PaaS if administration exceeds your capacity. Hetzner remains excellent for controlled IaaS — not as a substitute for an ops team.

The peak: low price hides the administration bill

Decide and move forward without blind spots

Estimate administration hours per month before comparing instance price. Create a test project, apply the forty-eight-hour checklist, then restore from snapshot and external backup to validate both paths. Open the Hetzner profile and comparison tool if your ops skills are limited — French shared hosting may cost less in total time.

Frequently asked questions

Is Hetzner Cloud suitable for beginners?

Yes if you accept administering Linux, firewall, updates and backups. No if you seek turnkey shared hosting with application support.

Which region for a European audience?

Falkenstein or Nuremberg (DE) for central Europe; Helsinki for the north. Check latency from your users and data residency constraints.

Are snapshots enough as backup?

Not alone. Hetzner snapshots protect local disk; add external copy (object storage, restic) for ransomware and human error.

Should you enable Cloud Firewall from the start?

Yes. Block everything except SSH (fixed IP or bastion), HTTP/HTTPS. Our Hetzner firewall guide details a healthy rule structure.


Hetzner Cloud rewards those who administer — and bills the others in incidents.

See the Hetzner sheet

Independent scores, plans, pros/cons and alternatives to Hetzner.

Open the Hetzner sheet
Blog

Related reading

All articles →