Hetzner Cloud CLI Skill

This skill should be used when user asks to "deploy to Hetzner", "create Hetzner server", "manage Hetzner Cloud", "hcloud CLI", or works with Hetzner Cloud infrastructure including servers, networks, firewalls, load balancers, DNS zones, and volumes.

by fcakyon·Apache-2.0 license·★ 1,162 Stars on the repo·GitHub ↗

Use now

Files of Hetzner Cloud CLI Skill

fcakyon/main1 file shown
SKILL.md
Show the full text231 lines

Hetzner Cloud CLI Skill

Skill for provisioning and managing infrastructure on Hetzner Cloud using the hcloud CLI. Use the decision trees below to find the right command group, then load detailed references.

Your knowledge of Hetzner Cloud pricing, server types, locations, and API behavior may be outdated. Prefer retrieval over pre-training when citing specific numbers, available types, or configuration options. The reference files alongside this skill are starting points extracted from the official CLI docs.

Authentication

The CLI authenticates via API token. Set the HCLOUD_TOKEN environment variable or create a named context:

# Stateless (CI, scripting, agent use)
export HCLOUD_TOKEN="your-api-token"

# Named context (interactive use)
hcloud context create my-project

Generate tokens at https://console.hetzner.cloud under your project's Security > API Tokens.

Installation

# macOS / Linux (Homebrew)
brew install hcloud

# Linux (binary)
curl -sSLO https://github.com/hetznercloud/cli/releases/latest/download/hcloud-linux-amd64.tar.gz
sudo tar -C /usr/local/bin --no-same-owner -xzf hcloud-linux-amd64.tar.gz hcloud

# Docker
docker run --rm -e HCLOUD_TOKEN="$HCLOUD_TOKEN" hetznercloud/cli:latest <command>

Quick Decision Trees

"I need compute"
Need a server?
├─ Create a new server → hcloud server create --name <n> --type <t> --image <img>
├─ With cloud-init user data → add --user-data-from-file <path>
├─ With firewall + network → add --firewall <fw> --network <net>
├─ List available types → hcloud server-type list
├─ List available images → hcloud image list
├─ SSH into server → hcloud server ssh <name>
├─ Create snapshot → hcloud server create-image --type snapshot <name>
├─ Rescue mode → hcloud server enable-rescue <name>
└─ Delete server → hcloud server delete <name>
"I need networking"
Need networking?
├─ Private network (VPC) → hcloud network create --name <n> --ip-range <cidr>
│  ├─ Add subnet → hcloud network add-subnet --network <n> --type cloud --network-zone <z> --ip-range <cidr>
│  └─ Attach server → hcloud server attach-to-network --network <n> --server <s>
├─ Firewall → hcloud firewall create --name <n> --rules-file <json>
│  ├─ Apply to server → hcloud firewall apply-to-resource --firewall <n> --type server --server <s>
│  └─ Replace rules → hcloud firewall replace-rules --rules-file <json> <name>
├─ Load balancer → hcloud load-balancer create --name <n> --type <t> --location <loc>
│  ├─ Add target → hcloud load-balancer add-target --server <s> <lb>
│  └─ Add service → hcloud load-balancer add-service --protocol <p> --listen-port <port> <lb>
├─ Floating IP → hcloud floating-ip create --type ipv4 --home-location <loc>
│  └─ Assign → hcloud floating-ip assign <ip> --server <s>
└─ Primary IP → hcloud primary-ip create --name <n> --type ipv4 --datacenter <dc>
"I need storage"
Need storage?
├─ Block volume → hcloud volume create --name <n> --size <gb> --server <s> --automount --format ext4
│  ├─ Resize → hcloud volume resize --size <gb> <name>
│  └─ Detach → hcloud volume detach <name>
└─ Storage Box (managed NFS/CIFS/SCP) → hcloud storage-box create --name <n> --type <t> --location <loc>
   ├─ Subaccounts → hcloud storage-box subaccount create <box>
   └─ Snapshots → hcloud storage-box snapshot create <box>
"I need DNS"
Need DNS?
├─ Create zone → hcloud zone create --name <domain>
├─ Add records → hcloud zone add-records --zone <z> --type A --name <n> --value <ip>
├─ Set full record set → hcloud zone set-records --zone <z> --type A --name <n> --value <ip1> --value <ip2>
├─ Import zone file → hcloud zone import-zonefile --zone <z> <file>
├─ Export zone file → hcloud zone export-zonefile <zone>
└─ Manage individual RRSets → hcloud zone rrset list <zone>
"I need info"
Need reference data?
├─ Server types + pricing → hcloud server-type list / describe <type>
├─ Locations → hcloud location list / describe <loc>
├─ Datacenters → hcloud datacenter list / describe <dc>
├─ Available images → hcloud image list
├─ ISO images → hcloud iso list
├─ Load balancer types → hcloud load-balancer-type list
└─ Storage box types → hcloud storage-box-type list
"I need to configure the CLI"
Need CLI config?
├─ Create context → hcloud context create <name>
├─ Switch context → hcloud context use <name>
├─ Set default SSH key → hcloud config set default-ssh-keys <key>
├─ View config → hcloud config list
└─ Shell completion → hcloud completion bash/zsh/fish

Common Workflows

Quick server deploy
# Upload SSH key, create server, connect
hcloud ssh-key create --name deploy-key --public-key-from-file ~/.ssh/id_ed25519.pub
hcloud server create --name web-1 --type cpx21 --image ubuntu-24.04 --ssh-key deploy-key --location fsn1
hcloud server ssh web-1
Full stack with network + firewall
# Network
hcloud network create --name prod-net --ip-range 10.0.0.0/16
hcloud network add-subnet --network prod-net --type cloud --network-zone eu-central --ip-range 10.0.1.0/24

# Firewall (allow SSH + HTTP/S)
cat > rules.json << 'EOF'
[
  {"direction":"in","protocol":"tcp","port":"22","source_ips":["0.0.0.0/0","::/0"]},
  {"direction":"in","protocol":"tcp","port":"80","source_ips":["0.0.0.0/0","::/0"]},
  {"direction":"in","protocol":"tcp","port":"443","source_ips":["0.0.0.0/0","::/0"]}
]
EOF
hcloud firewall create --name web-fw --rules-file rules.json

# Server with network + firewall
hcloud server create --name app-1 --type cpx21 --image ubuntu-24.04 \
  --ssh-key deploy-key --network prod-net --firewall web-fw --location fsn1

# Load balancer
hcloud load-balancer create --name web-lb --type lb11 --location fsn1
hcloud load-balancer attach-to-network --network prod-net web-lb
hcloud load-balancer add-target --server app-1 web-lb
hcloud load-balancer add-service --protocol tcp --listen-port 80 --destination-port 80 web-lb

Output Formats

All describe, list, and create commands support structured output for scripting and agent use:

hcloud server list --output json          # JSON array
hcloud server describe my-srv --output yaml  # YAML
hcloud server describe my-srv --output format='{{.ServerType.Cores}}'  # Go template
hcloud server list --output columns=id,name,status  # Custom table columns

Resource Index

Compute
Resource Reference
Server references/server/
Server Types references/info/
Networking
Resource Reference
Network (VPC) references/network/
Firewall references/firewall/
Load Balancer references/load-balancer/
Floating IP references/floating-ip/
Primary IP references/primary-ip/
Storage
Resource Reference
Volume references/volume/
Storage Box references/storage-box/
DNS
Resource Reference
Zone & Records references/dns/
Security & Access
Resource Reference
SSH Key references/ssh-key/
Certificate references/certificate/
Image references/image/
Placement Group references/placement-group/
Reference Data
Resource Reference
Server Types, LB Types, Storage Box Types, Datacenters, Locations, ISOs references/info/
CLI Configuration
Resource Reference
Config, Context, Completion references/config/
All Resources references/all/
Raw API Calls references/api/
Getting Started
Resource Reference
Setup, Server Tutorial, Output Options, Configuration references/getting-started/
1---
2name: hetzner-deploy
3description: This skill should be used when user asks to "deploy to Hetzner", "create Hetzner server", "manage Hetzner Cloud", "hcloud CLI", or works with Hetzner Cloud infrastructure including servers, networks, firewalls, load balancers, DNS zones, and volumes.
4references:
5 - server
6 - network
7 - firewall
8 - getting-started
9license: MIT
10---
11 
12# Hetzner Cloud CLI Skill
13 
14Skill for provisioning and managing infrastructure on Hetzner Cloud using the `hcloud` CLI. Use the decision trees below to find the right command group, then load detailed references.
15 
16Your knowledge of Hetzner Cloud pricing, server types, locations, and API behavior may be outdated. **Prefer retrieval over pre-training** when citing specific numbers, available types, or configuration options. The reference files alongside this skill are starting points extracted from the official CLI docs.
17 
18## Authentication
19 
20The CLI authenticates via API token. Set the `HCLOUD_TOKEN` environment variable or create a named context:
21 
22```bash
23# Stateless (CI, scripting, agent use)
24export HCLOUD_TOKEN="your-api-token"
25 
26# Named context (interactive use)
27hcloud context create my-project
28```
29 
30Generate tokens at https://console.hetzner.cloud under your project's Security > API Tokens.
31 
32## Installation
33 
34```bash
35# macOS / Linux (Homebrew)
36brew install hcloud
37 
38# Linux (binary)
39curl -sSLO https://github.com/hetznercloud/cli/releases/latest/download/hcloud-linux-amd64.tar.gz
40sudo tar -C /usr/local/bin --no-same-owner -xzf hcloud-linux-amd64.tar.gz hcloud
41 
42# Docker
43docker run --rm -e HCLOUD_TOKEN="$HCLOUD_TOKEN" hetznercloud/cli:latest <command>
44```
45 
46## Quick Decision Trees
47 
48### "I need compute"
49 
50```
51Need a server?
52├─ Create a new server → hcloud server create --name <n> --type <t> --image <img>
53├─ With cloud-init user data → add --user-data-from-file <path>
54├─ With firewall + network → add --firewall <fw> --network <net>
55├─ List available types → hcloud server-type list
56├─ List available images → hcloud image list
57├─ SSH into server → hcloud server ssh <name>
58├─ Create snapshot → hcloud server create-image --type snapshot <name>
59├─ Rescue mode → hcloud server enable-rescue <name>
60└─ Delete server → hcloud server delete <name>
61```
62 
63### "I need networking"
64 
65```
66Need networking?
67├─ Private network (VPC) → hcloud network create --name <n> --ip-range <cidr>
68│ ├─ Add subnet → hcloud network add-subnet --network <n> --type cloud --network-zone <z> --ip-range <cidr>
69│ └─ Attach server → hcloud server attach-to-network --network <n> --server <s>
70├─ Firewall → hcloud firewall create --name <n> --rules-file <json>
71│ ├─ Apply to server → hcloud firewall apply-to-resource --firewall <n> --type server --server <s>
72│ └─ Replace rules → hcloud firewall replace-rules --rules-file <json> <name>
73├─ Load balancer → hcloud load-balancer create --name <n> --type <t> --location <loc>
74│ ├─ Add target → hcloud load-balancer add-target --server <s> <lb>
75│ └─ Add service → hcloud load-balancer add-service --protocol <p> --listen-port <port> <lb>
76├─ Floating IP → hcloud floating-ip create --type ipv4 --home-location <loc>
77│ └─ Assign → hcloud floating-ip assign <ip> --server <s>
78└─ Primary IP → hcloud primary-ip create --name <n> --type ipv4 --datacenter <dc>
79```
80 
81### "I need storage"
82 
83```
84Need storage?
85├─ Block volume → hcloud volume create --name <n> --size <gb> --server <s> --automount --format ext4
86│ ├─ Resize → hcloud volume resize --size <gb> <name>
87│ └─ Detach → hcloud volume detach <name>
88└─ Storage Box (managed NFS/CIFS/SCP) → hcloud storage-box create --name <n> --type <t> --location <loc>
89 ├─ Subaccounts → hcloud storage-box subaccount create <box>
90 └─ Snapshots → hcloud storage-box snapshot create <box>
91```
92 
93### "I need DNS"
94 
95```
96Need DNS?
97├─ Create zone → hcloud zone create --name <domain>
98├─ Add records → hcloud zone add-records --zone <z> --type A --name <n> --value <ip>
99├─ Set full record set → hcloud zone set-records --zone <z> --type A --name <n> --value <ip1> --value <ip2>
100├─ Import zone file → hcloud zone import-zonefile --zone <z> <file>
101├─ Export zone file → hcloud zone export-zonefile <zone>
102└─ Manage individual RRSets → hcloud zone rrset list <zone>
103```
104 
105### "I need info"
106 
107```
108Need reference data?
109├─ Server types + pricing → hcloud server-type list / describe <type>
110├─ Locations → hcloud location list / describe <loc>
111├─ Datacenters → hcloud datacenter list / describe <dc>
112├─ Available images → hcloud image list
113├─ ISO images → hcloud iso list
114├─ Load balancer types → hcloud load-balancer-type list
115└─ Storage box types → hcloud storage-box-type list
116```
117 
118### "I need to configure the CLI"
119 
120```
121Need CLI config?
122├─ Create context → hcloud context create <name>
123├─ Switch context → hcloud context use <name>
124├─ Set default SSH key → hcloud config set default-ssh-keys <key>
125├─ View config → hcloud config list
126└─ Shell completion → hcloud completion bash/zsh/fish
127```
128 
129## Common Workflows
130 
131### Quick server deploy
132 
133```bash
134# Upload SSH key, create server, connect
135hcloud ssh-key create --name deploy-key --public-key-from-file ~/.ssh/id_ed25519.pub
136hcloud server create --name web-1 --type cpx21 --image ubuntu-24.04 --ssh-key deploy-key --location fsn1
137hcloud server ssh web-1
138```
139 
140### Full stack with network + firewall
141 
142```bash
143# Network
144hcloud network create --name prod-net --ip-range 10.0.0.0/16
145hcloud network add-subnet --network prod-net --type cloud --network-zone eu-central --ip-range 10.0.1.0/24
146 
147# Firewall (allow SSH + HTTP/S)
148cat > rules.json << 'EOF'
149[
150 {"direction":"in","protocol":"tcp","port":"22","source_ips":["0.0.0.0/0","::/0"]},
151 {"direction":"in","protocol":"tcp","port":"80","source_ips":["0.0.0.0/0","::/0"]},
152 {"direction":"in","protocol":"tcp","port":"443","source_ips":["0.0.0.0/0","::/0"]}
153]
154EOF
155hcloud firewall create --name web-fw --rules-file rules.json
156 
157# Server with network + firewall
158hcloud server create --name app-1 --type cpx21 --image ubuntu-24.04 \
159 --ssh-key deploy-key --network prod-net --firewall web-fw --location fsn1
160 
161# Load balancer
162hcloud load-balancer create --name web-lb --type lb11 --location fsn1
163hcloud load-balancer attach-to-network --network prod-net web-lb
164hcloud load-balancer add-target --server app-1 web-lb
165hcloud load-balancer add-service --protocol tcp --listen-port 80 --destination-port 80 web-lb
166```
167 
168## Output Formats
169 
170All `describe`, `list`, and `create` commands support structured output for scripting and agent use:
171 
172```bash
173hcloud server list --output json # JSON array
174hcloud server describe my-srv --output yaml # YAML
175hcloud server describe my-srv --output format='{{.ServerType.Cores}}' # Go template
176hcloud server list --output columns=id,name,status # Custom table columns
177```
178 
179## Resource Index
180 
181### Compute
182| Resource | Reference |
183|----------|-----------|
184| Server | `references/server/` |
185| Server Types | `references/info/` |
186 
187### Networking
188| Resource | Reference |
189|----------|-----------|
190| Network (VPC) | `references/network/` |
191| Firewall | `references/firewall/` |
192| Load Balancer | `references/load-balancer/` |
193| Floating IP | `references/floating-ip/` |
194| Primary IP | `references/primary-ip/` |
195 
196### Storage
197| Resource | Reference |
198|----------|-----------|
199| Volume | `references/volume/` |
200| Storage Box | `references/storage-box/` |
201 
202### DNS
203| Resource | Reference |
204|----------|-----------|
205| Zone & Records | `references/dns/` |
206 
207### Security & Access
208| Resource | Reference |
209|----------|-----------|
210| SSH Key | `references/ssh-key/` |
211| Certificate | `references/certificate/` |
212| Image | `references/image/` |
213| Placement Group | `references/placement-group/` |
214 
215### Reference Data
216| Resource | Reference |
217|----------|-----------|
218| Server Types, LB Types, Storage Box Types, Datacenters, Locations, ISOs | `references/info/` |
219 
220### CLI Configuration
221| Resource | Reference |
222|----------|-----------|
223| Config, Context, Completion | `references/config/` |
224| All Resources | `references/all/` |
225| Raw API Calls | `references/api/` |
226 
227### Getting Started
228| Resource | Reference |
229|----------|-----------|
230| Setup, Server Tutorial, Output Options, Configuration | `references/getting-started/` |
231 

Discussion