Hetzner
Hetzner Console › your project › Security › API tokens › Generate, with Read & Write. Use a project for Codemany alone.
Use a project for Codemany alone
A Hetzner API token can do everything in its project: Hetzner has no finer scope. So create a project just for Codemany's machines, and the token can't reach your other servers. Codemany also only touches servers it labelled codemany=managed, even there.
Create the token
Open the Hetzner Console and create a project, for example
codemany.Open that project and go to Security › API tokens.
Choose Generate API token. Give it a description (
codemany) and choose Read & Write: Codemany creates, starts, stops and deletes servers.Choose Generate API token and copy the token now. Hetzner shows it only once.
Connect
In Add a cloud machine, choose Hetzner.
Paste the token into API token (one line, no spaces) and choose Connect.
One read call checks the token before it is kept. It is kept in the Mac Keychain or the Linux keyring on this machine, never in a file, and never sent to Codemany's servers.
Regions and sizes
- Regions: Hetzner's locations (
fsn1,nbg1and so on), shown with their city and country. - Sizes: every current Cloud server type in that location, x86 and Arm (CAX). Deprecated types aren't offered.
- Image: Ubuntu 24.04 LTS; the disk is the server type's own.
- Prices: Hetzner's gross EUR prices (VAT included where Hetzner charges it), as the account is billed.
Hetzner Cloud servers have no nested virtualization, so they can't give each job a fresh VM.
Cost
Hetzner bills a stopped server in full. Idle stop saves nothing here, so it is off by default, and a spending cap isn't offered. Only removing the machine stops the bill. See Remove a cloud machine.
Revoke access
Delete the token under the project's Security › API tokens. Remove the machines from Codemany first, so their runners, seats and fleet membership go too.