If your team runs Kubernetes on Hetzner and it hurts, the problem is rarely Hetzner’s servers. It is the work on top: etcd, upgrades, certificates, the pager and the security questionnaire. You have three ways forward: stay on Hetzner and harden the setup, buy a managed control plane (on Hetzner servers or at another European provider), or keep any platform and hand the operations to someone else. The right one depends on who carries the pager today and whether you need things a self-run cluster cannot give you, such as an SLA on the Kubernetes API.
This guide lists the signs, the options for each, and a decision table. It does not repeat the task-by-task cost model in managed Kubernetes vs. in-house operations or the migration playbook in how to migrate to European managed Kubernetes; read those for the numbers and the cutover steps.
Should you leave Hetzner at all?
Often not. Hetzner Online GmbH is a German company with servers that are hard to beat on price per CPU, and the platform has grown up:
- An SLA for Cloud Servers: Hetzner commits to 99.9% monthly availability per Cloud Server, with compensation as Cloud Credits.
- A BSI C5:2020 Type 2 attestation, announced on 25 March 2026. Hetzner’s published summary lists Cloud Servers, Block Storage (Volumes), Load Balancers and Object Storage among the services in scope. It does not state the locations or the audit period.
- ISO/IEC 27001:2022 certification covering all its hosting services and its data centers in Germany (Nuremberg, Falkenstein) and Finland.
- 24/7 support by email for exceptional cases. Phone support runs Monday to Friday, 8:00 to 18:00 CET.
- Three European locations (Falkenstein, Nuremberg, Helsinki), plus Ashburn, Hillsboro and Singapore.
- An official cloud controller manager and CSI driver, so a cluster you build can create Hetzner load balancers and attach Hetzner volumes.
Prices have moved. Hetzner raised prices for new orders and rescales on 15 June 2026, so compare against current list prices, not an old invoice. It is still among the cheapest options per CPU.
What Hetzner does not list is a managed Kubernetes product. The control plane, etcd and every upgrade are yours. If you have two or more people who know the cluster, like the work and can share on-call, that is a fair trade for the price, and staying is the right call.
What are the signs you have outgrown a self-run cluster?
Watch for these. One of them is a nuisance; three or more usually mean the setup costs more in engineering time than it saves in server bills.
- One person carries the pager. If the cluster goes down at night and only one engineer can fix it, you have a single point of failure that no server SLA covers.
- Upgrades keep slipping. Kubernetes ships about three minor releases a year, and upstream patches only the three newest. Fall more than two minor versions behind and you are running without security patches, and catching up means several upgrades in a row, one minor version at a time. The Hetzner integrations need upgrades too: cloud controller manager releases up to v1.30.0 crash since Hetzner removed a field from its API on 1 July 2026.
- Nobody has restored etcd. etcd tolerates the loss of (N-1)/2 members; lose quorum and the cluster stops accepting changes. Recovery means restoring every member from the same snapshot. If you have backups but have never run that restore, you do not know whether you can.
- Security reviews ask questions you answer by hand. Customers and auditors want to know who changed what, how access is controlled and how incidents are handled. On a self-run cluster, all of that is documentation you write.
- Customers ask for an SLA on the platform. Hetzner’s SLA covers the Cloud Server. The Kubernetes API that runs on those servers is your responsibility, so the availability you can promise downstream is whatever your team can deliver.
- You need a second region or an exit plan. Spreading across locations, or proving you could move, needs the cluster to be reproducible from code.
What if your managed hoster does not grow with you?
The same signs apply when you are not self-running but paying a hoster to manage Kubernetes and it still falls over or cannot scale. The question there is not who runs the cluster but whether the provider’s managed layer delivers. Ask for the published SLA, what it measures and the incident history; how to judge the reliability of managed Kubernetes in Europe has the checklist. One public example: scanmetrix moved from IONOS to enum in one week, now runs 32+ tenants, and reports that availability went from 97% to 99.95%.
Option 1: How do you stay on Hetzner and harden the setup?
If the work is manageable but messy, fix the setup before you move. The goal is a cluster you can rebuild from code, upgrade on a schedule and restore from backup.
- Talos Linux. Sidero Labs describes Talos as an immutable, API-driven operating system for Kubernetes with no SSH, no shell and no package manager. The whole machine is one declarative config, which removes OS drift between nodes. Hetzner Cloud has offered Talos as a public ISO since April 2025, and the Talos docs have a Hetzner installation guide that uses the official cloud controller manager.
- k3s. A Kubernetes distribution shipped as a single binary of under 100 MB. It uses SQLite by default. For high availability you run either embedded etcd on an odd number of server nodes (at least three), or two or more server nodes against an external database.
- kube-hetzner and hetzner-k3s. Community projects that build clusters on Hetzner Cloud: kube-hetzner is Terraform for k3s or RKE2 on openSUSE Leap Micro, and hetzner-k3s is a CLI for k3s clusters. Both are community projects maintained outside Hetzner (kube-hetzner states it is not affiliated), and you still run the result.
- Cluster API Provider Hetzner. Maintained by Syself and the community, not an official Hetzner project. It manages clusters declaratively on Hetzner Cloud and bare metal.
- Sidero Omni. Sidero Labs (US) sells Omni, a management plane for Talos clusters, as SaaS or self-hosted, from US$10 a month for up to 10 nodes. It automates provisioning and upgrades, but you pick which of your machines become control plane nodes, so the control plane and etcd still run on your Hetzner servers.
Then close the gaps the tools do not:
- Put control plane nodes in a spread placement group so they land on different physical hosts (up to 10 servers per group). Placement groups protect against a host failure, not a site failure.
- Know what a location is. Hetzner offers locations and network zones but no availability zones within a location. The eu-central network zone covers Falkenstein, Nuremberg and Helsinki, so a private network can span all three, but stretching etcd across those sites adds cross-site latency to every write.
- Schedule etcd snapshots off the cluster and run a restore drill every quarter.
- Pin a target Kubernetes version and upgrade every few months, not every few years. Upgrade the cloud controller manager and CSI driver with it.
- Plan storage around the volume limits: a volume attaches to one server at a time (ReadWriteOnce), goes up to 10 TB, a server takes at most 16, and Hetzner offers no snapshots or backups for volumes. Back up persistent volumes with a file-level tool such as Velero’s file-system backup, and test the restore.
- Set up on-call with at least two people, or accept in writing that nights are best effort.
This option keeps your costs low and your control total. It does not remove the pager.
Option 2: Should you buy a managed control plane?
Buy one when the control plane itself is the problem: etcd, upgrades, API availability and nobody to own them. With a managed control plane, the provider runs the API servers and etcd and usually offers an SLA on the Kubernetes API, often only on the paid control plane tier. Workloads, add-ons, monitoring and on-call for your applications stay with you. There are two ways to get one.
Keep Hetzner servers. Third parties run the control plane and manage nodes in your own Hetzner account, so you keep paying Hetzner’s server prices plus a platform fee:
- Syself GmbH (Germany) sells a managed platform built on Cluster API Provider Hetzner. It has a free tier for one cluster with up to 5 nodes. Paid plans start at a €299 platform fee plus a percentage of your cloud spend, and standard support comes without an SLA; SLAs need the separate premium support.
- Cloudfleet GmbH runs the control plane and provisions nodes in your Hetzner account; Hetzner’s community tutorials describe the setup. The Basic plan is €12 a month with 8 vCPUs included and a best-effort SLA. The Pro plan is €69 a month with 24 vCPUs included and a 99.95% SLA. Extra vCPUs are billed per month on every plan.
Move to another European provider. OVHcloud, IONOS, STACKIT, Scaleway, Exoscale and enum are among the providers that sell managed Kubernetes in Europe. They differ on control plane pricing (free, or billed per cluster-hour on paid tiers), SLA scope, regions, availability zones and certifications. Choosing European managed Kubernetes sorts them by situation, and the sovereignty comparison covers jurisdiction and certificates.
Leaving Hetzner is usually simpler than leaving a hyperscaler. There is little proprietary to replace: Service annotations for the Hetzner load balancer, the storage class of the CSI driver, Object Storage endpoints, and Hetzner-specific add-ons such as the cluster autoscaler provider, Hetzner DNS integrations for external-dns or cert-manager, and firewall rules. If you run Arm (CAX) servers, check that the target has Arm nodes or build your images for x86. The rest of the work (data sync, parallel run, DNS cutover, rollback) follows the migration playbook.
Option 3: Should someone else run production for you?
A managed control plane removes etcd and control plane upgrades. It does not answer the alert at 3 a.m. when a pod on your nodes runs out of memory. If what you want to get rid of is the on-call and the operational work above the control plane, buy operations: a team that runs upgrades, monitoring, CI/CD, backups and incident response under a contract with response times. This can sit on top of Hetzner (a consultancy, or Syself’s platform with paid support for the cluster layer), on top of a managed provider, or come from the provider itself.
Read the scope before you sign. “Managed” in a contract is only what the contract lists. Check that you keep full access to your clusters and repositories, so the arrangement is easy to undo. The responsibility table and cost model show where this beats a hire and where it does not.
Which option fits your situation?
| Your situation | Stay and harden | Managed control plane | Hand over operations |
|---|---|---|---|
| Two or more platform engineers who like the work | Best fit | Only if you want an SLA on the API | Not needed |
| One engineer, upgrades slipping, no restore tested | Possible with Talos or Cluster API, still one pager | Good fit | Good fit if nights are the problem |
| No platform engineer at all | Poor fit | Workable if product engineers take on-call | Best fit |
| Customers ask for an SLA on the platform | Hard: you would be the SLA | Good fit, check what the SLA measures and which tier carries it | Good fit, with response times in the contract |
| Security review or audit asks for documented operations | You write it all | Partly covered by the provider | Covered if the contract names it |
| Price per CPU is the deciding factor | Best fit | On Hetzner servers: Hetzner prices plus a platform fee. Elsewhere: costs more per CPU | Costs more again |
| Need several European regions today | Good fit: three EU locations, no availability zones within a location | Check each provider’s regions and zones | Depends on the platform underneath |
Checked October 2026.
Check each provider’s pricing page for current prices: Hetzner, Syself, Cloudfleet, Sidero Omni, OVHcloud, IONOS, STACKIT price list, Scaleway, Exoscale, enum.
Where enum fits
enum covers option 2, and option 3 for clusters that run on enum. On enum Kubernetes Engine, enum runs a highly available control plane per cluster at no extra charge, rolls out upgrades node by node, and starts clusters private with NAT included. Load balancers have a flat monthly price of €10.00 with IPv4 included, object storage is S3-compatible without request fees, and nodes start at €0.06 per hour. DevOps as a Service adds enum’s engineers for upgrades, monitoring, CI/CD, security updates and incident response on enum Kubernetes Engine, so taking it means moving off Hetzner. See DevOps as a Service for pricing; platform usage is billed separately.
The limits, plainly:
- Price. Raw Hetzner servers cost less per CPU. Hetzner also includes 20 TB of traffic per server in its EU locations; enum charges €0.025 per GB of outgoing traffic from the first GB, so model egress-heavy workloads in the calculator.
- Location. enum runs production in one region (Frankfurt) with one zone (fra-a). Berlin is available on demand. If you need several regions or availability zones today, Hetzner or a larger provider is the better fit.
- Nodes. General-purpose x86 nodes only, with no Arm types, so images built for Hetzner CAX servers need x86 builds. There is no node autoscaling today; you size node pools for your peak.
- Tooling. Clusters are set up on request until self-service cluster creation ships in Q4 2026. The Terraform provider and the ExternalDNS provider are planned for Q4 2026.
- Network and storage. Load balancers are L4 (TCP and UDP) only. enum documents no volume snapshots, so plan file-level backups as you would on Hetzner.
- Access and audit. Fine-grained roles and a customer audit log are planned for Q4 2026. Until then, a security review that asks who changed what has to rely on your own tooling, such as Git history and CI logs.
- SLA and support. The 99.9% SLA covers the Kubernetes control plane API, not worker nodes, and the credit terms are not published; ask for the contract. Included support runs on working days. Enterprise Support adds 24/7 response for critical incidents, and DevOps as a Service includes on-call.
- Track record and certificates. enum GmbH was founded in November 2024 and runs with a small team, so ask for references and the contract’s response times. ISO 27001 certification is in progress (target Q4 2026) and BSI C5 is on the roadmap for 2027. If your reviewers require a C5 attestation today, Hetzner has one (ask for the full report, including locations and audit period) and enum does not have one yet.
The Hetzner comparison and the calculator show the trade-off for your setup.
FAQ
Does Hetzner offer managed Kubernetes? Not as a first-party product. Hetzner provides servers, load balancers, volumes and networks, plus an official cloud controller manager and CSI driver. You run the control plane, by hand or with a community tool such as kube-hetzner or hetzner-k3s, or a third party such as Syself or Cloudfleet operates it and manages nodes in your Hetzner account.
Is Hetzner’s 99.9% SLA an SLA for my Kubernetes cluster? No. It covers the availability of each Cloud Server. The Kubernetes API, etcd and your add-ons run on those servers, and their availability depends on how you build and operate them.
When does it make sense to stay on Hetzner? When you have at least two people who can run the cluster and share on-call, when price per CPU decides, or when you need several European locations today. Harden the setup with Talos or Cluster API, test etcd restores and keep upgrades on a schedule.
How hard is it to move from Hetzner to a managed Kubernetes provider? Easier than leaving a hyperscaler. Replace the load balancer annotations, the storage class, object storage endpoints and any Hetzner-specific add-ons (cluster autoscaler, firewall rules, DNS integrations, Arm images), then sync data, run both in parallel and switch DNS. See the migration playbook.
Can someone run our Kubernetes for us and keep us on Hetzner? Partly or fully, depending on whom you hire. Syself and Cloudfleet run the control plane and manage nodes in your Hetzner account; Syself’s standard support has no SLA, and Cloudfleet’s SLA starts with its Pro plan. Neither takes over your workload on-call. Consultancies offer full operations on top of a self-run cluster. Check what the contract covers and that you keep full access.
Sources
Checked on 2026-10-09.
- Hetzner: Hetzner Cloud, SLA for Cloud Servers, news: BSI C5 attestation, 25 March 2026, BSI C5:2020 Type 2 summary, ISO/IEC 27001 certificate, support hours, price adjustment 15 June 2026, included traffic, locations and network zones, placement groups, volumes, hcloud cloud controller manager, hcloud CSI driver, cluster autoscaler Hetzner provider
- Talos Linux: Sidero Labs, Talos on Hetzner
- k3s: documentation, HA with embedded etcd, HA with an external datastore
- Community and third-party tooling: kube-hetzner, hetzner-k3s, Cluster API Provider Hetzner, CAPH introduction (cloud and bare metal), Syself pricing, Cloudfleet pricing, Cloudfleet on Hetzner (Hetzner community tutorial), Sidero Omni pricing, Omni: create a cluster from registered machines, Velero file-system backup
- Kubernetes: releases and support period, release cycle, version skew policy
- etcd: disaster recovery
- enum: Kubernetes Engine, DevOps as a Service, pricing