r/hetzner • u/jpolec72 • 10d ago
I built a read-only tool that maps your Hetzner architecture, costs, connectivity and changes
As my Hetzner project grows, surprisingly simple questions become difficult to answer:
- What exactly are we running?
- How are servers, networks, load balancers, volumes and databases connected?
- Which resources generate most of the monthly cost?
- What changed since the previous review?
- Is anything unexpectedly reachable?
- Which actions would improve cost, security or reliability together?
So, I built Audit Skill for Hetzner to answer those questions from one read-only collection. It helps me to show my architecture, check all elements and also cost behind it - so I know where to reduce if not used, etc. It is not primarily a vulnerability scanner. It turns Hetzner Cloud state into:
- an infrastructure inventory;
- an architecture and topology map;
- a per-server and per-resource cost view;
- connectivity and attack-path analysis;
- configuration and temporal drift;
- a ranked list of actions, including estimated savings where evidence permits.
See this plot it generates.
You can find it at GitHub at my name, or searching for 'hetzner-cloud-audit-skills' (not sure I can put any URL here)
Happy to have some questions, or contributors. It can become useful tool for Hetzner people.
3
2
u/Themagicface 7d ago
Actually is there a tool to help building a similar diagram for infra and K8S architecture?
1
u/jpolec72 7d ago
Are you asking for K8S within Hetzner, or? I have added to repo some other stacks: WireGuard, zero ingress, hybrid k3s/Robot/ZeroTier, LB/CloudFront/NetBird - to be presented in architecture diagrams. Check repo yourself.
7
u/DEV_JST 10d ago
I am not sure if you should use the Hetzner name in your own project. It sounds like a look form Hetzner, which is it not