Integrate Your AssetsCloud

Secure Hetzner Cloud with Mondoo

Continuously secure your Hetzner Cloud project with Mondoo.

Mondoo continuously scans your Hetzner Cloud project for misconfigurations and vulnerabilities. Create a Hetzner Cloud integration to give Mondoo the access it needs.

Mondoo assesses the project's servers, networks, volumes, floating IPs, and SSH keys. It also discovers each firewall and load balancer in the project as its own asset, so you can review their findings individually.

Prerequisites

  • Editor or Owner access to the Mondoo space
  • A Hetzner Cloud project
  • A Hetzner Cloud API token for that project

Create a Hetzner Cloud API token

Mondoo authenticates to Hetzner Cloud with a project API token.

  1. Log in to the Hetzner Cloud Console.

  2. Select the project you want Mondoo to scan.

  3. In the left navigation, choose Security > API Tokens.

  4. Generate a new token with Read permission. Mondoo only reads configuration, and a Read & Write token grants more than the integration needs.

  5. Copy the token. Hetzner Cloud shows it only once.

Treat the API token like a password. Don't commit it to source control, and rotate it periodically.

An API token is scoped to a single project. To scan several Hetzner Cloud projects, create one integration per project.

Add a Hetzner Cloud integration

Only team members with Editor or Owner access can perform this task.

In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL. On the Install Integration page, find the integration you want by browsing a category or searching by name:

  1. Under Cloud Security, select Hetzner Cloud.

  2. Under Choose an integration name, enter a name that identifies the Hetzner Cloud project.

  3. Under Provide your Hetzner Cloud API token, paste the API token you created.

  4. (Optional) Under Enable security policies (optional), select the policies you want Mondoo to score the project against.

  5. Select CREATE INTEGRATION.

Mondoo starts the first scan as soon as the integration is created. To learn how policies work, read Manage Policies.

Manage your integration

To open the integration, navigate to the space and select Integrations in the side navigation bar. Select the Hetzner Cloud card, then choose the integration.

The status appears on the integration page under Integration Details:

StatusMeaning
activeThe integration is healthy and scanning.
errorMondoo detected an error during a scan attempt.

At the top of the integration page, select RUN to request a fresh scan, or select the ... (more integration actions) button and then Pause to stop scheduled scans (Resume starts them again).

To rename the integration or replace its API token, select the edit (pencil) icon. Leave the token box empty to keep the existing token.

To remove the integration, select the trash can icon, then select DELETE in the Remove Integration dialog. Mondoo stops scanning the Hetzner Cloud project.

Scan Hetzner Cloud from the command line

The integration scans continuously from the Mondoo Platform. To scan a Hetzner Cloud project from your workstation or a CI pipeline instead, see Secure Hetzner Cloud with cnspec.

Next steps

On this page