# Hetzner setup

> Create the Hetzner Cloud API token, and learn what Manage Runners creates in your project and how to use SSH keys, labels and firewalls.

Source: https://managerunners.com/docs/manual/hetzner/

Your runners are servers in your own Hetzner Cloud project. Manage Runners manages them through the Hetzner Cloud API with a token you provide.

## Create a project and an API token

1. In the [Hetzner Cloud Console](https://console.hetzner.cloud), create a project for your runners. The dashboard recommends a separate project that only contains your runners, so the token cannot affect other servers.
2. In the project, go to **Security** > **API tokens** and generate a token with **Read & Write** permission. Manage Runners creates and deletes servers and changes IP addresses, which a read-only token cannot do.
3. Copy the token and paste it into the **Hetzner Auth Token** field when you create a runner.

When you leave the token field, the dashboard checks the token by listing the project's SSH keys. That check only reads, so it also accepts a read-only token. A read-only token fails later, when the server is created, and the runner becomes **Unknown**.

Manage Runners stores the token encrypted and uses it only for the runner you entered it for. Each runner has its own token, so different runners can use different Hetzner projects.

## What Manage Runners creates

In your project, Manage Runners creates:

- **one server per active runner**, named after the runner and its ID, for example `build-01-812999368881481087`;
- **a primary IPv4 and a primary IPv6 address** for each server. They stay in your project while the runner is paused and are deleted with the runner.

It does not create firewalls, networks, volumes or SSH keys.

Do not delete or change runner servers in the Hetzner Console. Manage Runners does not watch the project for such changes, and the runner can end up in a state that does not match reality. Pause, resume and delete runners from the dashboard or the CLI instead.

## SSH keys

Manage Runners does not create SSH keys. To log in to a runner's server:

1. Add your public key to the project under **Security** > **SSH keys** in the Hetzner Console.
2. When you create or edit the runner, select the key under **Hetzner SSH Keys**. The list shows the keys of the project that the Hetzner token belongs to.

Selected keys are added to the server's `root` account. Password login is disabled. Changing the selected keys of an active runner [recreates its server](https://managerunners.com/docs/manual/concepts/#changes-that-recreate-the-server).

## Labels and firewalls

Labels you add to a runner become Hetzner server labels. A label written as `key=value` becomes the Hetzner label `key` with the value `value`. A label without `=` becomes a label with an empty value.

Hetzner firewalls can apply to all servers with a given label. To protect your runners with a firewall:

1. Create a firewall in the Hetzner Console with the rules you want.
2. Under **Apply to**, choose **Label selector** and enter a label, for example `role=ci-runner`.
3. Add the same label to your runners.

GitLab Runner only makes outgoing connections to your GitLab instance, so a runner needs no incoming rules for GitLab. Keep SSH open only if you log in to the servers. Changing labels never recreates a server.

## Changing the token

To use a new Hetzner token, for example after revoking the old one, edit the runner and enter the new token. Changing only the token does not recreate the server. If the runner was **Unknown** because the old token stopped working, saving the new token makes Manage Runners check the project again. See [Troubleshooting](https://managerunners.com/docs/manual/troubleshooting/#a-runner-is-unknown).
