Skip to content

Gardener on Hetzner

Gardener is the open-source project SAP runs its Kubernetes clusters on. It runs the control plane of every cluster as pods on a shared cluster, the seed, and keeps each cluster’s whole definition in one object that it reconciles continuously. The worker nodes run where you want them, here in your own Hetzner project.

On this site Gardener appears in two ways: as open components, the extensions and the CLI to run a Gardener landscape on Hetzner yourself, and as the next level that a course teaches. PaaSbox does not offer Gardener clusters, and no landscape runs for customers.

  • Start with small, isolated clusters. One single-node cluster per stage and per app keeps a failed upgrade or a broken test inside one cluster (why isolated clusters). PaaSbox Clusters or the open building blocks with Cluster API and k3s give you those.
  • Gardener pays off for a fleet. Once many clusters need one control point, with their control planes on a seed instead of on their own servers, Gardener is the next level.
  • A landscape has a floor. The garden and the seed need about 17 GiB of memory for themselves, so the smallest landscape is a server with 32 GB, before your first cluster. It also costs money every month, with or without a cluster on it, and needs upgrades, backups and restore drills.

How a landscape works with your Hetzner project

Section titled “How a landscape works with your Hetzner project”

Every cluster has three places:

WhereWhat runs there
The gardenGardener’s API and controllers, the record of every cluster
The seedeach cluster’s control plane as pods: API server, etcd, scheduler, controllers
Your projecteach cluster’s worker nodes, load balancers and volumes, billed to you by Hetzner
  • Your Hetzner project and token. You create a Hetzner Cloud project and a read/write API token. The landscape uses the token to create your workers, load balancers and volumes there. A Hetzner token opens its whole project, and Hetzner offers no narrower scope, so keep these clusters in a project of their own.
  • The worker image. The workers boot Garden Linux, which is uploaded into your project once, before the first cluster.
  • No inbound port on a worker. The control plane reaches your nodes through a tunnel that the nodes open outbound.
  • Backups. Each cluster’s etcd is backed up continuously to object storage, and a control plane is restored from it.
  • Gardener’s own schema. Every cluster is a Gardener cluster whose definition you can read as YAML at any time; nothing in it is specific to PaaSbox.

The paasbox CLI stands a landscape up in a Hetzner project from a values file and a GitOps repository that recreate it. Three servers is the landscape shape whose recovery from a lost server was tested in a lab, one server the smaller and cheaper one; choose before you set it up, because it cannot be changed later.

PartStatus
The Gardener extensions for Hetzner: infrastructure and workers, DNS records, etcd backups to object storage, the certificates of the landscape’s own endpointsBuilt Apache-2.0, being prepared for publication
The node images for Hetzner: Garden Linux and UbuntuBuilt the Garden Linux images published, the Ubuntu image being prepared for publication
The paasbox CLI, which stands up a landscape in a Hetzner projectBuilt being prepared for publication
A landscape on one dedicated server, from a wiped disk to a ready garden and seedBuilt in a lab, most recently on 2026-10-10, with clusters created, hibernated, woken and deleted on it
The PaaS layer on a Gardener cluster: apps, managed Postgres and Valkey, previewsBuilt an open component, being prepared for publication

The versions a new landscape starts with (as of 2026-10-10): Gardener v1.150, Kubernetes 1.36 and 1.35, Garden Linux workers. The open components lists each with its licence and the wave it is published in.

The course Your own managed Kubernetes on Hetzner teaches you to stand up and run a Gardener landscape in your own Hetzner project. It is designed and has no date yet; the training page says what it covers.

Until October 2026 this site offered clusters run for you on a Gardener landscape: a self-service sign-up in a console, list prices per cluster, hibernation, node pools with adopted servers, and an API. That offer ended, and the landscape behind it no longer runs. Its docs pages redirect here or to the page of PaaSbox Clusters on the same topic, and none of its prices or terms is on offer. If you had a cluster or asked about one, write to me.

Gardener is the next level.Learn to run it yourself.