Skip to content

What's included

This is the complete feature list, in one place, so the other pages can point here instead of repeating it. Each feature links to the page that shows how to use it. Every row says where the feature comes from — Gardener, the open-source cluster manager PaaSbox is built on, or PaaSbox, the layer on top — and which kind of cluster gets it. Facts are as of 2026-09-06.

Two kinds of cluster exist: a test cluster (€49/month, one etcd and one API server) and a production cluster (€99/month, a highly available control plane). Everything below is included in both unless the tier column says otherwise. Pricing has the price side.

FeatureWhat you getFromTier
Operated control planeAPI server, etcd, scheduler and controllers run as managed components; nothing on your nodes or your Hetzner billGardenerboth
Highly available control planethree etcd members and three API servers over three platform nodes; a platform node can fail without a pauseGardenerproduction
Kubernetes versionstwo current minor versions, 1.36 and 1.35; you pick at creation; patches roll automaticallyGardenerboth
Provisioning timeabout 10–15 minutes from token to kubectl get nodesPaaSboxboth
API endpointa DNS name and TLS certificate per cluster, no per-cluster load balancerGardenerboth
Secrets encrypted at reston by default; the key rotates automatically every 28 daysGardenerboth
Audit log on the API servera default audit policyGardenerboth
Short-lived credentials onlyno static admin token exists anywhereGardenerboth
Health conditionsAPI server, control plane, nodes and system components each report health; the console shows them with the last operation and its progressGardener + PaaSboxboth
FeatureWhat you getFromTier
Continuous etcd backupsdelta snapshots every five minutes, a full snapshot daily, to object storage in GermanyGardenerboth
Retentionevery snapshot of the last hour, hourly for a day, daily for a week, weekly for four weeksGardenerboth
Automatic restoreetcd data loss is recovered from the latest snapshot without a ticketGardenerboth
Recovery pointup to five minutes on a test cluster; zero for a single platform-node failure on a production clusterGardenersee text
Rebuild after total lossabout 30–40 minutes, drilled before every releasePaaSboxboth
Workloads during a control-plane outagepods keep running and serving; what pauses is changeGardenerboth
FeatureWhat you getFromTier
Your own Hetzner projectnodes, load balancers and volumes are created in your project and billed by Hetzner to youPaaSboxboth
Adopt grandfathered serversservers you already own become worker nodes, rebuilt in place and never deleted, so their pre-2026 price survivesPaaSboxboth
Never-delete, structurallythe component that manages adopted servers has no delete path; Hetzner delete protection is the second guardPaaSboxboth
Pooled and on-demand pools togethergrandfathered baseline plus current-price burst in one cluster; the autoscaler fills the pool firstPaaSboxboth
Machine typescpx22 to cpx62, ccx13 to ccx43; dedicated (Robot) servers on requestPaaSboxboth
Worker imagesGarden Linux and Ubuntu 24.04, both maintained by the platformGardenerboth
Cluster autoscalerper pool between the minimum and maximum you set; the minimum is one nodeGardenerboth
Self-healing nodesan unhealthy on-demand node is replaced after a health timeout; an adopted server is rebuilt in placeGardener + PaaSboxboth
Rolling updatesnode rolls respect PodDisruptionBudgets; surge and unavailability are yours to setGardenerboth
Labels, taints, kubelet settings, sysctlsper pool, validated before they reach the clusterGardenerboth
Placement groupsspread a pool over separate hostsPaaSboxboth
Node-critical readinessnew nodes take workload pods only once networking, storage and proxy are readyGardenerboth
Vertical Pod Autoscaler, HPA, metrics-serverincluded and onGardenerboth
FeatureWhat you getFromTier
CNICalico, IPv4, with a node range you chooseGardenerboth
Load balancersService type: LoadBalancer creates a Hetzner load balancer in your projectPaaSboxboth
VolumesHetzner volumes as the default StorageClass, expandable, up to 16 per serverPaaSboxboth
Managed CoreDNS and node-local DNSDNS inside the cluster is operated and autoscaled for youGardenerboth
Private workerspools without public addressesPaaSboxboth
Private clusters with a NAT gatewayone gateway per cluster in your project: a stable egress IP, allow-lists by CIDR and name, an audit mode, logs to your own collector, self-healingPaaSboxboth
Host firewall on every nodekubelet, proxy and SSH closed on public addresses; SSH only from networks you allowPaaSboxboth
Bring your own networkattach workers to an existing Hetzner network; it is never created or deleted by usPaaSboxboth
No inbound ports requiredthe control plane reaches nodes over an outbound tunnelGardenerboth
FeatureWhat you getFromTier
Maintenance windowyou pick it; patches, image updates and restarts happen inside itGardenerboth
Automatic patch and OS image updateson by default, each switchableGardenerboth
Forced upgrades off expired versionsno cluster is left on end-of-life KubernetesGardenerboth
Run maintenance now, reconcile, retryone button, one API callPaaSboxboth
Hibernationby hand or on a cron schedule with a time zone; state and volumes survive; wake in minutesGardener + PaaSboxboth
Credential rotationCA, service-account key, etcd key, SSH key rotate on schedule or on request; status visible in the consoleGardenerboth
FeatureWhat you getFromTier
Cluster-admin kubeconfigminted on demand, valid 1, 4 or 8 hours, never stored, issuance auditedGardener + PaaSboxboth
Bring your own identity provideryour OIDC issuer and groups in the cluster API; your RBACGardener + PaaSboxboth
Teams, roles, invitations, scoped API keysone team owns clusters, connections, fleet and billingPaaSboxboth
Token custodyyour Hetzner token is validated once, stored encrypted, never shown again, rotatablePaaSboxboth
Activity logevery change to a cluster, who made it and whenPaaSboxboth
Escrowyour cluster’s etcd snapshots and keys copied continuously, encrypted to your key, into a bucket in your projectPaaSboxboth
Exit kitopen source; bootstraps a garden and seed in your project and restores your control plane from the escrow, nodes reconnecting without a restartPaaSboxboth
Wind-down promisesix months’ notice, migration help at no charge, prices frozen, everything publicPaaSboxboth
FeatureWhat you getFromTier
Cluster composerinvalid combinations are shown greyed with the reason, not rejected after submitPaaSboxboth
REST APIdeclarative, with an OpenAPI schema and a TypeScript clientPaaSboxboth
Gardener settings in Gardener’s schemaan allow-listed set of settings per cluster and per pool, validated server-sidePaaSboxboth
Export as Gardener YAMLthe exact cluster definition, redacted of secrets, at any timePaaSboxboth
Status passthroughGardener’s last operation, errors and warnings, verbatim, with error codes turned into what to doPaaSboxboth
Cost and savings viewthe PaaSbox fee next to your Hetzner spend and what your adopted servers savePaaSboxboth
FeatureWhat you getFromTier
Monitoring stack for the clustermetrics and dashboards the platform uses to operate your cluster, which your own monitoring can federateGardenerproduction
NAT gateway metrics and alertsthe gateway’s metrics scraped inside your cluster, with alerts for gateway down, denials and conntrack pressurePaaSboxproduction
Health in the consoleconditions, last operation, hibernation state, for every cluster, even when the cluster itself is downPaaSboxboth

More on what the test cluster deliberately does not have is on monitoring & alerts.

FeatureWhat you getFromTier
Flat fee per clusterno per-node fees, no seats, no user limitsPaaSboxboth
Hourly pay-as-you-go€0.15 per awake hour, a 4-hour minimum per active period, €0 while hibernated, never more than the monthly pricePaaSboxtest
Included footprintup to 10 worker nodes, about 500 pods, about 50 attached volumes per clusterPaaSboxboth
Spend caps€200 a month on a new account, raised with billing history; at the cap clusters hibernate, never deletePaaSboxboth
Data locationcontrol planes and backups in Hetzner data centres in Germany; Hetzner is the only sub-processorPaaSboxboth
Support boundarywarranty is free, assistance is billable; the exact line is on pricingPaaSboxboth

The platform does not expose everything Gardener can do. Not offered: zone-spread control planes (one zone per cluster), multi-zone node pools, dual-stack networking, ARM nodes, root-volume sizing, the deprecated Gardener add-ons, and a web terminal. The smallest node pool is one node. If one of these decides your choice, tell us.