Deploy Agent HQ on Hetzner

Creates a server in your own Hetzner project that installs signed HQ releases, keeps itself updated and is reachable only from your tailnet. Nothing secret goes into the server's setup data, and the admin token is generated on the server, so this site never sees it.

Connect your Hetzner project

Create a project API token with read and write access in the Hetzner Cloud console (Security, API tokens). Each token belongs to one project, so this wizard can only touch that project. The token is sent to this site over HTTPS to make the Hetzner calls for you. It is not stored, logged or kept after you close the tab, and you can delete it in Hetzner when you are done.

How it works, the security model, retry and delete: docs/HETZNER.md.