Manual Provisioning for Hetzner Resellers: What to Automate and What to Keep Human
For a small hosting reseller, “customer pays and a server appears” is not always the best service. The reliable model is often review, provision, bill and document — with automation focused on repeatable work rather than irreversible decisions.
Manual provisioning is not a failure to automate. It can be a deliberate product choice: you review the customer, choose the right location and service size, configure access and security, then hand over a service that matches the agreement. The problem is not the human step. The problem is letting every invoice, renewal and service record become manual too.
A practical rule: automate predictable, reversible and well-defined steps. Keep commercial approval, exceptional infrastructure choices and destructive actions with a responsible person.
Three ways to run a Hetzner reseller service
A fully manual model works for bespoke managed services, but becomes slow as the client base grows. A fully automated catalogue works when every order has fixed choices and no review is needed. Most small resellers are better served by the middle option: review-then-provision.
| Model | Best for | Trade-off |
|---|---|---|
| Fully manual | Complex migrations, managed systems and one-off projects | High operational effort and inconsistent administration if undocumented |
| Review then provision | Small B2B reseller teams with standard services and client-specific terms | Requires a clear handoff from approved order to operations |
| Fully automated catalogue | High-volume, fixed products with pre-defined eligibility and technical choices | Exceptions, risk and support requirements must be designed in advance |
What is worth automating
Hetzner Cloud provides programmatic management for servers and related resources such as Volumes, Firewalls, Floating IPs and Load Balancers. A server build can be standardized around a selected location, image, server type, SSH key, network, volume, firewall and backup settings.
That makes these activities good candidates for automation or a saved operational template:
- creating a client and service record after the order is approved;
- recurring invoice generation, payment reminders and overdue follow-up;
- standard Cloud build parameters such as an approved image, SSH key, label and baseline firewall;
- creating a documented provisioning checklist and client handover email;
- adding standard recurring items for a server, backups or agreed storage;
- recording a one-off setup or migration charge with its agreed scope.
Automating these steps makes the process repeatable. It does not require giving a payment event direct power to create, delete or change infrastructure.
What should remain human
Some decisions affect cost, security, customer data or the reseller’s commercial risk. They should have an explicit owner rather than a blind workflow.
| Keep this human | Why |
|---|---|
| New-client approval and payment-risk review | The technical request is not enough to establish suitable commercial terms. |
| Custom price, discount and support commitment | These are the reseller’s contract decisions, not supplier defaults. |
| Location, architecture and non-standard sizing | Latency, capacity, operating-system and availability choices need context. |
| Firewall exceptions, migrations and data access | They can create security or data-handling consequences. |
| Cancellation, deletion and snapshot retention | These actions can affect data availability and final billing. |
| Resource-limit and exceptional-capacity requests | Hetzner reviews limit increases manually, so a reseller needs its own review path too. |
Use permissions as a guardrail
Hetzner Cloud project roles already reflect this distinction. Members can create, modify and delete most resources, while Restricted members cannot create or delete servers and have limits around backups and snapshots. Apply the same thinking to your internal workflow: routine people and systems should only have the permissions they need; exceptional actions should be deliberate and traceable.
The review-then-provision workflow
- Receive an order or service request and define the client-facing service.
- Review the client, agreed price, payment terms, technical scope and any migration or setup work.
- Approve a standard build or write down the required exception.
- Provision in Hetzner manually or through a controlled template.
- Verify access, firewall, backup scope and service readiness before handover.
- Activate recurring billing, add one-off work where applicable and send the client their service details.
- At renewal or cancellation, review outstanding payments, attached volumes and retained snapshots before closing the service.
This workflow leaves human judgment where it protects the business, while removing repeated administrative work from spreadsheets and inboxes.
Where BillOps fits
BillOps handles the commercial layer around that process: client records, recurring and one-off charges, per-client prices, invoices, payments, reminders and a client portal. Hetzner remains the infrastructure control plane. BillOps does not claim default native provisioning or synchronization with Hetzner; any API connection or custom automation is reviewed and scoped separately.
Official supplier references: Hetzner API overview, creating a Cloud server, Cloud project roles and limits and Robot Webservice.
Make manual provisioning predictable
We can show how BillOps structures approved services, setup work, recurring invoices and client communication around your Hetzner workflow.
Book a 30-minute demo