Every time I deploy a new Rails app to a €4 Hetzner box I lose an evening to the same things: forgetting to open the firewall, Let's Encrypt failing because Cloudflare's proxy was on, ERR_TOO_MANY_REDIRECTS from Flexible SSL, exec format error because I built on an M-series Mac, DB_HOST pointing at the wrong container name.
So I wrote it all down as scripts and I'm sharing it:
– hetzner-bootstrap.sh creates the server through the Hetzner API with a cloud-init that installs Docker, creates a deploy user, locks down sshd, ufw 22/80/443, fail2ban, 2 GB swap. Waits until it's ready and saves the IP.
– cloudflare-dns.sh creates the A record and sets SSL to Full (strict) + Always HTTPS through the API.
– preflight.sh checks tools, secrets, SSH, docker and DNS before kamal setup so the error is readable instead of a 200-line SSHKit trace.
– A Kamal 2 deploy.yml with proxy TLS, web + job roles (Solid Queue), Postgres accessory bound to localhost, volume, asset_path, aliases.
– A troubleshooting doc with the ~14 errors I've hit and the fix for each.
The whole flow is make server → make dns → make check → make first.
I'm selling it for $10 (link in the comments so the post isn't an ad). Happy to answer any Kamal/Hetzner/Cloudflare questions here either way, the troubleshooting section is basically my notes and I'll paste specific fixes in the thread if anyone is stuck.
Source: r/rails · by /u/MelodicInsect279