{"results":[{"id":"complete-ingress-zero-downtime-safe","text":"The fully managed Hetzner ingress pipeline — DNS zones with granular RRSet mutation, managed TLS certificates, hybrid load balancers with health checks — supports zero-downtime production traffic management with resource protection and incremental record updates at every layer.","truth_value":"OUT","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"deletion-safety-net-comprehensive","text":"Hetzner's multi-layer deletion safeguards (protection flags requiring explicit disable, deprecated image blocking, required flags for destructive operations) combined with the consistent delete-only protection pattern form a comprehensive safety net across all resource types — when the DNS zone import destructive-replace behavior is addressed as the remaining gap.","truth_value":"OUT","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"dns-full-bind-compatible-management","text":"Hetzner DNS provides full BIND-compatible zone management with 16 record types, three mutation strategies per RRSet (append/replace/delete), and support for both primary and secondary zones with AXFR.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"dns-to-tls-end-to-end-lifecycle","text":"Hetzner provides an end-to-end managed TLS lifecycle within a single provider — BIND-compatible DNS zone management for domain hosting, automatic managed certificate issuance via Let's Encrypt, and Load Balancer TLS termination with HTTP/2 and HTTP-to-HTTPS redirect — eliminating external DNS and certificate provider dependencies.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"dns-zone-management-production-safe","text":"Hetzner DNS zone management supports production-safe workflows with resource protection, granular RRSet-level mutation (append/replace/delete independently), and secondary zone replication for redundancy.","truth_value":"OUT","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-network-add-subnet-requires-type-and-network-zone","text":"The `hcloud network add-subnet` command requires `--type` and `--network-zone` as mandatory flags.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-network-subnets-scoped-to-network-zone","text":"Hetzner Cloud subnets are scoped to a network zone (e.g., `eu-central`), not to a specific datacenter location.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-object-storage-free-ingress-and-api","text":"Ingress traffic, internal eu-central zone traffic, and all S3 API calls are free for Hetzner Object Storage.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-resource-subcommands","text":"The hcloud CLI resource management subcommands are: certificate, firewall, floating-ip, image, load-balancer, network, placement-group, primary-ip, server, ssh-key, storage-box, volume, zone.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-add-records-auto-creates-rrset","text":"`hcloud zone add-records` auto-creates the target RRSet if it does not already exist.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-add-records-positional-args","text":"`hcloud zone add-records` requires three positional arguments: zone, record name, and record type.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-add-records-record-and-file-exclusive","text":"The `--record` and `--records-file` options in `hcloud zone add-records` are mutually exclusive.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-add-records-ttl-per-rrset","text":"TTL in `hcloud zone add-records` is set at the RRSet level, not per individual record.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-bind-format","text":"Hetzner Cloud DNS zone files use BIND format per RFC 1034/1035.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-create-default-mode-primary","text":"The default zone mode for `hcloud zone create` is `primary`.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-create-protection-delete-only","text":"The `--enable-protection` flag on `hcloud zone create` only supports `delete` as a value.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-create-secondary-requires-nameservers-file","text":"Secondary zones require the `--primary-nameservers-file` option when created with `hcloud zone create`.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-create-zonefile-stdin","text":"The `hcloud zone create --zonefile` flag accepts `-` for stdin input.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-import-replaces-all-rrsets","text":"Zone file import via `hcloud zone import-zonefile` replaces all existing RRSets — it is destructive, not additive.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"hcloud-zone-protection-prevents-deletion","text":"Zone resource protection must be explicitly disabled before a zone can be deleted or modified.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null}],"count":30,"limit":20,"offset":0}