InfraNestInfraNest
DigitalOcean

DigitalOcean integration

Droplets you can actually see the shape of

Connect a DigitalOcean account with one token and every Droplet, volume, firewall, network and DNS zone in it appears in InfraNest — with CPU, memory, disk and network read from DigitalOcean’s own metrics, beside the machines you run at other providers.

Free plan · About 2 minutes · Read-only token works too

  • Real CPU, memory, disk and network per Droplet
  • Power, reboot, rebuild, snapshots and weekly backups
  • Zones discovered on connect, records for any registrar’s domain
  • Certificate expiry tracked with everything else

api-02

cpx41 · Falkenstein · a reading every 5 minutes

CPU

46%

of 8 vCPU

Memory

needs the agent

Disk

needs the agent

Load average

needs the agent

Memory, disk space and load need the agent — a cloud API cannot report them.

api-01

cpx41 · Falkenstein · a reading every minute

CPU

50%

of 8 vCPU

Memory

62%

of 16 GB

Disk

44%

on /

Load average

4.03

8 cores

What the agent adds

  • An alert when the server stops reporting at all — the one thing polling structurally cannot notice.
  • The processes using the most CPU and memory, sampled on the machine itself.
  • What is filling the disk — the largest folders on the fullest mount, so “94% full” arrives with something to delete.
  • The services the machine was told to run, and in plain language why any of them failed.

One command, about a minute — and the same command on every server, whichever cloud it is on.

Droplets in the same list as everything else

Size, region, addresses and tags arrive with each Droplet, and the routine actions come with them: power on and off, reboot, rebuild, snapshot, and DigitalOcean’s weekly backups toggled from here. They sit in one fleet list with every other cloud, which is the only view that answers "what am I actually paying for" in one go.

  • Power, reboot, rebuild and snapshot
  • Weekly backups turned on and off from here
  • Size, region, addresses and tags on every row
  • Volumes, firewalls, networks and load balancers read into your inventory
  • Several DigitalOcean accounts at once
Servers

14 servers · 12 running

+ Add server
Snapshots

Point-in-time copies of your server disks, kept even after a server is deleted.

Create snapshot
IP addresses

Floating IP addresses you can attach to and move between your servers.

5 servers are polled by their provider, so memory, disk space and load are not being measured on them.

NamePrice
DigitalOcean — Staging1 of 5€204.00/mo
queue-01Frankfurt · 165.227.40.22 · s-4vcpu-8gbAgent · every minute€48.00/mo
Hetzner — Production2 of 6€149.59/mo
api-02Falkenstein · 5.75.140.21 · cpx41Provider · every 5 min€30.20/mo
build-01Falkenstein · 5.75.140.50 · cax21Monitoring off€7.49/mo
OVHcloud — Beauharnois1€12.00/mo
edge-us-01Beauharnois · 51.222.204.12 · vps-essential-4No metrics API€12.00/mo
TransIP — Amsterdam1 of 2€60.00/mo
mail-01Amsterdam · 89.41.166.20 · vps-bladevps-x8Provider · every 5 min€40.00/mo

14 servers across 4 accounts · €425.59/mo

web-01 golden imageProtectedfrom web-01 · 80 GB disk · 6.2 GB stored6.2 GB
db-01 nightlyfrom db-01 · 40 GB disk · 11.1 GB stored11.1 GB
queue-01 weeklyfrom queue-01 · 80 GB disk · 14.2 GB stored14.2 GB
api-01 before the 2.4 rolloutfrom api-01 · 60 GB disk · 9.8 GB stored9.8 GB
db-01 before schema migrationProtectedfrom db-01 · 40 GB disk · 11.4 GB stored11.4 GB
mail-01 pre-upgradeProtectedfrom mail-01 · 75 GB disk · 18.6 GB stored18.6 GB

6 snapshots · 71.3 GB stored

3 attached to nothing — €6.30 a month

A reserved address keeps billing after the server it was reserved for is gone. Release it at your provider, or attach it to a server.

IP AddressCost
5.161.70.99Ashburn€1.70/mo
5.75.140.99Nuremberg€0.60/mo
159.203.80.99New York€4.00/mo
49.13.55.30Helsinki€0.60/mo
5.75.140.10Nuremberg€0.60/mo
5.75.140.11Nuremberg€0.60/mo
5.75.140.20Falkenstein€0.60/mo
5.75.140.21Falkenstein€0.60/mo
5.75.140.50Falkenstein€0.60/mo
143.198.60.99Amsterdam
165.227.40.99Frankfurt
89.41.166.21Amsterdam
89.41.166.20Amsterdam
51.222.204.12Beauharnois

14 addresses across 4 accounts

DigitalOcean DNS for a domain you bought anywhere

DigitalOcean will host a zone for any name you point at it, and InfraNest finds the zones you already have the moment you connect. Records are created, edited and deleted in the editor your other providers’ zones use, and each one keeps its own DigitalOcean identifier — so an edit changes the record you meant, and a change made outside InfraNest still lines up.

  • Existing zones discovered and imported on connect
  • Records for any domain pointed at DigitalOcean, whoever sold it
  • Per-record identity, so edits land where you meant them
  • Changes made in DigitalOcean’s panel still match up here
DNSManage DNS records across all your zones and provider accounts.+ Add zone
ZoneSecurityRecords
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.comCloudflare · 7 records · synced 15m ago7
Showing 6 of 13 zones
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind.comCloudflare · 7 records · synced 15m ago7
northwind.ioCloudflare · 7 records · synced 15m ago7
nwcloud.coCloudflare · 4 records · synced 15m ago4
nwcloud.ioDynadot · 4 records · synced 4h ago4
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.deHetzner · 7 records · synced 54m ago7
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind.euOpenprovider · 7 records · synced 2h ago7
northwind.shopPorkbun · 7 records · synced 2h ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.nlTransIP · 7 records · synced 10m ago7

VPCs, and the machines sitting on them

Private networks come in with their CIDR ranges and the Droplets attached to them, so the question of what can reach what has an answer that does not involve reading a diagram someone drew last year. DigitalOcean is also one of the few clouds where a machine can join a network as it is created, rather than being attached afterwards.

  • Private networks with their ranges and members
  • Droplets joined to a network at creation, not after
  • Read beside the networks you run at other providers
private-backbone
10.0.0.0/16

6

servers

2

subnets

0

routes

In plain English

private-backbone is a private network in eu-central. 6 servers are connected over private IPs. No routes — traffic stays inside 10.0.0.0/16.

What attaching a server grants

6 servers are on this network today, and every one of them becomes reachable from the new one on its private address — on every port it exposes there. There is no allow step in between.

HetznerCloud firewall rules do not apply to private-network traffic at Hetzner: services on those private addresses cannot be filtered or seen there, so who is attached is the only control there is.
DigitalOceanDigitalOcean firewalls do filter private-network traffic, so your rules still apply on those addresses.

Staying off a private network is not treated as a problem to fix. A CI runner, or a public site with nothing to share, has no reason to join one. We removed a banner that suggested otherwise: we hold no traffic data, so it was an opinion rather than a measurement.

Certificates, counted once

Certificates held at DigitalOcean appear in your certificate list with their expiry dates, next to the ones at your other providers and the ones your servers issued themselves. Expiry stops being something you check per account and becomes something you are told about.

  • DigitalOcean certificates with their expiry dates
  • One list across every provider and every server
  • Warned ahead of expiry, not after the outage
CertificatesEvery SSL/TLS certificate we see across your infrastructure — discovered automatically from your monitors, with expiry tracking and alerts.+ Add certificate
All sourcesCloudflareDigitalOceanHetznerManualMonitorPublic log (crt.sh)TransIP
SubjectExpires
northwind.com5 certificates4 auto-renew · 2 discovered, not monitored
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
Showing 7 of 11 certificates
northwind.com1 certificates1 auto-renew · 1 discovered, not monitored
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
northwind-app.dev1 certificates1 auto-renew
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.cloud1 certificates1 auto-renew · 1 discovered, not monitored
*.northwind.cloudWildcardLet's Encrypt (R11) · ecdsa 256 · found by Hetznerin 2 months
vpn.northwind.example1 certificates1 discovered, not monitored
vpn.northwind.examplevpn.northwind.example · rsa 4096 · found by Manual12 days ago
northwind.com3 certificates3 auto-renew
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.com1 certificates1 discovered, not monitored
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-mail.com1 certificates1 auto-renew · 1 discovered, not monitored
northwind-mail.com+2Let's Encrypt (R3) · rsa 2048 · found by TransIPin 3 months
northwind.nl1 certificates1 discovered, not monitored
northwind.nl+1Sectigo RSA Organization Validation Secure Server CA · rsa 2048 · found by TransIPin 5 months

See your own Droplets in InfraNest

Free plan, no credit card. Connect an account and the Droplets, zones and certificates appear on their own.

Connect DigitalOcean in about two minutes

One personal access token from the API section of your DigitalOcean account. Read & Write if you want to act on things from here — a read-only token still shows you everything.

  1. 1

    Open the DigitalOcean integration

    Go to Integrations and open DigitalOcean.

  2. 2

    Choose which features to use

    Tick Servers, DNS and Certificates for whichever ones you want InfraNest to manage.

  3. 3

    Connect with DigitalOcean or paste a token

    Select Connect with DigitalOcean and approve it, or paste an API token created at API → Tokens → Generate New Token.

  4. 4

    Select Connect

    Your servers, zones and certificates appear once the connection completes.

That’s it — DigitalOcean is connected.

Full setup guide

Set up with AI

I use DigitalOcean and I want to connect it to InfraNest (infranest.io) — it manages servers, DNS and certificates across providers. It needs a DigitalOcean personal access token, created under API → Tokens/Keys. Walk me through creating one: where that screen is, what the Read and Write scopes each allow, whether the token can be given an expiry, and how to check it works before I paste it in. Also tell me what a read-only token would stop me doing.

What syncs

What InfraNest keeps in sync with DigitalOcean.

Cloud resourcesServers, volumes, firewalls, networks and load balancers
DNS zonesDNS zones and records
CertificatesCertificates and their expiry

What still happens at DigitalOcean

InfraNest can't register or manage domain names through DigitalOcean — that stays with whoever you bought the name from. Volumes, firewalls, networks and load balancers are read into InfraNest but not yet managed from it.

Questions about the DigitalOcean integration

#What happens if my API token expires or gets revoked?

The sync stops and InfraNest shows an authentication failed error. Create a new token in DigitalOcean and paste it in under Reconnect — or set the token to No expiry when you create it so this doesn't come up. One-click connect avoids this entirely, since there's no token to expire.

#Can InfraNest change things on DigitalOcean's side?

Yes. Droplet actions like power, reboot, rebuild, snapshot and backup toggling are sent to DigitalOcean, and DNS record changes made in InfraNest are written back too. Volumes, firewalls, networks and load balancers are currently read-only here.

#Do I need to move my domain to DigitalOcean to use its DNS?

No. DigitalOcean hosts DNS for domains registered anywhere — you just point the domain's nameservers at DigitalOcean and manage the zone from InfraNest.

#Does this stop deletions from happening in the DigitalOcean dashboard?

InfraNest can lock a server, volume, firewall, network or load balancer so it can't be deleted through the interface, the API, a bulk action or your own automations — something DigitalOcean does not offer on its own. It can't stop a deletion made directly in DigitalOcean's dashboard.

#Can I download the actual certificate file through InfraNest?

No. DigitalOcean's API only returns certificate details, not the certificate itself, so InfraNest shows what it covers and when it expires but has nothing to hand you to download.

Bring DigitalOcean into one dashboard

Connect an account in about two minutes, then add the next provider. Everything you run, in one place.

Free plan · No credit card required · Set up in minutes