Hetzner has a free firewall service outside of your machine. You can use that as the first line of defence.
The problem with Hetzner's firewall service is it nukes network performance especially on ipv6.
That's what I use. Is it enough? Or should I also install a firewall on my machine?
It's a good idea. At OCI, I have the VCN firewall enabled and ufw firewall enabled within my VPS's.