If you run some cluster FS on your single, external network interface, it's quite easy to DoS your cluster.
There is no option to place a service inside a DC, you can ask them but this will result in a manual provision taking days —or be ignored. Also you don't know how the different DCs are connected in terms of internal bandwidth and external reliability. Hetzner itself says their inter-dc connections "are not optimized", whatever that means.
If you run multiple customers on your system and one get's DoSed, Hetzner will disconnect your system. Sure, this was good enough 2-3 years ago, but they didn't change their DoS, provisioning and networking setup.