Yes, put the main IP and gateway which are currently configured on the physical interface into the configuration on vmbr0.
The PVE host doesn't need to know about the additional
VM
IP per se.
Since you have an additional interface with a separate MAC address, the VM will make itself known via ARP to the infrastructure of Hetzner and communicate through the vmbr0 interface.
Edit: Great, it works now. I also hat to disable the firewall via shell, then I could reach the web GUI. Will turn it off again and configure through another VM and LAN if I can manage that.