Back to articles
Technology Insight

Building a 100% Automated GitOps Infrastructure: Integrating Gitea, Woodpecker CI, and Renovate Bot on a Linux VPS

May 30, 2026

Introduction to Self-Hosted GitOps Automation

In the modern DevOps landscape, GitOps has emerged as the gold standard for infrastructure automation and continuous delivery. By using Git repositories as the single source of truth, organizations can achieve unparalleled transparency, auditability, and speed. However, relying on heavy enterprise cloud platforms can quickly become cost-prohibitive for small-to-medium businesses (SMBs) and independent engineering teams.

This article provides a comprehensive blueprint for building a 100% automated, lightweight GitOps infrastructure on a single Linux Virtual Private Server (VPS). By combining Gitea (a lightweight Git service), Woodpecker CI (a minimalist, container-first CI/CD engine), and Renovate Bot (an automated dependency tracking tool), you can eliminate manual operations entirely. This self-hosted stack keeps your operational costs low while maintaining enterprise-grade automation capabilities.

The Architecture: Why Gitea, Woodpecker, and Renovate?

When engineering an infrastructure stack for a resource-constrained Linux VPS, efficiency is paramount. Heavy alternatives like GitLab or Jenkins can easily consume 4GB to 8GB of RAM just sitting idle. Our curated stack is specifically chosen for its minimal footprint and maximum synergy:

  • Gitea: Written in Go, Gitea provides a full-featured Git hosting platform that mimics the GitHub user experience while consuming less than 100MB of RAM.
  • Woodpecker CI: A community-driven fork of Drone CI. It utilizes a simple, container-based pipeline execution model and features an extremely low memory footprint compared to Jenkins or GitLab Runners.
  • Renovate Bot: The industry standard for automated dependency updates. It scans your repositories, detects outdated Docker images, Helm charts, or software packages, and automatically opens Pull Requests with release notes included.
The ultimate goal of this architecture is zero manual overhead. Code changes trigger pipelines, infrastructure state is declared in declarative YAML files, and dependencies upgrade themselves securely overnight.

Prerequisites and System Preparation

Before proceeding with the deployment, ensure your environment meets the following baseline requirements:

  1. A Linux VPS running Ubuntu 24.04 LTS or Debian 12 with at least 2 vCPUs and 2GB of RAM.
  2. A registered domain name with A records pointing to your VPS public IP address (e.g., git.example.com, ci.example.com).
  3. Docker and Docker Compose installed on the host system.
  4. A reverse proxy such as Nginx or Caddy configured to handle TLS termination via Let's Encrypt.

Step 1: Deploying the Foundation (Gitea and Woodpecker CI)

To orchestrate our services cleanly, we will utilize Docker Compose. This ensures isolated networking and straightforward lifecycle management. Create a docker-compose.yml file on your VPS to define Gitea, Woodpecker Server, and Woodpecker Agent.

version: '3.8'

services:
  gitea:
    image: gitea/gitea:1.21
    container_name: gitea
    environment:
      - USER_UID=1000
      - USER_GID=1000
    volumes:
      - ./gitea:/data
    ports:
      - "3000:3000"
      - "2222:22"
    restart: always
    networks:
      - gitops_net

  woodpecker-server:
    image: woodpeckerci/woodpecker-server:v2.1
    container_name: woodpecker-server
    volumes:
      - ./woodpecker:/var/lib/woodpecker
    ports:
      - "8000:8000"
    environment:
      - WOODPECKER_GITEA=true
      - WOODPECKER_GITEA_URL=http://gitea:3000
      - WOODPECKER_GITEA_CLIENT_ID=${GITEA_OAUTH_ID}
      - WOODPECKER_GITEA_CLIENT_SECRET=${GITEA_OAUTH_SECRET}
      - WOODPECKER_AGENT_SECRET=${WOODPECKER_SHARED_SECRET}
    restart: always
    networks:
      - gitops_net

  woodpecker-agent:
    image: woodpeckerci/woodpecker-agent:v2.1
    container_name: woodpecker-agent
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
    environment:
      - WOODPECKER_SERVER=woodpecker-server:8000
      - WOODPECKER_AGENT_SECRET=${WOODPECKER_SHARED_SECRET}
    restart: always
    networks:
      - gitops_net

networks:
  gitops_net:
    driver: bridge

Before launching the containers, configure an OAuth2 Application within Gitea's administration panel to provide credentials for Woodpecker CI. Copy the generated Client ID and Client Secret into an .env file along with a randomly generated string for WOODPECKER_SHARED_SECRET. Once completed, execute docker compose up -d to initialize your core platform.

Step 2: Designing the Declarative GitOps Pipeline

With our version control and CI/CD platform integrated, we must define the deployment mechanism. In a true GitOps model, your application architecture is declared entirely within a specialized repository—often referred to as the infrastructure repo.

Create a repository named infra-live in Gitea. Inside this repository, create a configuration file at .woodpecker/deploy.yaml. This file instructs Woodpecker to execute deployments automatically whenever a commit reaches the main branch:

when:
  branch: main
  event: push

steps:
  validate:
    image: alpine/helm:3.14
    commands:
      - helm lint ./charts/production-app

  deploy-to-vps:
    image: appleboy/drone-ssh:latest
    settings:
      host:
        from_secret: vps_ip
      username:
        from_secret: vps_ssh_user
      key:
        from_secret: vps_ssh_key
      script:
        - cd /opt/apps/production-app
        - docker compose pull
        - docker compose up -d --remove-orphans
        - echo "Deployment successfully executed automatically!"

By leveraging secure secrets stored directly within Woodpecker CI, your deployment credentials remain protected while giving the runner the ability to safely manage services running on your production VPS environment.

Step 3: Integrating Renovate Bot for 100% Automation

The final pillar of our infrastructure is automated dependency management. Without Renovate Bot, your container images and base configurations would gradually become outdated, introducing operational friction and severe security vulnerabilities.

To run Renovate as a self-hosted cron job or a specialized pipeline within Gitea, we must configure a global config.js file that defines how Renovate interacts with our private ecosystem:

module.exports = {
  platform: 'gitea',
  endpoint: '[https://git.example.com/api/v1](https://git.example.com/api/v1)',
  token: process.env.RENOVATE_TOKEN,
  autodiscover: true,
  onboarding: true,
  extends: ['config:recommended'],
  packageRules: [
    {
      matchUpdateTypes: ['minor', 'patch'],
      automerge: true
    }
  ]
};

Notice the inclusion of automerge: true for minor and patch updates. This configuration allows minor library changes or patch-level Docker image tag updates to pass verification steps automatically. If the Woodpecker validation pipeline passes successfully, Renovate will automatically merge the Pull Request, triggering an instant, zero-touch deployment to your production environment.

Best Practices for Security and Monitoring

Running an entire enterprise-grade software delivery pipeline on a single VPS requires stringent operational constraints to maintain maximum availability and robust security:

  • Isolate Runtime Environments: Ensure the Woodpecker Agent does not have unrestricted access to the underlying host filesystem unless absolutely necessary. Utilize Docker network abstraction layers whenever possible.
  • Implement Strict Resource Limits: Use Docker Compose constraints (e.g., mem_limit: 512m) on Gitea and Woodpecker containers to guarantee that an unexpectedly heavy compilation or pipeline run doesn't inadvertently starve your actual production software of memory resources.
  • Automated Backups: Schedule a daily cron job on your VPS to execute a backup of Gitea's internal database and persistent volume mounts, pushing the encrypted archives out to an immutable external object storage location like AWS S3 or Backblaze B2.

Conclusion

By successfully integrating Gitea, Woodpecker CI, and Renovate Bot on a standard Linux VPS, you have effectively engineered a self-sufficient, highly optimized 100% automated GitOps infrastructure. Your engineering workflows are now fully declarative, security updates are handled dynamically by autonomous bots, and system administration tasks have been reduced to code reviews.

This streamlined, lightweight architecture effectively proves that achieving enterprise-level delivery speed and robust engineering automation does not require costly corporate cloud commitments. It merely demands intelligent tool selection and seamless operational integration.

Building a 100% Automated GitOps Infrastructure: Integrating Gitea, Woodpecker CI, and Renovate Bot on a Linux VPS | DPTCloud