Building a Lean GitOps Infrastructure: Woodpecker CI and Renovate Bot on ARM VPS
Introduction: The Shift Toward Lean GitOps
In the modern DevOps landscape, GitOps has become the gold standard for continuous delivery and infrastructure management. However, traditional GitOps toolchains often come with a heavy footprint. Running resource-intensive CI/CD engines and automated dependency management platforms can quickly drain IT budgets, especially for startups and small-to-medium enterprises.
Fortunately, the rise of ARM-based virtual private servers (VPS) offers a compelling alternative: exceptional performance per dollar. By pairing this cost-efficient hardware with lightweight software like Woodpecker CI and Renovate Bot, you can construct a robust, fully automated GitOps pipeline that runs smoothly on minimal infrastructure. This article provides an architectural blueprint and practical implementation guide for establishing a lean GitOps ecosystem entirely on an ARM VPS.
Why ARM VPS, Woodpecker CI, and Renovate Bot?
Before diving into the implementation details, it is essential to understand why this specific combination of technologies represents a paradigm shift for lean engineering teams.
1. The ARM Advantage in Cloud Computing
ARM architecture (such as Ampere Altra instances found in Oracle Cloud, AWS Graviton, or Hetzner’s ARM offerings) delivers predictable performance at a fraction of the cost of traditional x86_64 processors. For CI/CD workloads, which are inherently bursty and parallelized, ARM provides highly efficient core scaling, making it the perfect host for self-hosted infrastructure.
2. Woodpecker CI: The Lightweight Automation Engine
While Jenkins is often considered a legacy monolith and GitLab CI/GitHub Actions can become expensive or complex to self-host, Woodpecker CI emerges as a fork of Drone CI that prioritizes simplicity and low resource consumption. Written in Go, it utilizes a container-first design, executing pipeline steps in isolated containers. Its minimal memory footprint ensures your ARM VPS resources are spent running tests and deployments, not maintaining the CI server itself.
3. Renovate Bot: Automated Dependency Management
A critical, often overlooked component of GitOps is keeping dependencies secure and up to date. Renovate Bot automates this tedious process by scanning repositories, detecting outdated packages or container images, and automatically opening Pull Requests (PRs). When combined with automated testing, Renovate enables a true GitOps workflow where infrastructure and application updates are declared, verified, and merged with zero manual intervention.
Architectural Overview
The system architecture relies on a declarative loop. The central repository holds your application code, Dockerfiles, and Kubernetes manifests (or Docker Compose files). The workflow operates as follows:
- Renovate Bot periodically scans the repository, identifies outdated dependencies (e.g., base Docker images), and creates a new Git branch and Pull Request.
- The creation of the PR triggers a Woodpecker CI pipeline.
- Woodpecker launches specialized ARM-native containers to lint, test, and build the application.
- Once tests pass, the PR is merged into the main branch, triggering Woodpecker to deploy the updated manifests to the production environment on the VPS.
Note: Because every component runs as an ARM-native binary or container, the entire pipeline operates with near-zero virtualization overhead, maximizing the performance of your VPS.
Step-by-Step Implementation Guide
Let us walk through the practical setup required to deploy this lean GitOps infrastructure on a clean ARM-based Linux server running Docker.
Step 1: Preparing the ARM Environment
Ensure your ARM VPS is running a modern Linux distribution (such as Ubuntu 24.04 LTS or Debian 12) with Docker and Docker Compose installed. Verify that your system architecture is properly recognized:
uname -m
This command should output aarch64, confirming your ARM architecture. Ensure your Docker installation is configured to pull linux/arm64 images by default.
Step 2: Deploying Woodpecker CI
Woodpecker CI uses a server-agent architecture. The server manages configuration and webhooks, while the agent executes the actual workloads. Below is an optimized docker-compose.yml file tailored for an ARM VPS:
version: '3.8'
services:
woodpecker-server:
image: woodpeckerci/woodpecker-server:v2.4.0
ports:
- "8000:8000"
volumes:
- woodpecker-data:/var/lib/woodpecker
environment:
- WOODPECKER_OPEN=true
- WOODPECKER_GITEA=true # Or GITHUB/GITLAB
- WOODPECKER_GITEA_CLIENT=${GITEA_CLIENT}
- WOODPECKER_GITEA_SECRET=${GITEA_SECRET}
- WOODPECKER_GITEA_URL=[https://git.example.com](https://git.example.com)
- WOODPECKER_HOST=[https://ci.example.com](https://ci.example.com)
- WOODPECKER_AGENT_SECRET=${AGENT_SECRET}
woodpecker-agent:
image: woodpeckerci/woodpecker-agent:v2.4.0
command: agent
volumes:
- /var/run/docker.sock:/var/run/docker.sock
environment:
- WOODPECKER_SERVER=woodpecker-server:8000
- WOODPECKER_AGENT_SECRET=${AGENT_SECRET}
volumes:
woodpecker-data:
Deploy this stack using docker compose up -d. The server will be accessible via your configured domain name, ready to integrate with your Git provider via OAuth.
Step 3: Setting Up Renovate Bot
To run Renovate efficiently without an enterprise license, you can execute it as a scheduled cron job or via a self-hosted container running on your ARM VPS. Below is a minimal configuration file (config.js) for Renovate to interact with your self-hosted Git platform or GitHub:
module.exports = {
platform: 'github',
token: process.env.RENOVATE_TOKEN,
repositories: ['your-organization/your-gitops-repo'],
automerge: true,
onboarding: false,
labels: ['dependencies', 'gitops']
};
You can run this on your ARM server using a simple cron job that triggers the official, ARM64-compatible Renovate Docker image every night:
docker run --rm -e RENOVATE_TOKEN=$TOKEN -v $(pwd)/config.js:/usr/src/app/config.js renovate/renovate:latest
Designing the GitOps Pipeline
With both tools active, you need to define the pipeline behavior within your repository. Create a .woodpecker.yaml file in the root of your project. This file specifies how the code should be validated and deployed whenever Renovate or a developer pushes a change.
when:
event: [push, pull_request]
steps:
lint:
image: alpine:latest
commands:
- apk add --no-cache yamllint
- yamllint k8s/ manifests/
build-arm-image:
image: plugins/docker
settings:
repo: [registry.example.com/my-app](https://registry.example.com/my-app)
tags: ${CI_COMMIT_SHA:0:8}
username:
from_secret: registry_user
password:
from_secret: registry_password
when:
event: push
branch: main
deploy-gitops:
image: alpine:latest
commands:
- apk add --no-cache curl
- ./scripts/deploy.sh
when:
event: push
branch: main
This configuration ensures that every Pull Request opened by Renovate is thoroughly linted. Once the PR is merged into the main branch, Woodpecker builds an optimized ARM64 container image and deploys it to your environment, fulfilling the continuous delivery loop.
Best Practices for ARM GitOps Optimization
To maintain a lean, high-performing pipeline on a single or clustered ARM VPS, consider implementing the following best practices:
- Multi-Arch vs. Native Builds: Avoid building x86_64 images on your ARM server using QEMU emulation, as this drastically degrades performance. Stick to native
linux/arm64builds for maximum speed. - Aggressive Caching: Use Woodpecker’s caching plugins to cache node_modules, Go build caches, or Docker layers. This reduces disk I/O and speeds up execution times on constrained VPS storage.
- Resource Limits: Set memory and CPU constraints on your Woodpecker agents within Docker Compose to prevent a single faulty pipeline from locking up the entire host server.
Conclusion
Building a GitOps infrastructure does not require enterprise budgets or heavy cloud architectures. By strategically combining the processing efficiency of ARM VPS, the lightweight execution of Woodpecker CI, and the proactive automation of Renovate Bot, modern business organizations can establish an agile, secure, and self-sustaining deployment engine. This lean approach reduces operational costs, minimizes infrastructure overhead, and allows your engineering team to focus on what matters most: delivering high-quality software quickly and reliably.
