Back to articles
Technology Insight

Building a Lean GitOps Infrastructure: Woodpecker CI and Renovate Bot on ARM VPS

May 30, 2026

Introduction: The Quest for Lean GitOps

In the modern DevOps landscape, GitOps has become the gold standard for continuous delivery. By treating Git as the single source of truth for infrastructure and applications, organizations achieve unprecedented auditability, security, and velocity. However, implementing a traditional GitOps stack—often involving heavyweights like GitLab CI, Jenkins, or Argocd—frequently demands substantial computing resources. For startups, independent developers, and cost-conscious enterprise teams, dedicating multiple vCPUs and gigabytes of RAM just to maintain the automation pipeline is an inefficient use of capital.

Fortunately, the cloud ecosystem has evolved. The rise of high-performance, cost-effective ARM64 architecture (such as Oracle Cloud's Ampere instances or AWS Graviton) paired with ultra-lightweight automation tools opens up a new paradigm. This guide explores how to build a lean, robust GitOps infrastructure using Woodpecker CI and Renovate Bot, running entirely on a budget-friendly ARM VPS.

Why Woodpecker CI and Renovate Bot?

To understand why this specific combination is so powerful, we must look at the bottlenecks of traditional CI/CD setups. Standard tools are often built on monolithic architectures or heavy JVM-based runtimes. In contrast, our curated lean stack prioritizes minimalism without sacrificing capability.

Woodpecker CI: The Lightweight CI Engine

Woodpecker CI is a community-driven fork of Drone CI. It operates on a container-first design philosophy, where every pipeline step is executed inside an isolated Docker container. Key advantages include:

  • Minimal Resource Footprint: Unlike GitLab runner or Jenkins, the Woodpecker server and agent consume mere megabytes of RAM at idle.
  • Native ARM64 Support: Every official Woodpecker image is cross-compiled for ARM architectures, maximizing the hardware efficiency of your VPS.
  • Declarative Syntax: Pipelines are configured via simple, readable YAML files stored directly in your repositories.

Renovate Bot: Automated Dependency Management

A true GitOps workflow is only as good as its dependency management. Manually tracking updates for Docker images, Helm charts, and package managers is prone to human error. Renovate Bot solves this by automatically scanning your repositories, detecting outdated dependencies, and creating structured Pull Requests (PRs). When combined with Woodpecker CI's automated testing, Renovate ensures your infrastructure remains secure and up-to-date with zero manual intervention.

Architecture Overview

Our lean GitOps architecture relies on three core pillars interacting seamlessly on a single ARM VPS:

  1. The Git Provider: A platform like GitHub, GitLab, or a self-hosted Gitea instance acts as the webhook trigger and source of truth.
  2. Woodpecker CI Server & Agent: Orchestrates the build, test, and deployment phases based on Git events.
  3. Renovate Bot: Runs as a scheduled cron job or container within Woodpecker to keep external dependencies updated.
Architecture Note: By utilizing containerized workflows, the host OS remains completely clean. Everything runs inside isolated environments, preventing dependency conflicts and drift on the VPS itself.

Step-by-Step Implementation Guide

Step 1: Preparing the ARM VPS Environment

Before deploying the tools, ensure your ARM VPS is running a modern Linux distribution (e.g., Ubuntu 24.04 LTS or Debian 12) optimized for ARM64. Update the system and install the Docker engine:

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose-v2 -y

Step 2: Deploying Woodpecker CI via Docker Compose

Create a dedicated directory and configure the docker-compose.yml file for Woodpecker. We will utilize Woodpecker's native multi-architecture images.version: '3.8' services: woodpecker-server: image: woodpeckerci/woodpecker-server:latest volumes: - woodpecker-data:/var/lib/woodpecker environment: - WOODPECKER_OPEN=true - WOODPECKER_GITHUB=true - WOODPECKER_GITHUB_CLIENT=your_github_client_id - WOODPECKER_GITHUB_SECRET=your_github_client_secret - WOODPECKER_AGENT_SECRET=a_secure_random_string ports: - "8000:8000" restart: always woodpecker-agent: image: woodpeckerci/woodpecker-agent:latest command: agent volumes: - /var/run/docker.sock:/var/run/docker.sock environment: - WOODPECKER_SERVER=woodpecker-server:8000 - WOODPECKER_AGENT_SECRET=a_secure_random_string restart: always volumes: woodpecker-data:

Run docker compose up -d to launch the CI server and agent. Once active, authenticate via your Git provider to access the Woodpecker dashboard.

Step 3: Configuring Renovate Bot for ARM Efficiency

Renovate provides an official multi-arch Docker image that runs flawlessly on ARM64. To prevent constant background resource usage, we configure Renovate to run as a periodic pipeline job inside Woodpecker rather than a daemon. Create a .woodpecker.yaml file in a dedicated automation repository:

pipeline:
  renovate:
    image: renovate/renovate:latest
    environment:
      - RENOVATE_PLATFORM=github
      - RENOVATE_TOKEN=your_github_personal_access_token
      - RENOVATE_AUTODISCOVER=true
    when:
      event: [cron, push]

Optimizing the GitOps Pipeline for Production

To extract maximum performance from a lean setup, specific optimization strategies should be applied to your workflows:

  • Layer Caching: Use Woodpecker plugins like meltwater/drone-cache to persist Docker layers and package manager caches between runs, drastically reducing build times on low-power VPS instances.
  • Automated Merging (Automerge): Configure Renovate via a renovate.json file to automatically merge minor, non-breaking dependency updates if and only if your Woodpecker CI tests pass successfully.
  • Resource Constraints: Explicitly define memory and CPU limits in your Docker Compose configurations to guarantee that unexpected build spikes do not crash the host operating system.

Conclusion: High Efficiency, Low Overhead

Building a GitOps infrastructure does not require deep pockets or massive computing clusters. By intentionally combining the lightweight, container-first design of Woodpecker CI with the automated intelligence of Renovate Bot, and hosting the entire stack on an ARM VPS, you achieve an enterprise-grade automation system that costs next to nothing to maintain. This approach proves that in modern infrastructure engineering, intelligence and elegant design will always triumph over raw brute-force computing power.

Building a Lean GitOps Infrastructure: Woodpecker CI and Renovate Bot on ARM VPS | DPTCloud