Back to articles
Technology Insight

Building an Ultra-Lightweight On-Premise CI/CD Pipeline with Forgejo and Woodpecker CI

June 4, 2026

Introduction: The Quest for Lightweight On-Premise CI/CD

In the modern software development lifecycle, Continuous Integration and Continuous Deployment (CI/CD) have transitioned from luxury frameworks to absolute necessities. However, for organizations managing internal source code under strict data sovereignty, compliance, or budget constraints, the mainstream options can be daunting. Heavyweight tools like GitLab EE or Jenkins often demand substantial infrastructure overhead, requiring multiple gigabytes of RAM just to sit idle.

For small-to-medium enterprises (SMEs) or dedicated internal teams, allocating massive computing resources to DevOps tooling instead of core production applications is inefficient. Enter the powerful minimalist combination: Forgejo and Woodpecker CI. Together, they provide a robust, secure, and ultra-lightweight Git management and automation ecosystem that can run smoothly on a fraction of the hardware required by its competitors.

Why Forgejo and Woodpecker CI?

Before diving into the architecture, it is essential to understand why this specific stack is gaining rapid adoption among DevOps professionals looking for optimized on-premise solutions.

Forgejo: The Community-Driven Git Forge

Forgejo is a clean, community-driven fork of Gitea, created to ensure a truly open-source, independent self-hosted Git service. It retains all the characteristics that made Gitea famous: it is written in Go, compiles to a single lightweight binary, and consumes minimal CPU and memory. A fully functional Forgejo instance can comfortably serve dozens of developers while utilizing less than 100MB of RAM.

Woodpecker CI: A Lean, Container-First Automation Engine

Woodpecker CI is a fork of the Drone CI project. It utilizes a container-first approach, where every pipeline step is executed within an isolated Docker container. Unlike Jenkins, which relies on a complex web of plugins that can introduce security vulnerabilities and performance degradation, Woodpecker uses standardized container images for its plugins. It is highly concurrent, modular, and possesses a negligible footprint compared to modern alternatives.

Architectural Overview: Efficiency by Design

The synergy between Forgejo and Woodpecker CI lies in their shared philosophy of simplicity and speed. The basic architecture of this ultra-lightweight CI/CD system comprises three primary components:

  • Forgejo Core Server: Handles Git repositories, user authentication, pull requests, issue tracking, and webhooks.
  • Woodpecker Server: Orchestrates pipelines, manages user access (via Forgejo OAuth), processes webhooks, and dispatches jobs.
  • Woodpecker Agent(s): Lightweight daemons running on the same or separate machines that communicate with the Woodpecker Server to pull jobs and execute containerized workflows.
By decoupling the server orchestrator from the execution agents, this architecture allows organizations to scale horizontally by simply adding more agents as pipeline demands grow, without bloating the central server.

Step-by-Step Implementation Guide

Let us walk through the streamlined process of setting up this lightweight ecosystem using Docker Compose, which represents the cleanest deployment methodology for on-premise environments.

Step 1: Deploying Forgejo

First, we configure Forgejo to handle our internal source code. Below is an optimized Docker Compose configuration snippet to initialize the service:

version: '3.8'
services:
  forgejo:
    image: codeberg.org/forgejo/forgejo:latest
    environment:
      - USER_UID=1000
      - USER_GID=1000
    volumes:
      - ./forgejo-data:/data
    ports:
      - "3000:3000"
      - "2222:22"
    restart: always

Once deployed, complete the initial web setup, configure your admin account, and ensure your internal repositories are accessible.

Step 2: Configuring Forgejo OAuth for Woodpecker

To achieve seamless identity management, Woodpecker leverages Forgejo as its authentication provider. Navigate to your Forgejo Admin Settings -> Applications and create a new OAuth2 Application. Set the Redirect URI to match your Woodpecker server address: http://:8000/authorize. Safely record the generated Client ID and Client Secret.

Step 3: Deploying Woodpecker Server and Agent

With OAuth credentials in hand, you can now spin up the Woodpecker infrastructure. Add the following service blocks to your configuration:

  woodpecker-server:
    image: woodpeckerci/woodpecker-server:latest
    volumes:
      - ./woodpecker-data:/var/lib/woodpecker
    environment:
      - WOODPECKER_GITEA=true
      - WOODPECKER_GITEA_URL=http://:3000
      - WOODPECKER_GITEA_CLIENT=
      - WOODPECKER_GITEA_SECRET=
      - WOODPECKER_AGENT_SECRET=
    ports:
      - "8000:8000"
    restart: always

  woodpecker-agent:
    image: woodpeckerci/woodpecker-agent:latest
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
    environment:
      - WOODPECKER_SERVER=woodpecker-server:8000
      - WOODPECKER_AGENT_SECRET=
    restart: always

Defining Your First Ultra-Lightweight Pipeline

Woodpecker utilizes a highly intuitive syntax defined in a file named .woodpecker.yaml placed at the root of your repository. Because it is container-native, configuring a pipeline to build, test, and lint an application requires minimal configuration boilerplate.

Consider this standard enterprise example for a localized Node.js application:

pipeline:
  test:
    image: node:20-alpine
    commands:
      - npm install
      - npm run lint
      - npm test

  build:
    image: plugins/docker
    settings:
      repo: internal-registry.local/my-app
      tags: latest
      registry: internal-registry.local
    when:
      branch: main
      event: push

Notice the use of Alpine-based images. This guarantees that your CI execution steps remain as lightweight and fast as the core system orchestrating them, saving precious disk I/O and network bandwidth within your internal network infrastructure.

Key Business Advantages of This Lightweight Stack

Adopting the Forgejo and Woodpecker CI pipeline offers multiple strategic and tactical benefits to modern enterprises:

  1. Exceptional Resource Efficiency: The entire underlying infrastructure can run comfortably on a single core VPS with 1GB to 2GB of RAM, vastly reducing computing costs compared to corporate alternatives.
  2. Strict Data Privacy and Governance: Because both systems are hosted completely on-premise or within a private VPC, your sensitive internal source code and proprietary build artifacts never leave your controlled perimeter.
  3. Reduced Maintenance Overhead: The lack of a convoluted plugin ecosystem means fewer security vectors to patch, predictable upgrades, and long-term stability for operations teams.
  4. Rapid Execution Speeds: Eliminating heavy runtime wrappers allows container jobs to instantiate almost instantaneously, accelerating the feedback loop for active developers.

Conclusion

Building a modern, robust CI/CD workflow does not require sacrificing your infrastructure's computing power to resource-heavy platforms. By pairing Forgejo with Woodpecker CI, businesses can establish a resilient, secure, and ultra-lightweight DevOps pipeline tailored for internal development. This minimal footprint configuration proves that with modern software design, you truly can achieve maximum enterprise automation with minimal physical resources.