Back to articles
Technology Insight

Self-Hosting a Lightweight Git Server: Migrating from GitHub to Forgejo on Oracle Cloud Infrastructure ARM Free Tier

May 29, 2026

Introduction: The Case for Self-Hosted Git Infrastructure

In the modern software development lifecycle, the centralized Git repository serves as the single source of truth. For years, platforms like GitHub and GitLab have dominated this space, offering convenience at the cost of data sovereignty, privacy, and potential vendor lock-in. For enterprises, independent developers, and small teams, maintaining absolute control over intellectual property is increasingly paramount.

However, self-hosting a heavy DevOps platform like GitLab typically demands substantial hardware resources, often requiring a minimum of 4GB to 8GB of RAM just to run smoothly. This is where Forgejo enters the equation. As a community-driven, lightweight fork of Gitea, Forgejo provides a robust, secure, and incredibly efficient Git management solution. When paired with the highly generous Oracle Cloud Infrastructure (OCI) Always Free Tier—which grants users up to 4 ARM-based Ampere Altra CPUs and 24GB of RAM—you can deploy an enterprise-grade, lightning-fast Git ecosystem entirely for free.

---

Why Forgejo and Oracle Cloud ARM?

Before diving into the technical implementation, it is vital to understand why this specific combination of software and hardware creates an ideal synergy for source code management.

1. Forgejo: The Lean GitHub Alternative

Forgejo inherits the lightweight architecture of Gitea, compiled in Go. It operates with a near-negligible memory footprint—often consuming less than 100MB of RAM at idle. Despite its minimalism, Forgejo does not compromise on features. It delivers:

  • Comprehensive repository management, pull requests, and code reviews.
  • Built-in Issue Tracking and Kanban-style project boards.
  • Forgejo Actions: A built-in CI/CD engine that is natively compatible with GitHub Actions workflows.
  • Extensive user access controls, organization management, and SSH/HTTPS Git access.

2. Oracle Cloud OCI Ampere A1 Compute

Oracle Cloud's Free Tier is arguably the most generous in the cloud industry. The Ampere A1 Compute instances leverage the ARM64 architecture, providing exceptional multi-threaded performance. Allocating even a fraction of this free tier (e.g., 2 OCPUs and 12GB RAM) to Forgejo results in a blistering fast environment capable of handling hundreds of concurrent users and intensive CI/CD pipelines without hitting a performance bottleneck.

---

Prerequisites and Architecture Overview

To successfully execute this deployment, ensure you have the following prerequisites in place:

  1. An active Oracle Cloud Infrastructure account (Free Tier or Paid).
  2. A registered Domain Name (e.g., git.yourcompany.com) with access to its DNS management console.
  3. Basic familiarity with the Linux command line interface (CLI) and SSH access.

Our production-ready architecture will utilize Docker Compose for container orchestration, isolated behind an Nginx Reverse Proxy acting as the TLS termination point via Let's Encrypt certificates. A PostgreSQL container will serve as the relational database backend for optimal performance.

---

Step-by-Step Deployment Guide

Step 1: Provisioning the OCI ARM Instance

Log into your Oracle Cloud Console and navigate to Compute > Instances > Create Instance. Configure the instance with the following specifications:

  • Image: Canonical Ubuntu 22.04 LTS or 24.04 LTS (Ensure the image is compatible with ARM64).
  • Shape: Ampere (VM.Standard.A1.Flex). Allocate 2 OCPUs and 12GB of RAM.
  • Networking: Assign a Public IPv4 address and select or create a Virtual Cloud Network (VCN).
  • SSH Keys: Generate or upload your public key to ensure secure access.
Critical Security Note: OCI enforces strict ingress rules via Security Lists. Before proceeding, navigate to your VCN's Default Security List and add Ingress Rules to allow traffic on ports 80 (HTTP), 443 (HTTPS), and 2222 (Custom SSH port for Git actions).

Step 2: Server Preparation and Docker Installation

Establish an SSH connection to your newly created instance and update the system packages:

sudo apt update && sudo apt upgrade -y

Next, clear the built-in Ubuntu iptables rules that frequently interfere with Docker networking on OCI instances:

sudo iptables -F
sudo iptables-save | sudo tee /etc/iptables/rules.v4

Install Docker and Docker Compose using the official convenience script:

curl -fsSL [https://get.docker.com](https://get.docker.com) -o get-docker.sh
sudo sh get-docker.sh
sudo usermod -aG docker $USER

Log out and log back in to apply the group membership changes.

Step 3: Configuring the Docker Compose Environment

Create a dedicated directory for your Forgejo stack to keep configuration files organized:

mkdir -p ~/forgejo-stack && cd ~/forgejo-stack

Create a docker-compose.yml file using your preferred text editor. This configuration provisions Forgejo, a PostgreSQL database, and an Nginx proxy companion for automated SSL certificate issuance:

version: '3.8'

services:
  server:
    image: codeberg.org/forgejo/forgejo:7.0-alpine
    container_name: forgejo
    restart: always
    environment:
      - USER_UID=1000
      - USER_GID=1000
      - GITEA__database__DB_TYPE=postgres
      - GITEA__database__HOST=db:5432
      - GITEA__database__NAME=forgejo
      - GITEA__database__USER=forgejo
      - GITEA__database__PASSWD=SecurePassword123!
    volumes:
      - ./forgejo-data:/data
      - /etc/timezone:/etc/timezone:ro
      - /etc/localtime:/etc/localtime:ro
    ports:
      - "127.0.0.1:3000:3000"
      - "2222:22"
    depends_on:
      - db

  db:
    image: postgres:15-alpine
    container_name: forgejo-db
    restart: always
    environment:
      - POSTGRES_USER=forgejo
      - POSTGRES_PASSWORD=SecurePassword123!
      - POSTGRES_DB=forgejo
    volumes:
      - ./postgres-data:/var/lib/postgresql/data

Note: Replace 'SecurePassword123!' with a cryptographically secure string before deploying to production.

Step 4: Launching the Services and Setting Up Reverse Proxy

Execute the stack deployment in detached mode:

docker compose up -d

To expose Forgejo securely to the internet, install Nginx on the host machine to handle reverse proxy routing and Let's Encrypt certificates via Certbot:

sudo apt install nginx certbot python3-certbot-nginx -y

Configure an Nginx server block at /etc/nginx/sites-available/forgejo pointing incoming traffic from your domain to [http://127.0.0.1:3000](http://127.0.0.1:3000). Enable the site configuration and secure it using Certbot:

sudo certbot --nginx -d git.yourcompany.com
---

Post-Installation and Best Practices

Navigate to your domain via a web browser to complete the graphical installation wizard. Ensure the SSH Server Port is configured to 2222 and the Base URL accurately reflects your HTTPS domain name. The initial user registered automatically inherits global administrator privileges.

Optimizing Backup Strategies

Data integrity is vital when self-hosting source code. Implement a cron job on the host machine utilizing the native forgejo admin dump utility. This packages all repositories, configuration schemas, and database records into a single compressed file. It is highly recommended to synchronize these backups to an external object storage location, such as OCI Object Storage, using standard CLI tools.

---

Conclusion

Deploying Forgejo on the Oracle Cloud ARM Free Tier offers an unparalleled blend of efficiency, performance, and financial economy. By taking ownership of your Git infrastructure, you mitigate external systemic risks, completely eliminate per-user licensing costs, and secure absolute control over your continuous integration and deployment environments. The lightweight architecture of Forgejo ensures that your enterprise operates at peak agility without the overhead of bloated resource consumption.

Self-Hosting a Lightweight Git Server: Migrating from GitHub to Forgejo on Oracle Cloud Infrastructure ARM Free Tier | DPTCloud