Pros and Cons of Self-hosting a Public Git Forge
It's been over a year since I mostly broke up with GitHub. In that year, I've been running my own public Forgejo instance for my personal projects. It's important to stress the public part, as most of what I'm going to discuss is directly correlated to that.
This isn't a post to critique Forgejo vs. alternatives, either. I found Forgejo to be great. My only gripe is that I very much prefer GitLab runners and AWS CodeBuild to GitHub Actions, which Forgejo Actions is modeled after.
With regard to GitLab, I am in the process of moving my projects over there. Why not Codeberg? Aside from my need for private repositories, I have mixed feelings about their hard-line stance against "AI projects".
I definitely think it comes from the noblest of intentions, but I can't help but think, what happens when a project gets banned erroneously? Because there's no easy way to prove code is or isn't LLM generated, it leaves a lot open for interpretation.
A decade of running a social network in a past life has taught me a lot about the mistakes that can and will be made when attempting to enforce a policy like that.
All right, now that I got the meandering intro out of the way, here's my pros and cons of self-hosting a public git forge for the past year or so:
Pros
- I felt like a counterculture badass. Every time GitHub was afflicted, I was calling you all "sheep" and laughing in between prod deploys.
- Better control and transparency of backups. My hosting provider did their backups, and I backed up the repos offsite. This was in addition to my local clones of the repos.
- Infinite runner minutes glitch.
- It sparked my interest in Go, as I became kind of obsessed with the idea of being able to compile and deploy a single binary.
- No service accounts, but since it was my server, I could add accounts for my agentic experiments without fear of repercussions.
- I learned quite a few new nginx rate-limiting tricks while hardening the server.
Cons
- I was running 2 small instances on Linode (Forgejo + Forgejo Runner), so the cost was greater than zero.
- Massive attack surface, and it was beat to shit regularly.
- Experienced distributed denial-of-service attacks by way of what I assume to be data scrapers feeding LLMs. All coming from residential proxies.
- Spent a lot of time trying to get things dialed in with rate-limiting, and ultimately password-protecting the login page. Yes, I have to enter in a password before I can enter in my password.
- Updates weren't hard, but they were manual. Because of this, I did fear that I would eventually fall victim to a 0-day vulnerability.
- Good luck finding a service that supports your self-hosted Forgejo instance.
- It's kind of lonely being the only user of the git forge.
There's probably some things I've missed, and if I remember them before I'm done migrating my repos, I'll add them.
Conclusion
Could I have simply run a private git forge? Sure, I could. But I still would have needed to put my open source stuff somewhere. After a year of self-hosting, I can say that I've gotten my fill, and I'm fine with that.
I'd say my biggest takeaway is that I really liked running my own CI/CD runner. It's cost-effective at scale, and lets you cut the line. It's seriously the killer feature when self-hosting your own git forge. So much so that I'm probably going to spin up my own self-hosted GitLab runner in the near future.
:wq
Like this drivel? There's a whole RSS feed of it, or subscribe via email.