Deploy a self-hosted git forge and CI with OpenTofu
Deployment
Deploy a self-hosted git forge and CI with OpenTofu
Stand up Forgejo with a bundled Forgejo Actions runner on one CPU VM using the validated OpenTofu templateforgejo-git-ci. Forgejo Actions runs CI from the same workflow syntax as GitHub Actions. A data volume at /var/lib/forgejo holds repositories, CI artifacts, and the runner's Docker layers.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
Forgejo
s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps
$33.00/mo
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
$0.00
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
$0.00
Pricing data last validated: . For current rates, check quake.ai/pricing.
Click to zoom
Forgejo git and CI topology: private subnet, forge and Actions runner with a data volume, and one floating IP
Leave domain commented out to start on the floating IP over HTTP. Set domain later when you point DNS at the forge and configure TLS. Defaults match the Forgejo Git and CI reference page.
Open web_url in your browser and sign in with the admin username and generated password. Rotate the password under Settings > Account, then delete the credentials file:
Create a private repository named ci-demo in the forge UI. Generate a personal access token with the write:repository scope under Settings > Applications.
On your workstation:
bash
git clone "http://$FORGE_IP/forgejo-admin/ci-demo.git"cd ci-demomkdir -p .forgejo/workflowscat > .forgejo/workflows/ci.yml <<'YAML'on: [push]jobs: build: runs-on: docker steps: - uses: actions/checkout@v4 - run: node --version - run: echo "CI is running on my own forge"YAMLgit add .forgejo/workflows/ci.ymlgit commit -m "Add CI workflow"git push origin main
Open the Actions tab in the ci-demo repository and confirm the run goes green. If the run stays queued, check Site Administration > Actions > Runners or read runner logs on the instance.
Set domain in terraform.tfvars, point the DNS A record at floating_ip, run tofu apply again, and terminate TLS with Forgejo ACME or a reverse proxy. See the template reference page for both paths.
Run tofu destroy from the project directory when finished. Type yes to confirm. Verify in the Console that the instance, data volume, and floating IP are gone.