Layer 5 · self-hosting reality check
What it actually takes to self-host Gogs
The docs say 512 MB with 2 CPU cores, the README's 'baseline for teamwork'. It says a Raspberry Pi or $5 droplet is 'more than enough to get you started'. In practice you want 1 GB for Gogs plus a database. The README says memory use stays low as teams grow. Here is the honest version — real requirements, real monthly cost, what you will be maintaining, and the one thing that catches people out.
Usually reached from GitHub alternatives, where Gogs is one of the picks.
Wondering whether you need to at all? Is GitHub free? — what the free tier actually allows, and where the wall is.
| RAM — documented minimum | 512 MB with 2 CPU cores, the README's 'baseline for teamwork'. It says a Raspberry Pi or $5 droplet is 'more than enough to get you started' |
|---|---|
| RAM — what it really needs | 1 GB for Gogs plus a database. The README says memory use stays low as teams grow |
| CPU | 2 cores per the README; add cores as the team grows |
| Disk | Repositories and LFS objects. Gogs itself is a single Go binary. |
| Monthly cost | $5–6/mo for a 5–20 user instance on a 1 GB VPS |
| Setup time | 20 minutes with Docker or the binary and the first-run web installer |
| How you install it | The gogs/gogs Docker image or a single binary, with SQLite, PostgreSQL or MySQL. 0.14.x still has a first-run web installer; the unreleased 0.15 line removes it, so you will write app.ini by hand. |
| Ongoing maintenance | There were no releases from February 2023 to December 2024. Since then releases have come as batches of security fixes (0.13.2 Dec 2024, 0.13.3 Jun 2025, 0.13.4 Jan 2026, 0.14.x Feb–Jun 2026). Watch the advisories and patch the same week. |
| Where it stops scaling | The README says to add CPU cores as the team grows while memory stays low. Use PostgreSQL rather than SQLite for a team, and it runs comfortably on one small box. |
The thing that catches people out
Lightweight does not mean low-risk. In 2024 SonarSource disclosed four critical (CVSS 9.9) Gogs flaws, including remote code execution through the built-in SSH server, after 14 months without a fix. They were patched in 0.13.2 in December 2024. Then 0.14.3 (June 2026) fixed 22 more security issues, two of them remote code execution. Many need only an ordinary logged-in account, and 0.14.x allows anyone to sign up by default. Run 0.14.3 or later, set DISABLE_REGISTRATION = true, and patch within days.
When not to self-host Gogs
You need CI, a package registry or an active feature roadmap. Gogs's feature list has none of them. Forgejo, which descends from Gogs through Gitea, has CI and packages and ships a new version every quarter.
Every guide here carries this section. A site that only ever tells you to self-host is selling something — the useful answer is sometimes no.
Other Layer 5 self-hosting guides
- Self-hosting LibreOffice2 GB with a large spreadsheet open
- Self-hosting ONLYOFFICE6 GB for the Document Server with a handful of concurrent editors
- Self-hosting Collabora Online4 GB, and roughly 1 GB per 20 concurrent documents
- Self-hosting CryptPad2 GB for a small instance
- Self-hosting Mattermost4 GB for a team of 50 with PostgreSQL on the same box
- Self-hosting Rocket.Chat6 GB with MongoDB on the same machine
Common questions
- How much RAM does Gogs actually need?
- 1 GB for Gogs plus a database. The README says memory use stays low as teams grow in practice. The documented minimum is 512 MB with 2 CPU cores, the README's 'baseline for teamwork'. It says a Raspberry Pi or $5 droplet is 'more than enough to get you started', which is the figure at which the process starts rather than the figure at which it works under real use. 2 cores per the README; add cores as the team grows alongside it.
- What does self-hosting Gogs cost per month?
- $5–6/mo for a 5–20 user instance on a 1 GB VPS This is commodity VPS pricing and excludes your time, which is the larger cost for most people — budget for there were no releases from February 2023 to December 2024. Since then releases have come as batches of security fixes (0.13.2 Dec 2024, 0.13.3 Jun 2025, 0.13.4 Jan 2026, 0.14.x Feb–Jun 2026). Watch the advisories and patch the same week.
- How long does it take to set up Gogs?
- 20 minutes with Docker or the binary and the first-run web installer, via The gogs/gogs Docker image or a single binary, with SQLite, PostgreSQL or MySQL. 0.14.x still has a first-run web installer; the unreleased 0.15 line removes it, so you will write app.ini by hand..
- When should I NOT self-host Gogs?
- You need CI, a package registry or an active feature roadmap. Gogs's feature list has none of them. Forgejo, which descends from Gogs through Gitea, has CI and packages and ships a new version every quarter.
- What is the most common mistake when self-hosting Gogs?
- Lightweight does not mean low-risk. In 2024 SonarSource disclosed four critical (CVSS 9.9) Gogs flaws, including remote code execution through the built-in SSH server, after 14 months without a fix. They were patched in 0.13.2 in December 2024. Then 0.14.3 (June 2026) fixed 22 more security issues, two of them remote code execution. Many need only an ordinary logged-in account, and 0.14.x allows anyone to sign up by default. Run 0.14.3 or later, set DISABLE_REGISTRATION = true, and patch within days.