Architectures, Platforms and Operations for Independent Code Hosting
Chapter 1: The GitHub Monoculture Problem
- How GitHub Became Default
- Risks of Platform Lock-in
- The Regulatory and Geopolitical Dimension
- What “Beyond GitHub” Actually Means
- A Framework for This Book
Chapter 2: Git Fundamentals for Infrastructure Engineers
- The Distributed Model and Its Implications
- Objects, References, and Pack Files
- Remote Communication Protocols
- Hooks, Attributes, and Configuration Layers
- Git Internals That Affect Server Design
Chapter 3: The Architecture of a Git Hosting Platform
- Git Alone vs Git Hosting
- Core Platform Components
- The Protocol Stack: SSH, HTTP, and Git Smart Protocols
- Storage Architectures: Filesystem, Distributed Storage, and Object Stores
- Authentication, Authorization, and Identity Integration
- Extensibility: Webhooks, APIs, and Plugins
- Architectural Styles: Monolith vs Microservices
- Operational Complexity: The Hidden Cost
Chapter 4: GitLab, The Full-Stack Platform
- History and Philosophy: From a Side Project to Enterprise Platform
- Architecture: Omnibus, Monolith, and Kubernetes Deployment
- Feature Set: CI/CD, Registry, Security, and DevOps Features
- Operational Requirements: Resource Profile and Scaling
- Licensing: FOSS vs Premium and What That Means
- When GitLab Is the Right Choice
Chapter 5: Gitea and Forgejo, Lightweight and Community-Driven
- Gitea: Origins and Design Philosophy
- Architecture: Go, SQLite, and Single-Binary Simplicity
- The Forgejo Fork: Why It Happened and What Changed
- Comparison: Gitea vs Forgejo vs GitLab
- Deployment Patterns for Small Teams and Personal Use
- Scaling Gitea: Limits and Workarounds
- When Gitea or Forgejo Is the Right Choice
Chapter 6: Bitbucket, Enterprise and Cloud Integration
- Bitbucket Cloud vs Bitbucket Data Center
- Architecture and Deployment Models
- Jira and Atlassian Ecosystem Integration
- Enterprise Features: Branch Permissions, Code Insights, Audit Logs
- Comparison with GitLab and GitHub
- When Bitbucket Fits
Chapter 7: Gerrit, Code Review as a First-Class Citizen
- What Gerrit Actually Is
- Architecture: The Review-Centric Model
- Workflow: Change IDs, Drafts, and Approval Chains
- Integration with Jenkins, CI Systems, and Other Tools
- Operational Considerations: Performance and Complexity
- Gerrit in Practice: Android, Kubernetes, and Other Major Projects
- When Gerrit Is the Right Choice
Chapter 8: SourceHut, Minimalist Philosophy and Tools
- SourceHut Philosophy: Tools, Not Platforms
- The sr.ht Suite: Git, Issues, Mailing Lists, CI
- Architecture: Python, Mail-Driven Workflows, and Simplicity
- Extensibility and Automation via Hook Scripts
- Comparison with Feature-Rich Platforms
- When SourceHut Makes Sense
Chapter 9: Other Notable Solutions and Niche Platforms
- Codeberg and Community-Run Instances
- GitBucket and GitHub-Compatible Alternatives
- Gogs: The Ancestor of Gitea
- Phabricator and Arcanist
- Self-Hosted GitHub Enterprise Server
- Summary of Niche Platforms
Chapter 10: Authentication, Authorization, and Identity
- Authentication Methods: Password, SSH Keys, OAuth, SAML
- LDAP, Active Directory, and Enterprise Identity Integration
- Role-Based Access Control and Fine-Grained Permissions
- SSH Key Management at Scale
- Multi-Factor Authentication and Hardening
Chapter 11: Repository Governance, Branching Strategies, and Collaboration Models
- Branching Models: Git Flow, Trunk-Based, GitHub Flow
- Protecting Branches and Enforcing Policies
- Code Owners and Review Requirements
- Monorepos vs Polyrepos: Architectural Trade-Offs
- Conventional Commits and Structured History
- Governance Tools and Automation
Chapter 12: CI/CD Integration and Automation
- Webhooks: The Universal Glue
- Native CI Systems: GitLab CI, GitHub Actions, Gitea Actions
- External CI: Jenkins, Drone, Cirrus, and Buildkite
- Pipeline Architecture and Design Patterns
- Runners, Executors, and Build Infrastructure
- GitOps: Using Git as the Source of Truth for Infrastructure
Chapter 13: Package and Artifact Management
- Container Registries: GitLab Registry, Harbor, and Alternatives
- Language-Specific Package Managers
- Artifact Storage and Retention Policies
- Integration with CI Pipelines
- Self-Hosted Registry Architecture
Chapter 14: Security and Supply Chain Protection
- Git-Level Security: Signed Commits, Tags, and Verifications
- Dependency Scanning and Vulnerability Management
- Software Bill of Materials and SBOM Generation
- Secrets Detection and Management
- Supply Chain Attacks: Lessons from Real Incidents
- Platform-Level Security Hardening
Chapter 15: Decentralized, Federated, and Experimental Models
- Git’s Native Distribution as a Decentralization Primitive
- Federated Hosting and Cross-Instance Collaboration
- Are We Ready for Decentralized Code Hosting?
Chapter 16: Storage, Performance, and Scalability
- Git Repository Growth: When Does Size Become a Problem?
- Storage Options: Local, NFS, Ceph, S3-Compatible
- Cloning and Fetch Performance
- Database Scaling for Git Platforms
- CDN Strategies and Geo-Distributed Hosting
- Benchmarks and Performance Profiles
Chapter 17: High Availability, Backup, and Disaster Recovery
- Backup Strategies: Bare Clones, Dumps, and Replication
- Point-in-Time Recovery and Versioning
- Geo-Redundant and Multi-Region Deployments
- Disaster Recovery Planning for Git Infrastructure
- Monitoring and Alerting for Repository Health
Chapter 18: Observability, Logging, and Auditing
- Operational Metrics: What to Measure and Why
- Log Aggregation and Analysis
- Audit Logging for Compliance
- Tracing User Actions Across the Platform
- Compliance Frameworks: SOC2, ISO 27001, GDPR
- Security Monitoring and Incident Response
Chapter 19: Enterprise Deployment, Compliance, and Air-Gapped Environments
- Air-Gapped and Offline Deployments
- Multi-Cloud and Hybrid Architectures
- Compliance and Data Residency Requirements
- Enterprise Support and SLAs
- Capacity Planning and TCO Analysis
Chapter 20: Migration, Interoperability, and Emerging Trends
- Migration Strategies: Tools and Processes
- Preserving History, Permissions, and Metadata
- Interoperability Between Platforms
- Emerging Trends: AI-Assisted Development, Enhanced Collaboration, Ecosystem Evolution
- Making Your Choice: A Decision Framework
- The Future of Code Hosting