Everything for DevOps in One Place
Git hosting, CI/CD, container and package registries, issues, pull requests, GitOps deployment and security - in a single binary, at 46 MB of memory when idle
Git Hosting
Full-featured Git repository hosting with a modern web interface, built-in SSH server, and large file support
- HTTP Smart and a built-in SSH server (no system sshd)
- Branches, tags, blame with authorship, commit comparison
- Web editor: create, edit, multi-file batch commit
- Releases with binary artifacts
- Git LFS (Batch API + File Locking)
- GPG commit signatures: verification against account keys with author email matching
- Built-in Wiki with revision history
Compatibility and migration
Third-party tools work after changing the instance address and token, and history moves over together with pull requests
- The GitHub API on /api/v3 - gh, octokit and compatible libraries work
- The GitLab API on /api/v4 - glab, python-gitlab and the Terraform provider work
- Import from GitHub, GitLab, Bitbucket, Gitea, or arbitrary URL
- Import brings pull requests too (GitHub, GitLab, Gitea)
- An import report in repository settings
- Pull and Push mirroring on a configured interval or on demand
- The /api/v1 compatibility promise: what never changes in responses and how long a deprecated call lives
CI/CD Pipelines
Powerful continuous integration and delivery with built-in runner and YAML configuration
- YAML configuration in .gitriver/workflows/
- DAG dependencies (needs:) for parallel execution
- Matrix builds with fail-fast and max-parallel
- Rules (if/changes/when) with expression evaluator
- Retry with conditions (script_failure, stuck_or_timeout, always)
- Artifacts (paths, dotenv, JUnit, coverage reports)
- Cache with key interpolation and push/pull/pullpush policies
- Service containers (Docker networking, alias, env)
- 4-level variables: Instance -> Group -> Repo -> Environment
- Concurrency groups with auto-cancel interruptible pipelines
- Manual jobs (play button from UI)
- External Actions (uses: owner/action@ref)
- Scheduled pipelines (cron expressions)
- Web Terminal - interactive debugging (xterm.js + WebSocket + PTY)
- Remote Runners + K8s Auto-Scaling (pod template, tolerations)
- Docker-in-Docker (auto-detect: sysbox/rootless/privileged)
- Secret masking in logs
- Test and Coverage Reports (JUnit XML + Cobertura XML)
- Foreign code waits for human approval before it takes runners
- Cache across runs on remote runners, eviction of forgotten cache
- Schedules are stored in the database; the pipelines page names the reason a schedule stays silent
Container Registry
OCI-compatible Container Registry - built into the platform, no separate service required
- OCI Distribution Spec v2 (monolithic + chunked upload, cross-repo mount)
- Docker Token Auth (JWT with OCI scopes)
- Multi-arch manifests (index/manifest list)
- Vulnerability scanning (Trivy, SARIF)
- Tag Immutability Rules (glob patterns)
- Retention Policies (keep_last + max_age_days)
- Garbage Collection (manual + scheduled)
- Image Detail (layers, config, metadata)
- Quota tracking per-repo
- Storage backends: Filesystem + S3-compatible
- Image Drift Detection (live vs desired digest)
Package Registry
Private package repositories for 7 formats plus a mirror of external registries - free in Community
- npm (publish, install, metadata, search)
- PyPI (PEP 503, upload, simple index, download)
- Cargo (publish, yank/unyank, download, index, search)
- Maven (PUT/GET artifacts)
- NuGet V3 (push, delete, query, search, registration)
- Generic (upload/download arbitrary files)
- CI/CD integration for auto-publishing
- Composer (Packagist v2)
- Mirror of an external image registry: docker pull through your instance
- Proxied package delivery: external registry cache, warm-up, eviction, reports
Issues & Projects
Task and project management with Kanban boards, templates, and full-text search
- Issues with labels, assignees, and milestones
- Kanban boards (Projects, drag-and-drop, issue linking)
- Issue and PR templates (.gitriver/templates/)
- Markdown comments
- Issue relationships
- Filtering and full-text search
Pull Requests & Code Review
Complete code review workflow with branch protection, CODEOWNERS, and automatic merging
- Inline code comments in diff
- Code Review: approve / request changes
- CODEOWNERS - automatic reviewers by file paths
- Merge Queue with CI integration and temporary branches
- Branch protection (pattern matching, required approvals, CI checks)
- Squash, merge, and rebase strategies
- Cross-repo PR from forks
- Assignees and Review Requests
- Require signed commits
- Require up-to-date branch
- Discussion threads: replies, resolve marker, unresolved counter
- The "all discussion threads resolved" merge rule
GitOps Deploy (RiverCD)
Built-in GitOps controller - Kubernetes deployment directly from GitRiver without external tools
- Deployment, StatefulSet, DaemonSet, Job, CronJob
- Service, ConfigMap, Secret, PVC, Ingress, HPA
- CRD (Custom Resources, arbitrary manifests)
- Sync Waves (resource application ordering)
- Pre/Post Sync Hooks
- Drift Detection (live vs desired diff)
- Health Checks (per-resource, AppHealth)
- Canary Deployments (weight-based traffic shift)
- Blue-Green Deployments (service switching)
- Rollback to previous version
- Pod Logs and Pod Diagnostics from UI
- Multi-cluster (add and test clusters)
- Pull-based GitOps (auto-sync on HEAD change)
Knowledge and assistant
ProMaxTeam knowledge lives next to the code, and a language model analyses a failed build and pull request changes
- Knowledge records in .gitriver/knowledge/ - alongside the code and its history
- Drafts: assembling a batch of drafts into a branch and a pull request
- Secret scanning of a record on intake
- A knowledge tab in the repository with search
- Team counter roll-up and the "dead knowledge" report — Pro
- Code index: a "Symbols" tab, jump to definition and to callers — Pro
- Assistant: analysis of a failed CI job — Pro
- Assistant: analysis of pull request changes in a machine-tagged comment — Pro
- Model provider settings, spend accounting and per-user and per-group limits — Pro
- Knowledge draft limits — Max
Security & Analytics
ProMaxVulnerability scanning, dependency license compliance and DORA metrics in Pro; the audit log, quotas and installation-level IP rules in Max
- Vulnerability Scanning (SARIF Import: Semgrep, Trivy, CodeQL, OSV) — Pro
- Custom secret scanning patterns (regex) — Pro
- Security Findings Dashboard (severity, status, dismiss) — Pro
- License Compliance (allowlist/denylist, SPDX, CycloneDX SBOM) — Pro
- DORA Metrics (Deployment Frequency, Lead Time, CFR, MTTR) — Pro
- Custom Roles (custom permission sets per-group) — Pro
- Group-level IP rules (whitelist/blacklist) — Pro
- Audit Log - complete action journal — Max
- Installation-level IP rules (filter every incoming request, anonymous ones included) — Max
- Storage Quotas (per-user, per-group) — Max
- Registry image vulnerability scanning (Trivy) - free in Community
- Password checks against breach lists, a single minimum length of 12 characters
Notifications
8 notification channels out of the box with event filtering and message templates
- In-app notifications
- Email (SMTP)
- Telegram
- Max (VK messenger)
- Slack (Block Kit)
- Discord (Embeds)
- Microsoft Teams (Adaptive Cards)
- Matrix (Element)
- Webhooks (HMAC-SHA256, retry, delivery history)
- Email preferences (quiet / mention / all)
- Event filtering (branch/author glob)
- Customizable message templates
Backup & Restore
Full backup with encryption and incremental mode - managed from UI
- Full backup (DB + repositories + registry + CI + Pages)
- Incremental backup (changed files only)
- AES-256-GCM encryption
- Selective restore (choose components)
- Scheduled backups (cron scheduling)
- Auto-rotation (max_backups)
- Checksum verification (SHA256, streaming)
- S3 streaming upload (no OOM)
- One-time download tokens (security)
Pages & Wiki
Static site and documentation hosting directly from your repository
- Static hosting from repository (deploy from ZIP or CI)
- Built-in Wiki with Markdown and revision history
- Custom domains
- SPA fallback (index.html)
- Auto-deploy from CI (public/ artifact)
- Path traversal protection
Authentication & SSO
ProMaxFlexible authentication with enterprise providers, 2FA, and session management
- OAuth2 / OpenID Connect (GitHub, Google, GitLab)
- LDAP / Active Directory (bind, search, test from UI) — Max
- SAML 2.0 (SP metadata, ACS, XMLDsig, SLO, user/group sync) — Max
- SCIM 2.0 (User/Group CRUD, membership sync) — Max
- Two-factor authentication (TOTP with QR, backup codes)
- Personal Access Tokens (PAT, scopes, expiry)
- Deploy Tokens (per-repo, scopes)
- Custom Roles (custom permission sets per-group) — Pro
- Session Management (active sessions, remote logout)
- SSH and GPG keys
- The instance as an OIDC provider: id_token with a verifiable signature (JWKS)
- StartTLS: ldap:// is upgraded to TLS — Max
- Temporary account suspension instead of irreversible deletion
Installation and operation
A single Rust binary and a single PostgreSQL database - from a laptop install to several replicas in Kubernetes
- A single 67 MB binary, 46 MB memory at idle (measured on the 1.1.0 build)
- Docker and docker compose, deb and rpm packages, a Helm chart for Kubernetes
- Several replicas: background jobs are run by one of them, leadership on PostgreSQL locks
- Docker-free installation: the whole CI queue goes to remote runners
- Built-in SSH server - no system sshd, keys and settings from the admin area without a restart
- Setup wizard on first launch
- PostgreSQL 15 and newer (tests run on 17, the bundled compose brings up 18)
- The API documentation and the licence agreement text work without internet access
- Proxied package delivery - operation in an air-gapped network