Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To run Forgejo behind Traefik, send browser traffic to Forgejo’s web service on container port 3000, set Forgejo’s public ROOT_URL to its HTTPS address, and keep the web service reachable only from Traefik or another trusted network. Git over SSH is a separate connection: route it to Forgejo’s SSH service on container port 22 and make the advertised SSH port match the route clients use.

The examples below show the configuration shape, not a universal Compose file. Replace the domain, Traefik entrypoint, certificate resolver, Docker network, and SSH host port with values that match your deployment.

How Forgejo and Traefik fit together

Forgejo runs as a container with its own web and SSH listeners. Traefik’s Docker provider reads labels from containers and creates a router for web requests. The router terminates HTTPS and forwards the request to Forgejo’s HTTP listener, usually container port 3000 in Forgejo’s documented Docker example. SSH cloning does not use that HTTP router.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Browser and Git-over-HTTPS traffic: client connects to Traefik on the public HTTPS hostname; Traefik forwards to Forgejo’s web port.
  • Git-over-SSH traffic: client connects to the SSH port exposed by your chosen network design; that traffic must reach Forgejo’s SSH listener on container port 22.
  • Persistent application state: Forgejo stores its data under /data; persist that path outside the container.

Forgejo can serve HTTPS without a reverse proxy, but its reverse-proxy documentation describes proxying HTTPS as a common arrangement. See Forgejo’s reverse proxy guidance and Docker installation example.

#1 Best Overall
Sale
GMKtec G3S Mini PC Intel N95 Processor (Up to 3.4GHz) 8GB RAM 256GB M.2 SSD
  • 12th Intel Alder Lake N95 Processor – The GMKtec G3 S Mini PC is powered by the 12th Gen Intel N95 processor with 4 cores, 4 threads, 6MB cache and a burst frequency up to 3.4GHz. Compared with N100/N5105/N5100/N5095, the N95 delivers up to 36% overall performance improvement. Perfect for routine tasks, office work, and home entertainment, this compact mini desktop is more convenient than traditional bulky PCs.
  • 8GB RAM & 256GB SSD Storage – Pre-installed with 8GB DDR4 memory and a fast 256GB M.2 2242 SSD, the G3 S mini desktop offers quicker startup, smoother multitasking, and faster file transfers. Enjoy seamless performance whether you’re working on multiple applications, browsing, or streaming content.
  • Rich Interfaces & Connectivity – The G3 S mini computer comes equipped with USB 3.2 (up to 10Gbps), dual HDMI 2.0 (4K@60Hz), and a 3.5mm audio jack. With support for WiFi 5, Bluetooth 5.0, and Gigabit Ethernet (RJ45 1000MbE), it connects easily with monitors, projectors, printers, office equipment, and other peripherals, making it versatile for both home and business use.
  • Dual 4K Display Support – Featuring upgraded Intel UHD Graphics (up to 1000MHz), the G3 S supports 4K video playback and AV1 decoding for a smooth viewing experience. With dual HDMI outputs, you can connect two 4K@60Hz displays simultaneously, enabling efficient multitasking for work and entertainment.
  • GMKtec WARRANTY - GMKtec offers a 1-year limited GMKtec's warranty for each mini PC, starting from the date of the purchase. All defects due to design and workmanship are covered. With a professional after sales team always ready to attend to your needs, you can simply relax and enjoy your mini PC.

Prepare persistent data and the Docker network

Persist Forgejo’s /data directory

The official Docker example mounts a host directory or Docker volume at /data, where Forgejo keeps its application state. A host bind mount gives you direct control over the storage location; a named Docker volume lets Docker manage the volume location. Either way, persistence is not the same as a backup.

The Forgejo example also sets UID and GID values. If you use a host bind mount, ensure the directory ownership and permissions are compatible with those values; Forgejo warns that an incompatible host directory can prevent the container from starting. An external SSD can hold the host directory if that suits your server, but the drive does not automatically create a backup.

Connect Traefik to Forgejo

Traefik must be able to reach the Forgejo container over a Docker network. You can use a shared external network already used by Traefik, or create a dedicated network and attach both services to it. If Forgejo is attached to several networks, explicitly select the network Traefik should use. Traefik’s Docker provider supports a default network setting and a per-container traefik.docker.network label; see the Docker provider documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Route the Forgejo web interface through Traefik

Add Traefik labels to the Forgejo Compose service to define a router for the public hostname, enable TLS, and point the backend service at container port 3000. The exact label values depend on your existing Traefik setup: use its configured HTTPS entrypoint, certificate resolver, public hostname, and Docker network rather than copying names from an unrelated example.

Rank #2
GEEKOM A5 2027 Edition Mini PC, Ryzen 7 7730U, 16GB RAM, 256GB NVMe SSD
  • [15W Ryzen 7 Agentic PC for Everyday Workflows] Powered by the AMD Ryzen 7 7730U processor (8 Cores, 16 Threads), the GEEKOM A5 is built for sustained productivity. It doubles as your cloud-native Agentic AI assistant, seamlessly hosting cloud AI tasks, automating office workflows, and handling intelligent document summarization without complex local deployment. Smoothly manage Microsoft Office, dozens of browser tabs, heavy Excel spreadsheets, and remote learning throughout your workday.
  • [Smart Value Now, Expandable for Tomorrow] Equipped with 16GB RAM and a fast 256GB PCIe NVMe SSD for snappy daily performance, the A5 offers incredible value. Need more space later? It features dual-slot DDR4 RAM (upgradable to 64GB) and supports an M.2 SSD up to 4TB. With an extra M.2 2242 slot and 2.5" HDD bay for up to 10TB total storage, you get the flexibility to scale your storage seamlessly as your needs grow, beating soldered LPDDR solutions.
  • [Multi-Display Connectivity for Maximum Productivity] Create a complete workstation with support for up to four displays through Dual HDMI and Dual USB-C ports, including up to 8K output via USB-C. Stay connected with Wi-Fi 6, Bluetooth 5.4, a 2.5GbE LAN port, SD card reader, and multiple USB ports for fast networking, efficient multitasking, and seamless connectivity across all your devices.
  • [Built to Stay Cool, Quiet & Reliable] More than fast, the GEEKOM A5 is built to last. A reinforced one-piece all-metal internal frame enhances structural strength, while the upgraded IceBlast 3.0 cooling system improves cooling efficiency by up to 42% with up to 35% greater airflow for quieter operation. Backed by 339 reliability tests and a 72-hour full-load aging test, it's engineered for dependable long-term performance.
  • 🏢[Business-Ready, Compact & Efficient] Pre-installed OS, the GEEKOM A5 supports Wake-on-LAN, Scheduled Power On, and Group Policy, making deployment and remote management simple for businesses. Its ultra-compact 0.6L design fits neatly behind monitors or into space-limited workstations while delivering excellent power efficiency for home offices, front desks, and commercial environments.

A label set has this general shape; substitute the example values with your own configuration:

labels:
  - "traefik.enable=true"
  - "traefik.docker.network=YOUR_TRAEFIK_NETWORK"
  - "traefik.http.routers.forgejo.rule=Host(`git.example.com`)"
  - "traefik.http.routers.forgejo.entrypoints=YOUR_HTTPS_ENTRYPOINT"
  - "traefik.http.routers.forgejo.tls=true"
  - "traefik.http.routers.forgejo.tls.certresolver=YOUR_CERTIFICATE_RESOLVER"
  - "traefik.http.services.forgejo.loadbalancer.server.port=3000"

This is a label example, not a complete Compose deployment. Traefik can often detect a container port, but explicitly setting loadbalancer.server.port avoids ambiguity when automatic selection is unsuitable or multiple ports are exposed. The labels and port behavior are documented in Traefik’s Docker routing guide.

Set Forgejo’s public URL

Configure Forgejo’s ROOT_URL to the exact external HTTPS URL users will open, such as https://git.example.com/. This lets Forgejo generate links using the public scheme and hostname rather than an internal container address or HTTP URL. In Docker deployments, this setting is commonly provided as an environment variable, but confirm the configuration method for the image and version you run.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prefer a dedicated hostname over a subpath

A hostname such as git.example.com is the straightforward choice for a new deployment. Hosting Forgejo at a path such as example.com/git/ requires matching subpath configuration and changes browser same-origin assumptions. Forgejo warns that serving user-controlled content on the same origin can introduce risks; use subpath hosting only when you have a deliberate reason and have considered that caveat.

Rank #3
BOSGAME E5 11 Pro Mini PC, AMD Ryzen 5300U 4C/ 8T, Business Home Office PC
  • 【AMD Ryzen 3 5300U CPU: Outperforms N150 & 3500U】 BOSGAME E5 mini PC is powered by the TSMC 7nm FinFET architecture AMD Ryzen 3 5300U processor (4 Cores, 8 Threads, up to 3.8GHz boost, 6MB total cache). Compared to low-end Intel N150 or 3500U chips which only have 4 single threads and throttle under load, the 5300U delivers over 30% faster multi-core speed. Run 30+ browser tabs, large Excel sheets, and Zoom meetings simultaneously without system lag.
  • 【8GB DDR4 RAM & 256GB NVMe SSD Storage】 Installed with high-speed 8GB DDR4 dual-channel memory and a fast 256GB M.2 2280 SSD, eliminating slow boot times and application loading delays. To accommodate growing data requirements, the upgradeable hardware design features dual SODIMM slots that allow you to expand memory up to 64GB RAM, ensuring smooth operation during heavy multitasking.
  • 【High-Capacity Dual M.2 SSD Storage Expansion】 Never worry about running out of space for your business files. In addition to the pre-installed 256GB system drive, the motherboard houses an extra empty internal M.2 2280 NVMe PCIe 3.0 slot. This allows you to easily add a second solid-state drive for up to an additional 2TB of storage capacity (upgrades not included) without needing to remove or reinstall the original operating system.
  • 【Radeon 6-Core Graphics & Triple 4K Displays】 Integrated with official AMD Radeon Graphics (6 Graphics Cores, 1500 MHz frequency) for casual gaming, photo editing, and crisp 4K media decoding. Featuring 1x HDMI 2.0 port, 1x DisplayPort, and 1x Full-Function Type-C port, the E5 outputs true 4K@60Hz resolution to three monitors at once. This multi-screen setup eliminates constant window-switching for traders, programmers, and office workers.
  • 【Dual 2.5GbE LAN Ports for Advanced Networking】 Experience fast wired network transmission speeds up to 2500Mbps without lagging or buffering. The integration of dual 2.5 Gigabit Ethernet ports (powered by Realtek RTL8125 controller) makes this compact computer an exceptional hardware choice for tech enthusiasts. Easily configure it into software routers, hardware firewalls (pfSense, OpnSense), home NAS servers, or local homelabs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the web service private and configure proxy trust

If Traefik is intended to be the public ingress, do not publish Forgejo’s web port so it is directly reachable from untrusted networks. Keep the web listener on the proxy’s Docker network, or restrict host access with firewall rules. Otherwise, users may bypass Traefik and Forgejo may receive requests from sources you did not intend to trust.

Set Forgejo’s trusted proxy ranges to the addresses or subnet from which Traefik actually connects. Do not trust proxy headers from arbitrary client addresses. Forgejo’s current reverse-proxy documentation lists loopback addresses as the default trusted ranges and describes configuring trusted ranges and proxy depth; choose values that reflect your network rather than copying a generic wildcard.

Check the configuration for the exact Forgejo version deployed. In its v15 Docker documentation, Forgejo specifically warned that security.REVERSE_PROXY_TRUSTED_PROXIES defaulted to *, and advised limiting direct web-port access and setting an explicit value other than *. That page says the default changed in v16.0.0, while the v15 LTS line retained the earlier behavior as a breaking change. This is a version-specific warning, not a safe assumption about all releases. See the Forgejo v15 Docker documentation alongside the current reverse-proxy guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Forgejo also offers optional reverse-proxy authentication, but it is not required for ordinary proxying. Its documentation notes that this feature does not support the API; API access still requires token or basic authentication.

Rank #4
Dell OptiPlex 7050 Micro Computer, Intel Quad Core i5-6500T up to 3.1GHz, 16G DDR4, 256G SSD, Windows 11 Pro 64 Bit (Renewed)
  • This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high-performance bar may offer Certified Refurbished products on Amazon.com.
  • Dell OptiPlex 7050 Micro Computer, Intel Quad Core i5-6500T up to 3.1GHz, 16G DDR4, 256G SSD.
  • Includes: USB Keyboard & Mouse, Microsoft office 30 days free trail.
  • Ports: 1 x RJ-45, 1 x HDMI, 1 x DP, 6 x USB 3.0.
  • 4K Support: Support 4K (3840x2160) Dual display, makes it easy to connect two monitors at the same time, and you can expand working Windows, mirror content, or expand a single window across multiple monitors.

Make SSH cloning work as a separate route

Forgejo’s documented Docker example maps container port 22 to host port 222. That is one possible mapping, not a requirement. You can use a different host port, but SSH clients need a route to it, and Forgejo must advertise the same public SSH host and port in clone URLs.

For example, if clients connect to git.example.com on host port 222, that port must be forwarded to Forgejo’s container port 22, and Forgejo’s advertised SSH port must reflect 222. If you expose SSH on the standard port 22 instead, configure the host mapping and advertised URL accordingly. Traefik’s HTTP router does not automatically carry SSH traffic: decide whether to publish the SSH port directly, forward it at the network edge, or configure a separate TCP routing path in Traefik.

After configuring SSH, check a repository’s clone menu and test using the exact SSH URL it displays. A mismatch between the advertised port and the actual path commonly produces connection failures even when the web interface works.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a release and plan upgrades

Forgejo documents a stable release every three months and an LTS release every year. The stable line suits deployments that can follow a more frequent release cadence; LTS is the annually published long-term-support line. The documentation does not establish that either line is universally better for every operator.

Forgejo says moving from one major version to the next requires a manual operation and human verification. Before upgrading, review the release-specific notes and make a backup of the data and configuration you need to recover. A persistent /data volume supports continuity across container restarts, but by itself is not a verified backup-and-restore plan. See Forgejo’s installation and release documentation.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.