mrkeyoor.com_
Tue 29 Sept 04:05 UTC
Self-Hostedevaluationupdated 26 Aug 2026

harness review

Harness Open Source is a self-hosted developer platform that combines Git repository hosting, CI/CD pipelines, cloud development environments, and artifact registries. It is the next-generation project around Gitness and Drone ideas, aimed at teams that want one server for code and delivery work.

+35stars / 7d
Verdict

Our Harness run installed 799 packages, used 104 seconds for setup, and finished its 504-second test run with 87 of 88 passing, so this is a substantial platform with one unresolved measured failure. It is worth a controlled trial for teams that genuinely want source hosting, pipelines, Gitspaces, and registries together. Do not expose it broadly until the Docker-socket model and current Gitspace and authorization reports have been reviewed against the exact version you deploy.

We ran it

Lab card: what happened when we ran harnessScreenshot of harness (www.harness.io/open-source)
Install✓ · 104s799 packages
Build✓ · 4s
Tests✗ · 504s87 passed · 1 failed of 88 (go test)
Repo6183 files~604,580 lines of source · 26.9 MB · 1 CI workflows · Dockerfile · tests dir

Answers from our run

Does harness build from source?

Dependencies installed in 104 seconds (799 packages), and the build succeeded in 4 seconds. We cloned commit ad5c876 into a clean Debian container with 3 CPUs and no project-specific setup.

Do harness's tests pass?

Not all of them: 87 of 88 passed and 1 failed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use harness?

Operators unwilling to expose the Docker socket to the application: the documented pipeline setup mounts /var/run/docker.sock, which grants sensitive control over the host daemon.

What are the alternatives to harness?

Gitea, OneDev, GitLab Community Edition. Our Harness run installed 799 packages, used 104 seconds for setup, and finished its 504-second test run with 87 of 88 passing, so this is a substantial platform with one unresolved measured failure.

Setup3/5One-container trial, but source work and safe operation are demanding
Docs4/5Clear local paths, exact tools, Docker sockets, API, and conformance steps
Community4/5Recent pushes and active fixes across security and repository behavior
Maturity3/5Broad working platform with one test failure and open security reports

Discussed on

  1. hnImproving 15 LLMs at Coding in One Afternoon. Only the Harness Changed832 points
  2. hnDeepSeek Harness developer preview747 points
  3. hnWhat Is a Harness?589 points
  4. hnHarness engineering for self-improvement334 points
  5. hnHarness engineering: Leveraging Codex in an agent-first world297 points

Who it’s for

Teams seeking a self-hosted alternative that combines source control and pipelines.
Organizations that also need browser development environments and artifact registries.
Go and Node maintainers prepared to operate a large developer platform.
Existing Drone users willing to evaluate current pipeline coverage rather than assume parity.

Who it’s NOT for

Operators unwilling to expose the Docker socket to the application: the documented pipeline setup mounts /var/run/docker.sock, which grants sensitive control over the host daemon.
Security-sensitive teams that cannot evaluate open reports involving Gitspace SSRF, path traversal, authorization checks, and push-protection bypasses.
Small teams needing only Git hosting: the 6,183-file repository and 799-package install carry much more surface than a focused forge.
Drone users who require feature parity now: the README calls full parity a goal that will take time and keeps Drone on a separate branch.
Maintainers expecting a fully green generic test run: our suite ended with 87 passed and 1 failed.

Setup reality

Our sandbox installed 799 Go packages in 104 seconds at commit ad5c876. The build succeeded in 4 seconds. Tests ran for 504 seconds and failed overall: 87 passed and 1 failed out of 88. The supplied log tail showed passing packages followed by FAIL, without naming the failing assertion.

The easy trial is one Docker image, ports 3000 and 3022, persistent storage, and a mounted Docker socket. Source development also needs Node, Go, exact protobuf tooling, Yarn, and generated UI/API artifacts.

Pipelines depend on a reachable Docker daemon, with alternative socket configuration for Rancher Desktop or Colima. The documented test login uses admin and changeit; any real deployment needs immediate credential changes, protected networking, backups, and review of the open security reports.

Harness puts four developer services behind one server

Harness Open Source combines Git hosting, automated pipelines, browser development environments called Gitspaces, and artifact registries. The repository and binary still use the Gitness name in several places, while the product is presented as Harness Open Source. Its scope is closer to GitLab or OneDev than to a standalone CI runner. A web interface and REST API cover the platform, and a basic CLI handles development and server operations.

The integrated pitch is sensible for a team already operating separate code, CI, workspace, and registry services. One permission model and one backup boundary can be easier than four products. It also concentrates risk. A flaw in repository authorization or Gitspace networking sits next to source code, credentials, artifacts, and the Docker daemon that executes pipelines. Platform consolidation makes security review more important, not less.

The Docker trial is short and highly privileged

The README starts a published image on ports 3000 and 3022, stores data in a bind mount, and mounts /var/run/docker.sock. That is enough to open the web interface at localhost and execute container-based pipelines. The persistent volume is essential because stopping a container without one can remove repositories and database state.

Mounting the Docker socket gives the application powerful access to the host daemon. Treat the server as privileged infrastructure: isolate it, restrict who can define pipelines, and do not place untrusted projects beside sensitive workloads without a threat model. Rancher Desktop and Colima users can configure their alternative sockets through GITNESS_DOCKER_HOST; the application can negotiate a Docker API version or use an explicit version such as 1.45.

What happened when we ran it

Our sandbox tested commit ad5c876 in Go 1.24 on Debian. Installing dependencies took 104 seconds and added 799 packages. The build succeeded in 4 seconds. Tests ran for 504 seconds and failed overall: 87 passed and 1 failed out of 88.

The provided end of the test log listed passing packages such as store, stream, tests/load, types, and version, then printed only FAIL. It did not name the failing assertion in those last lines, so we cannot responsibly assign a cause. The result is one real failure in our environment and a reason to inspect the full suite before deployment, not evidence that a particular subsystem is broken.

The checkout contained 6,183 files, about 604,580 lines of source, and 26.9 MB. It had one CI workflow, a Dockerfile, and a tests directory. The 799-package dependency set and 504-second suite make source changes more expensive than the 4-second build suggests. Budget CI time for the tests and registry conformance checks rather than using compilation as the release gate.

Source development needs pinned generators and two toolchains

Building from source requires a current Node release, Go 1.20 or newer, protobuf 3.21.11, protoc-gen-go 1.28.1, and protoc-gen-go-grpc 1.2.0. Developers install and build the Yarn frontend before running make build. API changes also require regenerating Swagger and the TypeScript client used by the UI.

These exact generator versions reduce accidental diffs, but they make onboarding more involved than the single-container demo. The registry has separate conformance targets, and pipelines need a working Docker runtime. A contributor should reproduce the pinned toolchain in CI or a development image instead of relying on whatever Homebrew or Go happens to install that week.

The README's API example logs in with admin and changeit, then creates a personal access token valid for one year. That is test guidance, not a production credential policy. Change the initial password, shorten token lifetimes, bind the service to protected networks, and verify backups before importing real repositories.

Open security reports deserve version-specific review

Several open issues in 2026 concern meaningful boundaries. Issue 3695 describes blind SSRF in the Gitspace repository lookup endpoint through git ls-remote. Issue 3696 reports archive extraction writing outside the intended feature directory. Issue 3689 reports a missing authorization branch when listing Gitspaces. Issue 3697 covers authenticated reads of infrastructure-provider configuration without the expected space permission.

Repository protection also has an open report. Issue 3681 says plain API content writes can be treated as if push-protection bypass were requested. Fix pull requests exist for that report and the infrastructure-provider authorization issue, but an open fix is not the same as a released patch. Operators should map each report to the chosen image digest and confirm the relevant change has landed.

These reports do not prove every current deployment is exploitable, since versions and configuration matter. They are specific enough to affect a buying decision. Gitspaces accept repositories and development-container metadata, while pipelines reach Docker. A public instance with many untrusted users faces a different risk than a small internal server with controlled projects.

Drone parity is an aspiration, not current behavior

Harness describes itself as the next generation of Drone, adding source hosting, Gitspaces, and registries. The README says full pipeline parity with Drone is a goal and will take time. Drone continues on a snapshot branch so development can proceed separately. Existing Drone users should inventory required triggers, secrets, pipeline syntax, and plugins before considering migration.

Version 2.28.2 was released on 2026-04-20, and the repository was pushed on 2026-08-21. GitHub showed 106 open issues and pull requests combined, with active changes through August 25. That activity indicates maintenance, including security-related fixes, even though the latest release is several months older than the default branch.

Harness is most convincing when a team needs all four services and can operate them as privileged infrastructure. Gitea is easier to justify for a focused forge. GitLab CE offers a more established integrated platform at its own considerable cost. Run Harness in an isolated trial, reproduce the 88-part test result, inspect the chosen image against open security fixes, and migrate only the workflows that pass those checks.

Alternatives

ProjectWhat it isPick it when
Gitea gh↗A focused, lightweight self-hosted Git forge with issues, pull requests, and actions.pick this instead when code hosting is primary and you want a smaller operating surface.
OneDevA self-hosted DevOps server combining Git, CI/CD, packages, and project work.pick this instead when you want another integrated platform and its administration model fits better.
GitLab Community Edition gh↗A mature all-in-one forge with source control, CI/CD, packages, and planning tools.pick this instead when breadth, established operations, and a larger ecosystem outweigh deployment weight.

What people are saying

  1. [velocity-scout] browser-use/macos-harness
  2. [hackernews] Munder Difflin – Agent harness to run an office of your clones
  3. [github-trending] browser-use/browser-harness
  4. [techcrunch-ai] Nvidia just showed that the harness, not the AI model, is now the real hero
  5. [google-trends] deepseek harness github
  6. [hackernews] Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams

Sources

  1. Harness Open Source README
  2. Harness Open Source documentation
  3. Harness v2.28.2 release
  4. Harness issue 3695: Gitspace lookup SSRF
  5. Harness issue 3696: feature archive extraction
  6. Harness issue 3681: API write push protection

More self-hosted reviews

anythingmcp · Calibre-Web-Automated · CF-Server-Monitor · niubigeo · kuboard-press · taskview-community · the whole board →