I'm in the opposite camp, especially when this separate system is as simple as Drone CI or Woodpecker CI (I mostly use the former, but the latter is more permissive, license wise). I came to holding this view after I ran into some issues by using a self-hosted GitLab Omnibus install previously: https://blog.kronis.dev/articles/goodbye-gitlab-hello-gitea-...
Using separate systems for working with the code, doing CI/CD and storing artifacts made each of the parts easier to update, limit the resources available to each, as well as limited the fallout when something does go wrong - say, still being able to interact with the codebase, even if the container repo is temporarily unavailable, or vice versa.
That said, in a few years I might come around to holding the opposite views again - frankly, both approaches are good and seeing the Gitea Actions project is nice! Though I'll also acknowledge that some might claim that all-in-one solutions are sometimes a bit half-baked, a criticism that I've heard of GitLab in the past (though honestly they're also fine, especially for the more enterprise settings, where you have beefier servers and a few people to manage the install).
This situation is actually a bit more insidious. All these CI/CD features are just a thinly veiled attempt at locking users into the platform. There's not big money to be made selling git hosting, but if you control how the software is built, then you have made yourself a hard dependency. If you look at the starter workflows they provide, they encourage bad practices where your application build is defined in their DSL. Experienced programmers might steer away from such usage, but many novice won't. If you have enough novice adoption, it becomes the norm. So many projects these days cannot even be built locally without a CI service dependency, where instead 99% of the time, all you needed was a simple makefile.
Disclaimer: I am a part of the Gitea project, the TOC, and am employed to work on Gitea
This is perfect for my needs. Thank you to the Gitea folks for getting this added/integrated!
Alternatively, I was wondering if it supported podman. I prefer podman in most cases since it runs without root and doesn't mess with my host's nftables. Docker always invokes iptables and adds a bunch of chains/rules. Grrr...