Gitea stays where the project lives and push-mirrors every branch and tag to GitHub. With the Actions variable BUILD_ON set to 'github' on both forges, the GitHub copy does the building and reports back to Gitea as a commit status; unset, nothing changes and Gitea builds as before. .github/workflows/ci.yml replaces the GitHub-era files. Branch pushes run what Gitea's ci.yml checks (fork checks, dev build, test targets, the release profile on main). v* tags run what publish.yml does, with the same two guards: the image per architecture on native runners side by side, the multi-arch index and :latest, the Gitea Release if the tag has none, and the host-install binaries taken out of the image. A final job posts "github/ci (branch)" or "github/ci (tag)" to the commit on Gitea. On Gitea, the heavy jobs skip under BUILD_ON=github and a `github` job waits for that status and passes or fails with it, so pull requests and merges still look at a Gitea run. The weekly release, the upstream watch and the announcement stay on Gitea. Removed: cleanup.yml and publish.yml (GHCR), release.yml (a second weekly schedule), and dependabot.yml, whose pull request branches every mirror sync would delete.