Short version: the cheapest OSINT infra that actually survives an incident is git push + cron. Long version, with the numbers.
I run Telegram channel collection on GitHub Actions free tier: a scheduled workflow (every 30 minutes, 20 public channels per run, ~0.4 build minutes per run) does fetch → normalize → diff → commit. The output of the pipeline is literally a git history of normalized snapshots. That single design choice buys you four things that a "real" server pipeline has to engineer in by hand.
1. The archive is versioned for free. Every collection run commits. git log --stat is your ingestion audit trail: when a channel went quiet, when the parser changed, when a source dropped out. Incident reconstruction = git log -p -- <channel>.jsonl. On a server, you build this; on Actions, you get it.
2. Diffing is a first-class operation. The alert rule for advisory wording changes is a git diff between yesterday's and today's normalized text with a fuzzy-match threshold. The tool is not a proxy for the problem; it is the problem, expressed in the right representation.
3. Failure is public and boring. A failed workflow shows up as a red X and (configurable) an email. No log rotation, no box to SSH into at 3am, no daemon to supervise. The entire ops surface of the pipeline is one YAML file. For a one-person OSINT shop, the budget that a server eats is the budget research doesn't get.
4. Reproducibility is the deliverable. When a client questions a claim, the answer is a commit hash. The collection rule, the corpus, and the analysis are the same artifact. Analysts who work this way can defend their findings line-by-line; analysts with scrapers into databases can't, and everyone in the field knows which is which.
The real limit: Actions free tier is ~2,000 build-minutes/month, and public repos are unlimited. A 30-minute cadence over 20 channels costs under 5% of that. Scale to a few hundred channels at hourly cadence and you're at 50%. The design degrades gracefully: cadence first, channels never.
The workflow YAML patterns, the normalization + dedup rules, and the diff-alert logic are in my Telegram & Web OSINT Bundle ($5). Free sample brief: here.
No server, no paid APIs - and the pipeline has outlived every VPS I've had to pay off.
Top comments (2)
Zero‑server OSINT setup: GitHub Actions cron + Git history store Telegram‑channel snapshots; delivers audit trails, diff‑alerts and reproducible outputs; watch GitHub Actions free‑minute quota for scaling.
Some comments may only be visible to logged-in visitors. Sign in to view all comments.