Kituwa IT · Self-hosting guides

Install Vaultwarden with Docker Compose

Self-hosted Bitwarden-compatible password manager

passwords2FAsecrets

Vaultwarden is a lightweight, Rust reimplementation of the Bitwarden server. It speaks the same protocol, so the official Bitwarden browser extension, desktop app and mobile apps all connect to it unchanged — you get the polished clients with a server that runs in 20 MB of RAM.

Category
Security & access
License
AGPL-3.0
Needs
Nothing
Image
vaultwarden/server

What it is

Self-hosted password storage with end-to-end encryption, secure notes, card and identity records, TOTP generation, and file attachments. Optionally add a second factor with WebAuthn for hardware-key support. The trade versus Bitwarden cloud is simple: no subscription, and no one else can subpoena your vault.

Before you start

  • You need HTTPS. Vaultwarden will refuse to start without it unless you set ROCKET_TLS explicitly. There is no good reason to weaken this.
  • Decide the signup policy before you start. SIGNUPS_ALLOWED=false plus invitations is the sane default for a family or team.
  • Turn on admin via a strong ADMIN_TOKEN on day one, or you'll be locked out of settings later.

1 — Create the directory

Command / configuration
mkdir -p ~/services/vaultwarden/data
cd ~/services/vaultwarden
openssl rand -base64 48   # use for ADMIN_TOKEN

2 — Write the compose file

Command / configuration
services:
  vaultwarden:
    image: vaultwarden/server:latest
    container_name: vaultwarden
    restart: unless-stopped
    environment:
      DOMAIN: "https://vault.example.com"
      ROCKET_PORT: "80"
      ADMIN_TOKEN: "CHANGE_ME_48_random_bytes"
      SIGNUPS_ALLOWED: "false"
      INVITATIONS_ALLOWED: "true"
      SHOW_PASSWORD_HINT: "false"
      I_REALLY_WANT_VOLATILE_STORAGE: "false"
      SIGNING_KEY: /data/signing_key
      WEBSOCKET_ENABLED: "true"
      ORG_CREATION_ALLOWED: "false"
      LOG_LEVEL: warn
    volumes:
      - ./data:/data
    ports:
      - "127.0.0.1:8222:80"
    healthcheck:
      test: ["CMD", "curl", "-fs", "http://localhost/alive"]
      interval: 30s
      timeout: 5s
      retries: 3

3 — Start it

Command / configuration
docker compose up -d
curl -s http://127.0.0.1:8222/alive; echo

/alive returning true is the quickest confirmation the container is healthy.

4 — First-run setup

  1. Register the very first account yourself. After that, Admin Panel → Users → Invite is how everyone else gets in.
  2. Point the official Bitwarden clients at your URL. On the browser extension it's a self-hosted option on the login screen; on mobile it's under the server dropdown. Verify the URL reads https://vault.example.com and not the Bitwarden default.
  3. From Admin Panel → Settings, set the Signups and Show password hint toggles the way you want them regardless of the environment variables, and enable WebAuthn support.
  4. Do a real sync: create an item in the browser extension, pull to refresh on a second device, confirm it lands. That proves both directions of the sync channel.

5 — Never lose the vault

Command / configuration
sqlite3 ./data/db.sqlite3 ".backup '/backup/vaultwarden-$(date +%F).sqlite3'"
The admin token is a full password resetAnyone holding ADMIN_TOKEN can reset your master password. Generate it from openssl rand -base64 48, store it in a password manager, and never commit this compose file to a public repo. If the token ever leaks, rotate it and restart immediately.

Help when you need it

Want help getting this running?

We can help with a supported Linux host, application setup, migration or troubleshooting. Contact us to confirm the software, scope and scheduling before ordering.

Related guides

← Browse all 30 guides · Back to top