With Vaultwarden, you run the password manager for yourself and your team on a Seed of your own. You use the official Bitwarden apps for browser, phone and desktop and add your Seed there as a self-hosted server. Your devices encrypt passwords, passkeys, TOTP codes and secure notes before they reach the Seed. Organizations let you share logins with colleagues through collections, and Send delivers text or files as a link with an expiry date. File attachments, emergency access and two-factor login with an authenticator app or security key are available to every account. Vaultwarden comes without license fees, and its source code is open.
After the first boot
On the Seed, Vaultwarden and Caddy run as Docker containers, with Caddy accepting HTTPS connections and passing them on to Vaultwarden. From creating the Seed to a ready vault usually takes 1 to 3 minutes. As a last step, the installation signs in with the admin token and writes the address of your vault to /root/ready.txt, which you can read over SSH or in the VNC console. If a step fails, you will find failed.txt there instead with the reason, and /root/vaultwarden-install.log shows the full run. If neither file is there yet, the installation has not finished.
You create your user account yourself. Open the address from ready.txt, choose Create account and set a master password. Your device derives the key for your vault from it, the Seed never sees it, and that is why nobody can reset it. Until you close registration, anyone who knows the address can create an account. So right afterwards, sign in at /admin with the admin token from /root/vaultwarden-credentials.txt and turn off Allow new signups under General settings.
To add more people, use Invite User under Users in the admin area. Without a mail server they get no invitation email, but they can register with the invited address through Create account. For invitations, master password hints and sign-in codes by email, enter your mail server's details under SMTP Email Settings and check them with a test email.
In the Bitwarden apps for browser, phone and desktop, switch the server to self-hosted on the sign-in screen and enter your vault's address. Everyone on your team stores this address in their apps, so we recommend using your own domain from the start. Once your domain's A record points to the Seed's IPv4 address, switch Vaultwarden over with seed-tls domain vault.example.com via SSH. Your vault gets a Let's Encrypt certificate in the process, and the previous address redirects to the domain.
In /opt/vaultwarden, compose.yaml defines the containers vaultwarden and caddy, and .env holds the images with their versions, the address of your vault and, under VAULTWARDEN_ADMIN_TOKEN, the hash of the admin token. Vaultwarden stores settings from the admin area in config.json, and they take precedence over .env. The database with all encrypted vaults, the file attachments and config.json live in the Docker volume vaultwarden_vw_data, so include that volume in your backups. sqlite3 is already installed for consistent backups of the running SQLite database.
To update, replace the entire value of VAULTWARDEN_IMAGE in .env, including the @sha256 part, with the new version, for example docker.io/vaultwarden/server:1.38.0, then run docker compose pull and docker compose up -d in /opt/vaultwarden. CADDY_IMAGE updates Caddy in the same way, and apt update && apt upgrade takes care of Docker itself. Read the Vaultwarden release notes first and take a snapshot of the Seed. Both containers start automatically when the Seed reboots.
Our guide Set up Vaultwarden as your password manager shows how to import passwords from your previous password manager, set up daily backups with a cron job and restrict access to a VPN. The installation is already done on this Seed, so start at the section “Admin panel”. The directory and volume have the same names as in the guide.
Suitable models
Entry
The entry point for low CPU load
Standard
All-rounder for variable production load
Performance
Exclusive compute for sustained load
Show all 15 suitable models
Entry
| Model | CPU | RAM | Storage | Traffic | Bandwidth | Price/hour | Price/month | |
|---|---|---|---|---|---|---|---|---|
| S | 1 Core | 2 GB | 20 GB | 10 TB | 1 Gbit/s | 0,005848 € | 3,65 € | |
| M | 2 Cores | 4 GB | 40 GB | 10 TB | 1 Gbit/s | 0,011694 € | 7,29 € | |
| L | 4 Cores | 8 GB | 80 GB | 10 TB | 1 Gbit/s | 0,023389 € | 14,59 € | |
| XL | 8 Cores | 16 GB | 160 GB | 10 TB | 1 Gbit/s | 0,038312 € | 23,91 € |
Standard
| Model | CPU | RAM | Storage | Traffic | Bandwidth | Price/hour | Price/month | |
|---|---|---|---|---|---|---|---|---|
| XS | 1 Core | 4 GB | 40 GB | 20 TB | 2.5 Gbit/s | 0,014303 € | 8,93 € | |
| S | 2 Cores | 8 GB | 80 GB | 20 TB | 2.5 Gbit/s | 0,024579 € | 15,34 € | |
| M | 4 Cores | 16 GB | 160 GB | 20 TB | 2.5 Gbit/s | 0,049158 € | 30,68 € | |
| L | 8 Cores | 24 GB | 240 GB | 20 TB | 2.5 Gbit/s | 0,093740 € | 58,49 € | |
| XL | 10 Cores | 32 GB | 360 GB | 20 TB | 2.5 Gbit/s | 0,120608 € | 75,26 € | |
| XXL | 16 Cores | 64 GB | 500 GB | 20 TB | 2.5 Gbit/s | 0,188623 € | 117,70 € |
Performance
| Model | CPU | RAM | Storage | Traffic | Bandwidth | Price/hour | Price/month | |
|---|---|---|---|---|---|---|---|---|
| S | 2 Cores | 16 GB | 80 GB | 20 TB | 10 Gbit/s | 0,070561 € | 44,03 € | |
| M | 4 Cores | 32 GB | 160 GB | 20 TB | 10 Gbit/s | 0,141122 € | 88,06 € | |
| L | 8 Cores | 64 GB | 240 GB | 20 TB | 10 Gbit/s | 0,277666 € | 173,26 € | |
| XL | 16 Cores | 128 GB | 360 GB | 20 TB | 10 Gbit/s | 0,548467 € | 342,24 € | |
| XXL | 32 Cores | 192 GB | 500 GB | 20 TB | 10 Gbit/s | 1,011118 € | 630,94 € |
Create it via the Public API
A single call creates this Seed. Replace the placeholders starting with $ with your own values, such as your API token and the IDs from your account. Go to the Public API
curl -X POST "https://api.dataforest.net/api/v1/public/seeds" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"plan": "lines/standard/models/std1-xs",
"location": "fra01",
"source": {
"type": "app",
"ref": "apps/vaultwarden/versions/vaultwarden-v1.37.3"
},
"project_id": "$PROJECT_ID",
"name": "vaultwarden"
}'