Vaultwarden

Vaultwarden

Collaboration · Network & Security · Version 1.37.3 · Debian 13

Your Seed is up within seconds and sets up Vaultwarden on its first boot. A few minutes later the app is ready to use.

With Vaultwarden, you run the password manager for yourself and your team on a Seed of your own. You use the official Bitwarden apps for browser, phone and desktop and add your Seed there as a self-hosted server. Your devices encrypt passwords, passkeys, TOTP codes and secure notes before they reach the Seed. Organizations let you share logins with colleagues through collections, and Send delivers text or files as a link with an expiry date. File attachments, emergency access and two-factor login with an authenticator app or security key are available to every account. Vaultwarden comes without license fees, and its source code is open.

After the first boot

On the Seed, Vaultwarden and Caddy run as Docker containers, with Caddy accepting HTTPS connections and passing them on to Vaultwarden. From creating the Seed to a ready vault usually takes 1 to 3 minutes. As a last step, the installation signs in with the admin token and writes the address of your vault to /root/ready.txt, which you can read over SSH or in the VNC console. If a step fails, you will find failed.txt there instead with the reason, and /root/vaultwarden-install.log shows the full run. If neither file is there yet, the installation has not finished.

You create your user account yourself. Open the address from ready.txt, choose Create account and set a master password. Your device derives the key for your vault from it, the Seed never sees it, and that is why nobody can reset it. Until you close registration, anyone who knows the address can create an account. So right afterwards, sign in at /admin with the admin token from /root/vaultwarden-credentials.txt and turn off Allow new signups under General settings.

To add more people, use Invite User under Users in the admin area. Without a mail server they get no invitation email, but they can register with the invited address through Create account. For invitations, master password hints and sign-in codes by email, enter your mail server's details under SMTP Email Settings and check them with a test email.

In the Bitwarden apps for browser, phone and desktop, switch the server to self-hosted on the sign-in screen and enter your vault's address. Everyone on your team stores this address in their apps, so we recommend using your own domain from the start. Once your domain's A record points to the Seed's IPv4 address, switch Vaultwarden over with seed-tls domain vault.example.com via SSH. Your vault gets a Let's Encrypt certificate in the process, and the previous address redirects to the domain.

In /opt/vaultwarden, compose.yaml defines the containers vaultwarden and caddy, and .env holds the images with their versions, the address of your vault and, under VAULTWARDEN_ADMIN_TOKEN, the hash of the admin token. Vaultwarden stores settings from the admin area in config.json, and they take precedence over .env. The database with all encrypted vaults, the file attachments and config.json live in the Docker volume vaultwarden_vw_data, so include that volume in your backups. sqlite3 is already installed for consistent backups of the running SQLite database.

To update, replace the entire value of VAULTWARDEN_IMAGE in .env, including the @sha256 part, with the new version, for example docker.io/vaultwarden/server:1.38.0, then run docker compose pull and docker compose up -d in /opt/vaultwarden. CADDY_IMAGE updates Caddy in the same way, and apt update && apt upgrade takes care of Docker itself. Read the Vaultwarden release notes first and take a snapshot of the Seed. Both containers start automatically when the Seed reboots.

Our guide Set up Vaultwarden as your password manager shows how to import passwords from your previous password manager, set up daily backups with a cron job and restrict access to a VPN. The installation is already done on this Seed, so start at the section “Admin panel”. The directory and volume have the same names as in the guide.

Suitable models

Entry

The entry point for low CPU load


Shared vCPUs
Xeon Gold class CPU
DDR4 ECC RAM
For low CPU load
3-way replication via Ceph
10 TB traffic included
Up to 1 Gbit/s connectivity

from
7,29 €
/ Month
from
0,011694 €
/ Hour
Recommended

Standard

All-rounder for variable production load


Shared vCPUs
AMD EPYC 9655 (Turin)
DDR5 ECC RAM
For variable production load
3-way replication via Ceph
20 TB traffic included
Up to 2.5 Gbit/s connectivity

from
8,93 €
/ Month
from
0,014303 €
/ Hour

Performance

Exclusive compute for sustained load


Dedicated vCPUs
AMD EPYC 9575F (Turin)
DDR5 ECC RAM
For sustained load
3-way replication via Ceph
20 TB traffic included
Up to 10 Gbit/s connectivity

from
44,03 €
/ Month
from
0,070561 €
/ Hour

All prices incl. 19% VAT

Show all 15 suitable models

Entry

ModelCPU RAM StorageTraffic BandwidthPrice/hourPrice/month
S1 Core2 GB20 GB10 TB1 Gbit/s
0,005848 €
3,65 €
M2 Cores4 GB40 GB10 TB1 Gbit/s
0,011694 €
7,29 €
L4 Cores8 GB80 GB10 TB1 Gbit/s
0,023389 €
14,59 €
XL8 Cores16 GB160 GB10 TB1 Gbit/s
0,038312 €
23,91 €

Standard

ModelCPU RAM StorageTraffic BandwidthPrice/hourPrice/month
XS1 Core4 GB40 GB20 TB2.5 Gbit/s
0,014303 €
8,93 €
S2 Cores8 GB80 GB20 TB2.5 Gbit/s
0,024579 €
15,34 €
M4 Cores16 GB160 GB20 TB2.5 Gbit/s
0,049158 €
30,68 €
L8 Cores24 GB240 GB20 TB2.5 Gbit/s
0,093740 €
58,49 €
XL10 Cores32 GB360 GB20 TB2.5 Gbit/s
0,120608 €
75,26 €
XXL16 Cores64 GB500 GB20 TB2.5 Gbit/s
0,188623 €
117,70 €

Performance

ModelCPU RAM StorageTraffic BandwidthPrice/hourPrice/month
S2 Cores16 GB80 GB20 TB10 Gbit/s
0,070561 €
44,03 €
M4 Cores32 GB160 GB20 TB10 Gbit/s
0,141122 €
88,06 €
L8 Cores64 GB240 GB20 TB10 Gbit/s
0,277666 €
173,26 €
XL16 Cores128 GB360 GB20 TB10 Gbit/s
0,548467 €
342,24 €
XXL32 Cores192 GB500 GB20 TB10 Gbit/s
1,011118 €
630,94 €

Create it via the Public API

A single call creates this Seed. Replace the placeholders starting with $ with your own values, such as your API token and the IDs from your account. Go to the Public API

bash
curl -X POST "https://api.dataforest.net/api/v1/public/seeds" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "plan": "lines/standard/models/std1-xs",
  "location": "fra01",
  "source": {
    "type": "app",
    "ref": "apps/vaultwarden/versions/vaultwarden-v1.37.3"
  },
  "project_id": "$PROJECT_ID",
  "name": "vaultwarden"
}'

Our cloud newsletter

Stay up to date and get valuable tips by subscribing to our newsletter.

Any questions?

Our experts are happy to help. You'll be surprised how fast we are.

Background image