Vaultwarden is a lightweight, self-hosted password manager that works with the official Bitwarden apps and browser extensions. You get a full password manager for yourself, your family or your team, with your vault stored on your own VPS instead of someone else's cloud.

This guide runs Vaultwarden in Docker, with Caddy in front of it to provide a free HTTPS certificate automatically. HTTPS is required, because the Bitwarden apps won't connect without it. The guide works on every operating system we offer: Ubuntu 22.04, 24.04 and 26.04, Debian 12 and 13, AlmaLinux 8, 9 and 10, and Rocky Linux 9 and 10.

Please note: Vaultwarden is an independent project and isn't affiliated with Bitwarden, Inc. Because your passwords will live on your VPS, keeping the server secure, updated and backed up is especially important.

Before you start

  • Docker must be installed. If it isn't, follow our guide: Install Docker Engine and Docker Compose on your VPS.
  • Any VPS size will do. Vaultwarden uses very little memory.
  • A domain or subdomain with an A record pointing to your VPS IP address, for example vault.example.co.nz.
  • Nothing else using ports 80 or 443 on the server. If you already use Nginx Proxy Manager, see the note at the end.
  • SSH access as root or as a user with sudo rights. If you're logged in as root, you can leave sudo off the commands.

Step 1: Open the firewall

Ubuntu/Debian with UFW enabled:

sudo ufw allow 80/tcp
sudo ufw allow 443

AlmaLinux/Rocky with firewalld:

sudo firewall-cmd --permanent --add-service=http --add-service=https --add-port=443/udp
sudo firewall-cmd --reload

Step 2: Create the configuration files

sudo mkdir -p /opt/vaultwarden
cd /opt/vaultwarden
sudo nano .env

Paste in the following, replacing the domain with your own. Leave sign-ups set to true for now, so you can create your account.

DOMAIN=vault.example.co.nz
SIGNUPS_ALLOWED=true

Press Ctrl+O and Enter to save, then Ctrl+X to exit. Next, create the Docker Compose file:

sudo nano compose.yaml

Paste in the following. You don't need to change anything in this file.

services:
  vaultwarden:
    image: vaultwarden/server:latest
    container_name: vaultwarden
    restart: unless-stopped
    environment:
      DOMAIN: "https://${DOMAIN}"
      SIGNUPS_ALLOWED: "${SIGNUPS_ALLOWED}"
    volumes:
      - ./vw-data:/data

  caddy:
    image: caddy:2
    container_name: caddy
    restart: unless-stopped
    environment:
      DOMAIN: "${DOMAIN}"
    ports:
      - "80:80"
      - "443:443"
      - "443:443/udp"
    volumes:
      - ./Caddyfile:/etc/caddy/Caddyfile:ro
      - ./caddy-data:/data
      - ./caddy-config:/config

Save and exit. Finally, create the Caddy configuration:

sudo nano Caddyfile

Paste in the following exactly as shown. Caddy reads your domain from the .env file.

{$DOMAIN} {
    encode zstd gzip
    reverse_proxy vaultwarden:80 {
        header_up X-Real-IP {remote_host}
    }
}

Save and exit.

Step 3: Start Vaultwarden

sudo docker compose up -d

Caddy gets an SSL certificate for your domain automatically. This usually takes under a minute.

Step 4: Create your account

  1. Open https://vault.example.co.nz in your browser.
  2. Click Create account, and enter your email address, name and a strong master password.
  3. Create accounts for anyone else who needs one now, such as family members or colleagues.

Your master password can't be recovered. If you forget it, your vault can't be opened. Choose something memorable and store a copy somewhere safe offline.

Step 5: Turn off public sign-ups

Once your accounts are created, stop anyone else from signing up. Edit the .env file:

cd /opt/vaultwarden
sudo nano .env

Change SIGNUPS_ALLOWED=true to SIGNUPS_ALLOWED=false, save, and apply the change:

sudo docker compose up -d

To add someone later, set it back to true briefly, or invite them through an organisation in the web vault.

Step 6: Connect the Bitwarden apps

Install the Bitwarden app or browser extension from bitwarden.com/download. On the login screen:

  1. Look for the Logging in on or Region option and choose Self-hosted.
  2. Enter your server URL, for example https://vault.example.co.nz, and save.
  3. Log in with your email address and master password.

We also recommend turning on two-step login in the web vault, under Settings → Security → Two-step login.

Back up your vault

Everything is stored in /opt/vaultwarden/vw-data. Back it up regularly, and keep copies off the server:

cd /opt/vaultwarden
sudo docker compose stop vaultwarden
sudo tar czf /root/vaultwarden-backup-$(date +%F).tar.gz vw-data
sudo docker compose start vaultwarden

You can also export your vault as an encrypted file from the web vault, under Tools → Export vault.

Keeping it up to date

Updates often include security fixes, so update regularly:

cd /opt/vaultwarden
sudo docker compose pull
sudo docker compose up -d

Already using Nginx Proxy Manager?

Leave out the caddy service and the Caddyfile, add Vaultwarden to your proxy network, and create a proxy host pointing to vaultwarden on port 80 with an SSL certificate and Websockets Support turned on.

Troubleshooting

  • The site won't load over HTTPS: check the Caddy logs with sudo docker logs caddy. The usual cause is DNS that doesn't point to this VPS yet, or ports 80 and 443 being blocked.
  • The app says it can't connect: check you chose Self-hosted and entered the full URL starting with https://.
  • Sign-ups are still allowed after Step 5: run sudo docker compose up -d again in /opt/vaultwarden so the container picks up the new setting.

Need help?

Our Cloud VPS plans are self-managed, so you're responsible for installing, securing and maintaining the software on your server. If something on our side isn't working, such as the network, or your VPS won't boot, open a support ticket. New to your VPS? Start with our Cloud VPS Getting Started Guide.

Was this answer helpful? 0 Users Found This Useful (0 Votes)