Bitflake logo

Self-host Vaultwarden with Docker Compose

Lightweight self-hosted password manager compatible with Bitwarden clients.

The steps below take a few minutes end to end.

  1. Docker compose setup and file
    save the generated compose and env files.
  2. Start Vaultwarden with Docker Compose
    bring the stack up and check it's healthy.

Requirements

You'll need these installed on the machine you're deploying to:

Docker

Packages Vaultwarden and everything it depends on into an isolated container, so it runs the same way on your machine as it does everywhere else.

Install guide

Docker Compose

Reads docker-compose.ymland starts everything in it together. Ships with Docker Desktop. On Linux servers it's usually a separate install.

Install guide

1. Docker compose setup and file

Create a folder for Vaultwarden and save the file below into it as docker-compose.yml. It describes every container the stack needs — Vaultwardenitself and any supporting services, such as its database — along with the ports, volumes and environment variables each one uses. You'll also need an empty .env file in the same folder; Docker Compose reads it automatically and uses it to fill in the ${VARIABLE}references you'll see in the file below.

docker-compose.yml

version: "3.9"
services:
  vaultwarden:
    image: vaultwarden/server:latest
    restart: unless-stopped
    ports:
      - 80:80
    environment:
      DOMAIN: http://localhost
      SIGNUPS_ALLOWED: "true"
    volumes:
      - data:/data
    healthcheck:
      test:
        - CMD
        - curl
        - -f
        - http://localhost:80/
      interval: 10s
      timeout: 5s
      retries: 5
volumes:
  data: null

Volumes

Vaultwarden stores its data in named Docker volumes, so it survives container restarts and updates:

  • data mounted at /data

2. Start Vaultwarden with Docker Compose

From the folder with docker-compose.yml and .env, run:

Terminal

Start Vaultwarden and all its supporting services in the background.

docker compose up -d

The -d flag runs the stack in the background so it keeps running after you close the terminal. Docker will pull the images the first time, which can take a minute or two.

To check on it afterwards: docker compose ps shows whether containers are healthy, and docker compose logs -f follows their logs if something looks wrong. Once it's running, open http://localhost:80 in your browser.