Files
jonas@geiger-natur.de 9dd908d31c External Access
2024-11-23 20:28:29 +01:00

3.7 KiB

Vaultwarden

Why Vaultwarden?

Vaultwarden is an alternative implementation of the Bitwarden server API written in Rust and compatible with Bitwarden clients. It has the base features of Bitwarden and also some free features that you have to pay for on Bitwarden. For example 2-factor-authentification (TOTP).

Prerequisites

Installation Guide

For the installation i use a docker-compose file. To run it go to Portainer Stacks. You have to modify the comment variables before execution.

version: "3.9"
services:
  vaultwarden:
    image: vaultwarden/server:latest
    container_name: Vaultwarden
    restart: unless-stopped
    ports:
      - #3012:3012
      - #80:80
    volumes:
      - #/volume1/docker/vaultwarden/data:/data:rw
    environment:
      PUID: #1027
      PGID: #65555
      ROCKET_PROFILE: release
      ROCKET_PORT: 80
      ROCKET_ADDRESS: 0.0.0.0
      ROCKET_ENV: staging
      RODCKET_WORKERS: 10
      DEBIAN_FRONTEND: noninteractive
      SIGNUPS_ALLOWED: true
      WEBSOCKET_ENABLED: true
    networks:
      default:
        ipv4_address: 192.168.xxx.xxx

networks:
  default:
    name: #macvlan
    external: true

After successful execution of the docker-compose file you have to create a new account.

Create a new Account

To create a new account you have to call your defined ipv4_address via web-browser (for example: 192.168.1.123:35554).

Caution

Don't forget to Disable SIGNUPS_ALLOWED. If you don't do this, anyone who reaches the login-page can create an account.

Disable SIGNUPS_ALLOWED

Stop the container and change the SIGNUPS_ALLOWED to false in the container settings.

External Access (Synology-DSM)

This describes how to access the container externally with a Dynamic DNS and a Reverse Proxy. You have to modify some values like Hostname and Port.

DDNS

  • First Open the Control Panel
  • Select "External Access" and Tab "DDNS"

Reverse Proxy

  • First Open the Control Panel
  • Select "Login Portal" and Tab "Advanced"
  • Click on Button "Reverse Proxy" and "Create"

General

Source
Property Input/Selection
Protocol HTTPS
Hostname example.synology.me
Port 35555
Enable HSTS checked
Access control profile Not configured
Destination
Property Input/Selection
Protocol HTTP
Hostname 192.168.xxx.xxx
Port 80

Custom Header

Header Name Value
Upgrade $http_upgrade
Connection $connection_upgrade
X-Real-IP $remote_addr
X-Forwarded-For $proxy_add_x_forwarded_for
Host $host
X-Forwarded-Proto $scheme

Advanced Settings

Property Input/Selection
Proxy connection timeout 60
Proxy send timeout 60
Proxy read timeout 60
Proxy HTTP version HTTP 1.1
Use the error page
sent back by target server
checked