cresdock
Home Apps Deploy Pricing
Cresdock  /  Apps  /  Vaultwarden
Utilities

How to self-host Vaultwarden

Keep every password in one encrypted vault that the Bitwarden apps on your phone and browser plug straight into. Cresdock runs it on a server you own, from a catalogue, with no Docker and no reverse proxy to configure.

What Cresdock does for you with Vaultwarden

Why run Vaultwarden yourself

Small tools are where a subscription is hardest to justify: a few pounds a month, times a dozen tools, for software that would run happily on a server you already pay for.

It is also how you retire a password manager subscription — the Bitwarden apps connect to it — one line in replacing cloud subscriptions, app by app.

What kind of server Vaultwarden needs

Small. These are the sort of app people run on a server they already have, alongside everything else, without thinking about capacity.

Cresdock itself is undemanding — it runs on a small rented server, an old desktop or a mini PC, on Ubuntu or Debian. Everything it installs shares that machine, so the honest question is not "will this app run" but "how much am I going to put on here in total".

Where to run Vaultwarden

Vaultwarden runs wherever Cresdock runs, and the choice is about the machine, not the app:

Installing Vaultwarden

  1. Put Cresdock on a server

    One line on any Ubuntu or Debian machine — a rented VPS, a spare PC, a home server. It sets itself up.

  2. Pick Vaultwarden from the catalogue

    Click Install. The panel pulls the image, writes the configuration, gets a certificate and starts it.

  3. Open it from your dashboard

    Its address and any login details are on its card. Start, stop, update, roll back or remove it from the same place, any time.

What's left for you to do

Cresdock does not pretend to do the parts that are genuinely yours to decide. After it's running:

What this replaces

Doing it by hand means writing something like this, then keeping it working:

services:
  vaultwarden:
    image: vaultwarden/server:1.37.1
    restart: unless-stopped
    ports:
      - "80:80"
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
    volumes:
      - ./vaultwarden/config:/config

And that is the easy half. Still to do:

On Cresdock, Vaultwarden is one click and none of the above exists.

Common questions

Do I need to know Docker to run Vaultwarden?

No. Cresdock installs Vaultwarden in one click from its catalogue: it pulls the image, writes the configuration, gets an HTTPS certificate and starts it. Vaultwarden's configuration is written before it first starts, so it opens already set up.

What happens to my Vaultwarden data when it updates?

Cresdock updates the Vaultwarden image and leaves its stored data in place. Vaultwarden keeps its own files in its own folder, which survives an update, a rebuild and a reinstall — and Cresdock never writes into it.

Can I run Vaultwarden at home instead of on a VPS?

Yes. Cresdock runs on a mini PC, an old desktop or anything that boots Debian, behind a normal home router with no port forwarding, and Vaultwarden is reachable on your own network first. A rented server is only needed when Vaultwarden must be reachable from anywhere without a VPN.

Can I remove Vaultwarden later?

Yes. Cresdock removes Vaultwarden in one click, and asks whether to keep its configuration for a future reinstall. Nothing else you have installed is affected.

Looking for what Vaultwarden itself can do? That lives in its own documentation — this page is only about running it.

Pairs well with: Actual Budget  ·  code-server  ·  WireGuard

Before you start: where to rent a server  ·  what it needs to run  ·  Cresdock vs Cloudron