How to self-host Vaultwarden
Keep every password in one encrypted vault that the Bitwarden apps on your phone and browser plug straight into. Cresdock runs it on a server you own, from a catalogue, with no Docker and no reverse proxy to configure.
What Cresdock does for you with Vaultwarden
Its configuration is written before the container ever starts — including the web address it lives at, so Vaultwarden generates correct links from the first page load instead of half-working behind a prefix.
Reached through your panel login. There is no second password to invent for Vaultwarden and no port to open on your firewall.
Why run Vaultwarden yourself
Small tools are where a subscription is hardest to justify: a few pounds a month, times a dozen tools, for software that would run happily on a server you already pay for.
It is also how you retire a password manager subscription — the Bitwarden apps connect to it — one line in replacing cloud subscriptions, app by app.
What kind of server Vaultwarden needs
Small. These are the sort of app people run on a server they already have, alongside everything else, without thinking about capacity.
Cresdock itself is undemanding — it runs on a small rented server, an old desktop or a mini PC, on Ubuntu or Debian. Everything it installs shares that machine, so the honest question is not "will this app run" but "how much am I going to put on here in total".
Where to run Vaultwarden
Vaultwarden runs wherever Cresdock runs, and the choice is about the machine, not the app:
- At home, on hardware you already own. A mini PC, an old desktop or a NAS that can run Debian. Cresdock works behind a home router with no port forwarding and no domain, so Vaultwarden is reachable on your own network first and from outside only if you choose.
- On a rented server. A small VPS is enough for most apps and is the usual answer when Vaultwarden should be reachable from anywhere. The setup guide covers the specs and the one-command install.
- Through a provider that runs Cresdock. Hosting companies deploy Cresdock workspaces for their customers, so Vaultwarden can come with a server you rent rather than one you set up — ask your provider, or see how providers offer it.
Installing Vaultwarden
- Put Cresdock on a server
One line on any Ubuntu or Debian machine — a rented VPS, a spare PC, a home server. It sets itself up.
- Pick Vaultwarden from the catalogue
Click Install. The panel pulls the image, writes the configuration, gets a certificate and starts it.
- Open it from your dashboard
Its address and any login details are on its card. Start, stop, update, roll back or remove it from the same place, any time.
What's left for you to do
Cresdock does not pretend to do the parts that are genuinely yours to decide. After it's running:
Open it and create your account. That account holds your vault
Install the Bitwarden app on your phone and point it at this address
What this replaces
Doing it by hand means writing something like this, then keeping it working:
services:
vaultwarden:
image: vaultwarden/server:1.37.1
restart: unless-stopped
ports:
- "80:80"
environment:
- PUID=1000
- PGID=1000
- TZ=Etc/UTC
volumes:
- ./vaultwarden/config:/config
And that is the easy half. Still to do:
Install a reverse proxy and write a server block for it
Get a TLS certificate and set up automatic renewal
Create the folders above with the right ownership, or it will not start
Repeat all of it for the next app, and again on every server rebuild
On Cresdock, Vaultwarden is one click and none of the above exists.
Common questions
Do I need to know Docker to run Vaultwarden?
No. Cresdock installs Vaultwarden in one click from its catalogue: it pulls the image, writes the configuration, gets an HTTPS certificate and starts it. Vaultwarden's configuration is written before it first starts, so it opens already set up.
What happens to my Vaultwarden data when it updates?
Cresdock updates the Vaultwarden image and leaves its stored data in place. Vaultwarden keeps its own files in its own folder, which survives an update, a rebuild and a reinstall — and Cresdock never writes into it.
Can I run Vaultwarden at home instead of on a VPS?
Yes. Cresdock runs on a mini PC, an old desktop or anything that boots Debian, behind a normal home router with no port forwarding, and Vaultwarden is reachable on your own network first. A rented server is only needed when Vaultwarden must be reachable from anywhere without a VPN.
Can I remove Vaultwarden later?
Yes. Cresdock removes Vaultwarden in one click, and asks whether to keep its configuration for a future reinstall. Nothing else you have installed is affected.
Looking for what Vaultwarden itself can do? That lives in its own documentation — this page is only about running it.
Pairs well with: Actual Budget · code-server · WireGuard
Before you start: where to rent a server · what it needs to run · Cresdock vs Cloudron