Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (1.37.3, 2026-09-18), podman (1.37.3, 2026-09-14); Proxmox VM: docker (1.37.3, 2026-09-14), podman (1.37.3, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
vaultwarden:
image: vaultwarden/server:latest
container_name: vaultwarden
restart: unless-stopped
volumes:
- './data/vaultwarden:/data'
ports:
- '8088:80'
environment:
- ADMIN_TOKEN_HASH={{ DOTENV.VAULTWARDEN_ADMIN_TOKEN }}
- SIGNUPS_ALLOWED=true
- WEB_VAULT_ENABLED=true
networks:
- njorddeploy_net
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
SIGNUPS_ALLOWED |
true |
Set to 'true' to allow new users to register, or 'false' to disable registration. |
WEB_VAULT_ENABLED |
true |
Set to 'true' to enable the web-based vault interface. |
VAULTWARDEN_WEB_PORT |
8088 |
The external TCP port for the Vaultwarden web interface. |
VAULTWARDEN_ADMIN_TOKEN |
{{ DOTENV.VAULTWARDEN_ADMIN_TOKEN }} |
Secure hashed token for the admin panel. Generate one via docker exec -it vaultwarden ./vaultwarden hash. For maximum security, leave this blank in your .env file to disable the admin panel entirely. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.