migrate
This commit is contained in:
@@ -0,0 +1,168 @@
|
||||
# **Vaultwarden Setup and Configuration**
|
||||
|
||||
## **Overview**
|
||||
|
||||
Vaultwarden (formerly Bitwarden_RS) is a lightweight, open-source password management server designed to be an alternative to the official Bitwarden server. It offers an efficient, self-hosted solution to securely manage passwords, notes, and sensitive data. Vaultwarden is ideal for home labs due to its minimal resource requirements and robust feature set.
|
||||
|
||||
---
|
||||
|
||||
## **Docker Compose Configuration**
|
||||
|
||||
Deploying Vaultwarden with Docker Compose ensures ease of setup, portability, and maintainability. Below is the configuration file:
|
||||
|
||||
```yaml
|
||||
services:
|
||||
vaultwarden:
|
||||
image: vaultwarden/server:latest
|
||||
container_name: vaultwarden
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
DOMAIN: "https://vaultwarden.lan" # Replace with your domain or IP
|
||||
ADMIN_TOKEN: "<secure-random-token>" # Replace with a secure admin token
|
||||
LOG_LEVEL: "info" # Adjust log verbosity (debug, info, warn, error)
|
||||
ports:
|
||||
- "80:80" # HTTP port
|
||||
- "443:443" # HTTPS port
|
||||
volumes:
|
||||
- vaultwarden-data:/data
|
||||
networks:
|
||||
- vaultwarden-net
|
||||
|
||||
volumes:
|
||||
vaultwarden-data:
|
||||
|
||||
networks:
|
||||
vaultwarden-net:
|
||||
driver: bridge
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## **Configuration Details**
|
||||
|
||||
### **1. Image and Container**
|
||||
|
||||
- **Image**: The `vaultwarden/server:latest` image provides the latest stable release.
|
||||
- **Container Name**: The container is named `vaultwarden` for clarity and easy identification in Docker commands.
|
||||
|
||||
### **2. Environment Variables**
|
||||
|
||||
- **DOMAIN**: Specifies the Vaultwarden service's domain or IP address. Replace `https://vaultwarden.lan` with your domain or IP.
|
||||
- **ADMIN_TOKEN**: A secure token for accessing the admin panel. Generate one using:
|
||||
|
||||
```bash
|
||||
openssl rand -base64 48
|
||||
```
|
||||
|
||||
- **LOG_LEVEL**: Controls log verbosity. Default is `info`, but you can use `debug`, `warn`, or `error` based on your monitoring needs.
|
||||
|
||||
### **3. Ports**
|
||||
|
||||
- Maps HTTP (80) and HTTPS (443) ports to the host. HTTPS ensures secure communication, especially when accessed remotely.
|
||||
|
||||
### **4. Volumes**
|
||||
|
||||
- **`vaultwarden-data`**: Persists all Vaultwarden data, including user credentials and server configurations, across container restarts and updates.
|
||||
|
||||
### **5. Network**
|
||||
|
||||
- **Bridge Network**: Vaultwarden runs on a dedicated Docker bridge network, isolating it from other containers for added security.
|
||||
|
||||
---
|
||||
|
||||
## **Deployment Steps**
|
||||
|
||||
1. **Prepare Your Environment**
|
||||
|
||||
- Ensure Docker and Docker Compose are installed on your host.
|
||||
2. **Create the `docker-compose.yml` File**
|
||||
|
||||
- Save the above configuration as `docker-compose.yml` in your preferred directory.
|
||||
3. **Generate an Admin Token**
|
||||
|
||||
- Run the following command to generate a secure admin token:
|
||||
|
||||
```bash
|
||||
openssl rand -base64 48
|
||||
```
|
||||
|
||||
- Replace `<secure-random-token>` in the `ADMIN_TOKEN` field with the generated token.
|
||||
4. **Start the Service**
|
||||
|
||||
- Deploy Vaultwarden with:
|
||||
|
||||
```bash
|
||||
docker-compose up -d
|
||||
```
|
||||
|
||||
5. **Access Vaultwarden**
|
||||
|
||||
- Open a web browser and navigate to `http://<server-ip>` (or `https://<your-domain>` if HTTPS is configured).
|
||||
6. **Admin Panel**
|
||||
|
||||
- Access the admin panel at `http://<server-ip>/admin` (or `https://<your-domain>/admin`) using the `ADMIN_TOKEN`.
|
||||
|
||||
---
|
||||
|
||||
## **Enhancing Security**
|
||||
|
||||
- **Enable HTTPS**:
|
||||
|
||||
- Use a reverse proxy like NGINX or Traefik to configure SSL with Let's Encrypt.
|
||||
- Alternatively, generate a self-signed certificate or import an existing SSL certificate.
|
||||
- **Firewall Configuration**:
|
||||
|
||||
- Restrict access to the admin panel (`/admin`) to trusted IPs using a firewall or reverse proxy.
|
||||
- **Regular Backups**:
|
||||
|
||||
- Backup the `vaultwarden-data` volume to prevent data loss:
|
||||
|
||||
```bash
|
||||
docker run --rm -v vaultwarden-data:/data -v $(pwd):/backup alpine tar czf /backup/vaultwarden-backup.tar.gz /data
|
||||
```
|
||||
|
||||
- **Use a Strong Admin Token**:
|
||||
|
||||
- Ensure the `ADMIN_TOKEN` is a long, unique string to prevent unauthorized admin access.
|
||||
|
||||
---
|
||||
|
||||
## **Why Vaultwarden?**
|
||||
|
||||
- **Lightweight and Efficient**:
|
||||
|
||||
- Minimal system resource usage, ideal for home labs or low-spec servers.
|
||||
- **Self-Hosted Privacy**:
|
||||
|
||||
- Full control over your data without relying on third-party services.
|
||||
- **Feature-Rich**:
|
||||
|
||||
- Multi-user support, secure notes, 2FA, and API compatibility with Bitwarden clients.
|
||||
- **Cost-Effective**:
|
||||
|
||||
- No subscription fees or licensing costs.
|
||||
|
||||
---
|
||||
|
||||
## **Troubleshooting**
|
||||
|
||||
- **Container Won't Start**:
|
||||
|
||||
- Check logs:
|
||||
|
||||
```bash
|
||||
docker logs vaultwarden
|
||||
```
|
||||
|
||||
- Verify environment variables and network settings.
|
||||
- **Access Issues**:
|
||||
|
||||
- Ensure the correct domain or IP is used in the `DOMAIN` variable.
|
||||
- Verify firewall rules are not blocking the configured ports.
|
||||
- **Admin Panel Not Accessible**:
|
||||
|
||||
- Confirm the `ADMIN_TOKEN` is correctly set and retry.
|
||||
|
||||
---
|
||||
|
||||
Vaultwarden is a powerful, lightweight solution for self-hosting your password manager. By following this guide, you'll have a secure and reliable service tailored to your home lab environment.
|
||||
Reference in New Issue
Block a user