# Vaultwarden - Password Manager (Bitwarden-compatible) # Domain: ${SUBDOMAIN}.${DOMAIN} # Database: None (SQLite, built-in) # RAM: ~50MB (mem_limit: 256M) | Pi-compatible: Yes # # Environment variables: # DOMAIN - Your domain (e.g., demo-felhom.eu) # ADMIN_TOKEN - Admin panel token (auto-generated) # SIGNUPS_ALLOWED - "false" by default (R-512): only invited addresses can register # # First-time setup (invite-first; settings are read-only after install): # 1. Open https://${SUBDOMAIN}.${DOMAIN}/admin with the generated ADMIN_TOKEN # 2. Invite the household's addresses (Users → Invite User; works without mail) # 3. Visit https://${SUBDOMAIN}.${DOMAIN} and create the account with an invited address # # Clients: # Use any Bitwarden client (desktop, mobile, browser extension) # Set server URL to: https://${SUBDOMAIN}.${DOMAIN} services: vaultwarden: image: vaultwarden/server:1.36.0-alpine container_name: vaultwarden restart: unless-stopped environment: - DOMAIN=https://${SUBDOMAIN}.${DOMAIN} # R-512: registration is CLOSED by default. A stranger who guesses vault. must not be able to # open an account. The household is invited from the admin panel; measured 2026-09-15 on # 1.36.0-alpine with SMTP off: stranger register 400, admin invite 200, invited register 200. - SIGNUPS_ALLOWED=${SIGNUPS_ALLOWED:-false} - ADMIN_TOKEN=${ADMIN_TOKEN:-} - WEBSOCKET_ENABLED=true - TZ=Europe/Budapest # App-email (managed relay). Injected by the controller only when app-email is on # (global + per-app); see .felhom.yml smtp_mapping. # TRAP (campaign finding F1, 2026-07-06): Vaultwarden treats a defined-but-EMPTY env var as # "set" — with SMTP_HOST/SMTP_FROM both defined-empty its config validation errors out and # the container crash-loops. The whole SMTP group is therefore gated by _ENABLE_SMTP # (default false = validation skipped, mail off); the controller's app-email injection flips # it to true via smtp_mapping.extra. Note: a config.json saved from the admin panel would # override these env values — not applicable to fresh deploys. - _ENABLE_SMTP=${_ENABLE_SMTP:-false} - SMTP_HOST=${SMTP_HOST:-} - SMTP_PORT=${SMTP_PORT:-587} - SMTP_SECURITY=${SMTP_SECURITY:-off} - SMTP_FROM=${SMTP_FROM:-} - SMTP_FROM_NAME=${SMTP_FROM_NAME:-} - SMTP_ACCEPT_INVALID_CERTS=${SMTP_ACCEPT_INVALID_CERTS:-false} - SMTP_ACCEPT_INVALID_HOSTNAMES=${SMTP_ACCEPT_INVALID_HOSTNAMES:-false} volumes: - vaultwarden_data:/data networks: - traefik-public deploy: resources: limits: memory: 256M healthcheck: test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/alive"] interval: 30s timeout: 5s retries: 3 start_period: 10s labels: - "traefik.enable=true" - "traefik.http.routers.vaultwarden.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" - "traefik.http.routers.vaultwarden.entrypoints=websecure" - "traefik.http.routers.vaultwarden.tls=true" - "traefik.http.routers.vaultwarden.tls.certresolver=letsencrypt" - "traefik.http.services.vaultwarden.loadbalancer.server.port=80" volumes: vaultwarden_data: networks: traefik-public: external: true