73a9bc4807
gates / gates (push) Successful in 1s
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
78 lines
3.3 KiB
YAML
78 lines
3.3 KiB
YAML
# Vaultwarden - Password Manager (Bitwarden-compatible)
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: None (SQLite, built-in)
|
|
# RAM: ~50MB (mem_limit: 256M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# ADMIN_TOKEN - Admin panel token (auto-generated)
|
|
# SIGNUPS_ALLOWED - "false" by default (R-512): only invited addresses can register
|
|
#
|
|
# First-time setup (invite-first; settings are read-only after install):
|
|
# 1. Open https://${SUBDOMAIN}.${DOMAIN}/admin with the generated ADMIN_TOKEN
|
|
# 2. Invite the household's addresses (Users → Invite User; works without mail)
|
|
# 3. Visit https://${SUBDOMAIN}.${DOMAIN} and create the account with an invited address
|
|
#
|
|
# Clients:
|
|
# Use any Bitwarden client (desktop, mobile, browser extension)
|
|
# Set server URL to: https://${SUBDOMAIN}.${DOMAIN}
|
|
|
|
services:
|
|
vaultwarden:
|
|
image: vaultwarden/server:1.36.0-alpine
|
|
container_name: vaultwarden
|
|
restart: unless-stopped
|
|
environment:
|
|
- DOMAIN=https://${SUBDOMAIN}.${DOMAIN}
|
|
# R-512: registration is CLOSED by default. A stranger who guesses vault.<domain> must not be able to
|
|
# open an account. The household is invited from the admin panel; measured 2026-09-15 on
|
|
# 1.36.0-alpine with SMTP off: stranger register 400, admin invite 200, invited register 200.
|
|
- SIGNUPS_ALLOWED=${SIGNUPS_ALLOWED:-false}
|
|
- ADMIN_TOKEN=${ADMIN_TOKEN:-}
|
|
- WEBSOCKET_ENABLED=true
|
|
- TZ=Europe/Budapest
|
|
# App-email (managed relay). Injected by the controller only when app-email is on
|
|
# (global + per-app); see .felhom.yml smtp_mapping.
|
|
# TRAP (campaign finding F1, 2026-07-06): Vaultwarden treats a defined-but-EMPTY env var as
|
|
# "set" — with SMTP_HOST/SMTP_FROM both defined-empty its config validation errors out and
|
|
# the container crash-loops. The whole SMTP group is therefore gated by _ENABLE_SMTP
|
|
# (default false = validation skipped, mail off); the controller's app-email injection flips
|
|
# it to true via smtp_mapping.extra. Note: a config.json saved from the admin panel would
|
|
# override these env values — not applicable to fresh deploys.
|
|
- _ENABLE_SMTP=${_ENABLE_SMTP:-false}
|
|
- SMTP_HOST=${SMTP_HOST:-}
|
|
- SMTP_PORT=${SMTP_PORT:-587}
|
|
- SMTP_SECURITY=${SMTP_SECURITY:-off}
|
|
- SMTP_FROM=${SMTP_FROM:-}
|
|
- SMTP_FROM_NAME=${SMTP_FROM_NAME:-}
|
|
- SMTP_ACCEPT_INVALID_CERTS=${SMTP_ACCEPT_INVALID_CERTS:-false}
|
|
- SMTP_ACCEPT_INVALID_HOSTNAMES=${SMTP_ACCEPT_INVALID_HOSTNAMES:-false}
|
|
volumes:
|
|
- vaultwarden_data:/data
|
|
networks:
|
|
- traefik-public
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/alive"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 10s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.vaultwarden.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.vaultwarden.entrypoints=websecure"
|
|
- "traefik.http.routers.vaultwarden.tls=true"
|
|
- "traefik.http.routers.vaultwarden.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.vaultwarden.loadbalancer.server.port=80"
|
|
|
|
volumes:
|
|
vaultwarden_data:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|