GuidesFiles, photos and homePasswords with Vaultwarden

Run Vaultwarden, a password manager, with rootless Podman

Vaultwarden on Debian 13, a Bitwarden-compatible password manager for you or your team, in rootless Podman under a user of its own, with HTTPS, updates and backups.

Tested on Vaultwarden 1.37.3 on Debian 13 (trixie) on a Melonslab server Updated September 25, 2026

Recommended server for this guide

VC-S Micro · 2 vCPU · 8 GB Memory · 250 GB Storage

Month to month, no lock-in 7-day money-back guarantee

€7.99/mo

Deploy now
On this page

What you will set up

Vaultwarden is a small password manager server that works with the Bitwarden apps: the browser extensions, the phone and desktop apps, and the command-line client. The apps encrypt your passwords before they leave your device, so the server only ever stores encrypted data.

Here it runs as one container, under a user of its own called vaultwarden, with Caddy from the Podman guide in front for HTTPS.

Every step below was run on a Melonslab VC-P Alloy (2 vCPU, 8 GB) with Debian 13. An account was created, and the official Bitwarden command-line client logged in, stored a login and read it back after a sync. Failed logins were recorded with the visitor's real IP address, sign-ups were closed, and the backup and a reboot were checked. At idle, Vaultwarden used under 10 MB of memory, so the smallest of our Standard plans has room to spare.

Before you start

You need:

  • a server set up as in the Podman guide, with Caddy running;
  • a name for it, such as vault.example.com, with an A record and an AAAA record pointing at your server.

The examples use vault.example.com for the name and 203.0.113.10 for your server's IPv4 address. Replace them with your own throughout.

1. Create the user

As root:

useradd -m -s /bin/bash vaultwarden
loginctl enable-linger vaultwarden
machinectl shell vaultwarden@

2. Describe the container

mkdir -p ~/.config/containers/systemd

Create ~/.config/containers/systemd/vaultwarden.container:

[Unit]
Description=Vaultwarden, a password manager server

[Container]
ContainerName=vaultwarden
Image=docker.io/vaultwarden/server:latest
Volume=vaultwarden-data:/data
# Only Caddy, on this server, can reach Vaultwarden: the port is not open to the internet.
PublishPort=127.0.0.1:8083:80
Environment=DOMAIN=https://vault.example.com
Environment=SIGNUPS_ALLOWED=true
Environment=IP_HEADER=X-Forwarded-For IP_HEADER_TRUSTED_PROXIES=203.0.113.10
AutoUpdate=registry

[Service]
Restart=always

[Install]
WantedBy=default.target

DOMAIN is the address you will open it at. Sign-ups are open for now, so you can create your own account in step 4, and closed right after.

Vaultwarden slows down password guessing per IP address, so it needs each visitor's real one. Caddy passes it on in the X-Forwarded-For header, but Vaultwarden only trusts that header from private addresses by default, and Caddy's connections reach the container from the server's own IPv4 address. IP_HEADER_TRUSTED_PROXIES names that address.

Start it:

systemctl --user daemon-reload
systemctl --user start vaultwarden
podman logs -f vaultwarden

When the log says Rocket has launched, press Ctrl+C.

3. Put Caddy in front

Go back to root with exit, and switch to Caddy's user with machinectl shell caddy@. Add this block to the end of ~/Caddyfile:

vault.example.com {
    reverse_proxy 127.0.0.1:8083
}

And restart Caddy, which briefly interrupts every site it serves:

systemctl --user restart caddy

Caddy gets a certificate for vault.example.com and renews it by itself. The web vault only works over HTTPS.

4. Create your account, then close sign-ups

Open https://vault.example.com and choose to create an account. Pick a long master password you will remember: your data is encrypted with it, so nobody, including Vaultwarden, can reset it for you.

Then go back to Vaultwarden's user (exit, then machinectl shell vaultwarden@) and close sign-ups:

sed -i 's/^Environment=SIGNUPS_ALLOWED=true/Environment=SIGNUPS_ALLOWED=false/' ~/.config/containers/systemd/vaultwarden.container
systemctl --user daemon-reload
systemctl --user restart vaultwarden

Nobody else can now create an account. To add someone later, open sign-ups the same way, let them sign up, and close them again.

5. Connect your apps

In a Bitwarden app or browser extension, choose a self-hosted server before you log in, and enter https://vault.example.com.

In our test, the Bitwarden command-line client 2026.9.0 could not log in to Vaultwarden 1.37.3: it asks the server for a feature that was added after that release. Version 2026.8.0 worked. The fix is merged for Vaultwarden's next release, which the daily updates in step 6 will install.

6. Keep it up to date

Switch on Podman's daily updates for this user:

systemctl --user enable --now podman-auto-update.timer

7. Back up

mkdir -p ~/backup
systemctl --user stop vaultwarden
podman volume export vaultwarden-data --output ~/backup/vaultwarden-data.tar
systemctl --user start vaultwarden

Stopping Vaultwarden for the few seconds it takes gives a consistent copy of its database. The archive holds the database, attachments and the key the server signs logins with. The passwords in it are encrypted with each user's master password, but keep the archive private anyway, and copy ~/backup to another machine: a backup on the same server does not survive losing the server.

Troubleshooting

Every failed login in the log shows your server's own address. IP_HEADER_TRUSTED_PROXIES in step 2 must be the server's IPv4 address, the one Caddy's connections arrive from.

Signing up says "Registration not allowed or user already exists". Sign-ups are closed, which is what step 4 does, or the email address already has an account.

The app cannot connect. Check that it points at https://vault.example.com, and read the log with podman logs vaultwarden as the vaultwarden user.

Your passwords, in Sweden

With Vaultwarden on a Melonslab server, your encrypted vault is stored in Sweden, under Swedish and EU law, on a server you control.

Run it on your own server

VC-S Micro

€7.99/mo

vCPU
2
Memory
8 GB
Storage
250 GB
Transfer
10 TB
Standard
HDD · RAID 10
  • Full root access
  • Native /64 IPv6
  • RAID-protected storage
  • Malmö, Sweden
  • Month to month, no lock-in
  • 7-day money-back guarantee
All guides