Skip to main content
Upstream source: Current installation guide. Vaultwarden uses SQLite in /data by default. Keep the public URL in DOMAIN and enable HTTPS before adding accounts; the volume holds the database and attachments.

Towbar manifest

.towbar/services/vaultwarden.service.yml

Configure

  1. Prepare the example server, connect the repository, and map production to the branch containing these manifests. Replace the example server IP and domain. Commit the manifests, then sync the repository and inspect the resolved configuration.
  2. Set the Service’s declared runtime values under Service → Settings → Secrets using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
  3. Keep the Service’s named volumes attached across deployments. Towbar’s Datastore backup policy does not back up Service volumes, so include them in your own recovery plan.
  4. Deploy the Service, then perform the checks below before enabling auto-deploy.

Runtime values

Save these values on the Service after the repository sync. The manifest declares required keys, not their values.

Verify

Create an account over HTTPS, lock and unlock the vault, then verify the account survives a redeploy. Back up /data separately. For field constraints, see Service manifest.
Last modified on September 27, 2026