/data by default. Keep the public URL in DOMAIN and enable HTTPS before adding accounts; the volume holds the database and attachments.
Towbar manifest
.towbar/services/vaultwarden.service.yml
Configure
- Prepare the example server, connect the repository, and map
productionto the branch containing these manifests. Replace the example server IP and domain. Commit the manifests, then sync the repository and inspect the resolved configuration. - Set the Service’s declared runtime values under Service → Settings → Secrets using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
- Keep the Service’s named volumes attached across deployments. Towbar’s Datastore backup policy does not back up Service volumes, so include them in your own recovery plan.
- Deploy the Service, then perform the checks below before enabling auto-deploy.
Runtime values
Save these values on the Service after the repository sync. The manifest declares required keys, not their values.Verify
Create an account over HTTPS, lock and unlock the vault, then verify the account survives a redeploy. Back up/data separately.
For field constraints, see Service manifest.