> ## Documentation Index
> Fetch the complete documentation index at: https://www.towbar.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Vaultwarden

> Vaultwarden is a lightweight server for Bitwarden-compatible password vaults.

export const UseCaseNavigation = () => {
  useLayoutEffect(() => {
    const storageKey = "towbar-use-case-open-groups";
    const groupSelector = "#sidebar li[data-title] > button[aria-expanded]";
    let restoring = false;
    let frame = 0;
    function storedGroups() {
      try {
        return new Set(JSON.parse(sessionStorage.getItem(storageKey) || "[]"));
      } catch {
        return new Set();
      }
    }
    function save(groups) {
      try {
        sessionStorage.setItem(storageKey, JSON.stringify([...groups]));
      } catch {}
    }
    function groupName(button) {
      return button.parentElement?.dataset.title;
    }
    function rememberOpenGroups() {
      const groups = new Set();
      for (const button of document.querySelectorAll(groupSelector)) {
        if (button.getAttribute("aria-expanded") === "true") {
          const name = groupName(button);
          if (name) groups.add(name);
        }
      }
      save(groups);
    }
    function restoreOpenGroups() {
      frame = 0;
      const groups = storedGroups();
      if (!groups.size) return;
      restoring = true;
      for (const button of document.querySelectorAll(groupSelector)) {
        if (groups.has(groupName(button)) && button.getAttribute("aria-expanded") === "false") {
          button.click();
        }
      }
      restoring = false;
    }
    function scheduleRestore() {
      if (!frame) frame = requestAnimationFrame(restoreOpenGroups);
    }
    function onClick(event) {
      if (restoring || !(event.target instanceof Element)) return;
      const button = event.target.closest(groupSelector);
      if (button) {
        const name = groupName(button);
        if (!name) return;
        const groups = storedGroups();
        if (button.getAttribute("aria-expanded") === "true") groups.delete(name); else groups.add(name);
        save(groups);
        return;
      }
      if (event.target.closest('a[href^="/docs/use-cases/"]')) {
        rememberOpenGroups();
      }
    }
    const observer = new MutationObserver(scheduleRestore);
    document.addEventListener("click", onClick, true);
    observer.observe(document.getElementById("sidebar") || document.body, {
      childList: true,
      subtree: true
    });
    scheduleRestore();
    return () => {
      document.removeEventListener("click", onClick, true);
      observer.disconnect();
      cancelAnimationFrame(frame);
    };
  }, []);
  return null;
};

<UseCaseNavigation />

<img className="towbar-doc-brand-logo" src="https://mintcdn.com/avgeek/Wq-9tmR7jDSzqtpH/assets/use-case-logos/vaultwarden.svg?fit=max&auto=format&n=Wq-9tmR7jDSzqtpH&q=85&s=d361297e21997e73eedfb82e9c13b436" alt="Vaultwarden logo" aria-hidden="true" width="24" height="24" data-path="assets/use-case-logos/vaultwarden.svg" />

**Upstream source:** [Current installation guide](https://github.com/dani-garcia/vaultwarden/blob/main/README.md).

Vaultwarden uses SQLite in `/data` by default. Keep the public URL in `DOMAIN` and enable HTTPS before adding accounts; the volume holds the database and attachments.

## Towbar manifest

```yaml title=".towbar/services/vaultwarden.service.yml" theme={"system"}
id: vaultwarden
name: Vaultwarden
buildServer: null
deployment:
  type: image
  image: vaultwarden/server:1.34.3
container:
  port: 80
  volumes:
    - name: data
      mountPath: /data
      initialData: image
environments:
  production:
    server: 192.0.2.10
rollout:
  type: recreate
  maintenanceMode: true
  reason: Persistent application data uses a single writer
secrets:
  runtime:
    - DOMAIN
domains:
  primary: vaultwarden.example.com
tls:
  mode: direct
```

## Configure

1. Prepare the example server, connect the repository, and map `production` to the branch containing these manifests. Replace the example server IP and domain. Commit the manifests, then sync the repository and inspect the resolved configuration.
2. Set the Service's declared runtime values under **Service → Settings → Secrets** using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
3. Keep the Service's named volumes attached across deployments. Towbar's Datastore backup policy does not back up Service volumes, so include them in your own recovery plan.
4. Deploy the Service, then perform the checks below before enabling auto-deploy.

## Runtime values

Save these values on the Service after the repository sync. The manifest declares required keys, not their values.

| Key      | Value to save                                                      |
| -------- | ------------------------------------------------------------------ |
| `DOMAIN` | [https://vaultwarden.example.com](https://vaultwarden.example.com) |

## Verify

Create an account over HTTPS, lock and unlock the vault, then verify the account survives a redeploy. Back up `/data` separately.

For field constraints, see [Service manifest](/docs/services/manifest).
