← All projects
SELF-HOSTED PASSWORD MANAGER · stable

VAULTWARDEN

Vaultwarden in Docker on a Proxmox VM, published through a Cloudflare Tunnel with no open ports. Works with the official Bitwarden extensions across four browsers, syncs every device, and keeps multi-user vaults cryptographically segregated.

proxmoxdockercloudflare-tunnelvaultwardenbackup

// problem

Run a password manager at home with zero inbound exposure, real multi-user isolation, and a backup whose restore has actually been tested.

// constraints

  • No inbound firewall rule anywhere on the network.
  • Cloudflare sees request metadata, never secrets. Vault items are encrypted on-device.
  • Safari supported with no paid Apple Developer account.

// approach

  • Docker runs in a dedicated Debian VM, not on the Proxmox host or in an LXC, for a clean blast radius and whole-host snapshots.
  • Vaultwarden publishes no host port. It sits on an internal Docker network only cloudflared can reach, which dials out to Cloudflare.
  • Cloudflare Access gates only /admin, so Bitwarden extensions and mobile apps can still complete their login flow.
  • Nightly backup uses sqlite3 .backup, encrypts with age, and ships off-box. The restore is rehearsed and logged.

// outcome

A documented threat model, verified security claims, and a backup proven by a rehearsed restore, not assumed.

View source ↗