VAULTWARDEN
Vaultwarden in Docker on a Proxmox VM, published through a Cloudflare Tunnel with no open ports. Works with the official Bitwarden extensions across four browsers, syncs every device, and keeps multi-user vaults cryptographically segregated.
proxmoxdockercloudflare-tunnelvaultwardenbackup
// problem
Run a password manager at home with zero inbound exposure, real multi-user isolation, and a backup whose restore has actually been tested.
// constraints
- No inbound firewall rule anywhere on the network.
- Cloudflare sees request metadata, never secrets. Vault items are encrypted on-device.
- Safari supported with no paid Apple Developer account.
// approach
- Docker runs in a dedicated Debian VM, not on the Proxmox host or in an LXC, for a clean blast radius and whole-host snapshots.
- Vaultwarden publishes no host port. It sits on an internal Docker network only cloudflared can reach, which dials out to Cloudflare.
- Cloudflare Access gates only /admin, so Bitwarden extensions and mobile apps can still complete their login flow.
- Nightly backup uses sqlite3 .backup, encrypts with age, and ships off-box. The restore is rehearsed and logged.
// outcome
A documented threat model, verified security claims, and a backup proven by a rehearsed restore, not assumed.