# Setup + Docker Compose details (3rd/April/2026) # Vaultwarden: The Self-Hosted Password Manager You Need! # YT - https://www.youtube.com/watch?v=EARDyWw7Id4 # Docker-Compose sample file # https://whatsnewandrew.com/vaultwarden-password-manager/ # Cloudflare: Test this token # == This is WRONG! - this CMD code is for linux systems NOT Windows == # curl "https://api.cloudflare.com/client/v4/user/tokens/verify" \ # -H "Authorization: Bearer cfut_IiiFD5vXm4GZftaZ1sOkSufmrvQswv874L6dFLcKe0fd6868" # == This is CORRECT! - this CMD code is for Windows == # curl -H "Authorization: Bearer cfut_IiiFD5vXm4GZftaZ1sOkSufmrvQswv874L6dFLcKe0fd6868" -H "Content-Type: application/json" "https://api.cloudflare.com/client/v4/user/tokens/verify" # NGinX Domain for VaultWarden Container # vw.localvault.shinobi491.work # https://vw.localvault.shinobi491.work:8383 # CMD Verify # nslookup vw.localvault.shinobi491.work # https://vw.localvault.shinobi491.work # === Local Network == # http://192.168.68.112:8383 # === TS-Vpn Network == # http://100.98.17.37:8383 # === Tailscale == # .....NGix CERT Domain: *.tail.shinobi491.work # ...Cloudflare API Key: cfut_IiiFD5vXm4GZftaZ1sOkSufmrvQswv874L6dFLcKe0fd6868 # ==================== Proxy Host =========================== # ......Proxy Host Domain Name: warden.tail.shinobi491.work # .........Forward Hostname/IP: 192.168.68.112 # ................Forward Port: 8383 # +++++++++++++++++++ This WORKED!! +++++++++++++++++++++ # Tailscale ONLY SSL URL: https://warden.tail.shinobi491.work # No port number required! # # https://vw.localvault.shinobi491.work/admin # # OAuth 2.0 client credentials # client_id: # user.84cc91e9-0d55-4707-8ff7-3c268798c7c1 # client_secret: # Vq7rkUcLjSrUZ6vDTwNQgxHQGPaiKv # scope: # api # grant_type: # client_credentials # # http://mealee3ts.tail.shinobi491.work/ # 100.98.17.37 # === The My File v1.0 === docker-compose file services: vaultwarden: image: vaultwarden/server:latest container_name: vaultwarden restart: unless-stopped ports: - "8383:80" environment: ADMIN_TOKEN: $${LGO009mGdEuuf9UGkKsfi/KPRY2YBdMCo/W7+gJ4zjhA4S4DATW97zND3Gf4IqM6} # openssl rand -base64 48 (command to generate your ADMIN_TOKEN) WEBSOCKET_ENABLED: true SIGNUPS_ALLOWED: true # Set to true on first run so that you can create your initial account! DATABASE_URL: vw-data/db.sqlite3 DOMAIN: "192.168.68.112:8383" TZ: Europe/London volumes: - ./vw-data/:/data/ volumes: vaultwarden: # === The OG File === docker-compose file # ================ The My File v2.0 ================ docker-compose file # ================ The My File v2.0 ================ docker-compose file # Now adding Gmail # Bcoz I got the reverse proxy SSL working, I'll add it here # or when email links are sent 192.168.68.112 is NOT secure (SSL) # When at home & if Tailscale is OFF... https://vw.localvault.shinobi491.work # Portainer Stack Name: vaultwarden-v2-ssl # ================ This Worked!! v2.0 ================ docker-compose file services: vaultwarden: image: vaultwarden/server:latest container_name: vaultwarden restart: unless-stopped ports: # Do NOT touch!!!!... The number on the right (80) vaultwarden ALWAYS runs on that port # You can change the left number to any available ports - "8383:80" environment: # Used to login to & Enable: Vaultwarden Admin Panel # Vaultwarden Admin Panel URL: https://vw.localvault.shinobi491.work/admin # If not set, the admin panel is disabled ADMIN_TOKEN: $${LGO009mGdEuuf9UGkKsfi/KPRY2YBdMCo/W7+gJ4zjhA4S4DATW97zND3Gf4IqM6} # openssl rand -base64 48 (command to generate your ADMIN_TOKEN) WEBSOCKET_ENABLED: true # Controls if new users can register (At the login page) # SIGNUPS: Set to true on first run so that you can create your initial account! SIGNUPS_ALLOWED: true DATABASE_URL: /data/db.sqlite3 # Reverse proxy for Tailscale ONLY. resolves to port:8383 # Tailscale ONLY SSL URL (You MUST Have Tailscale switched ON, Local or Not) DOMAIN: "https://warden.tail.shinobi491.work" TZ: Europe/London # vaultwarden SMTP Settings # vaultwarden SMTP Settings (Corrected + Fixed) # Fixed by LLM Studio >> Gemma 4 SMTP_HOST: "smtp.gmail.com" SMTP_PORT: 587 SMTP_USERNAME: "mas4525@gmail.com" SMTP_PASSWORD: "adum pzcx abth yknp" # My Google App Password SMTP_TLS: true SMTP_FROM: "mas4525@gmail.com" # vaultwarden SMTP Settings (WRONG!!) - Email was not setup, when the container was deployed!! # Vaultwarden, the SMTP configuration variables do not use the word DEFAULT # Even more importantly, # the specific prefix for those variables isn't EMAIL_TRANSPORT_..., it is actually SMTP_ EMAIL_TRANSPORT_DEFAULT_HOST: "smtp.gmail.com" EMAIL_TRANSPORT_DEFAULT_PORT: "587" EMAIL_TRANSPORT_DEFAULT_USERNAME: "mas4525@gmail.com" # Your gmail address EMAIL_TRANSPORT_DEFAULT_PASSWORD: "adum pzcx abth yknp" # If using Gmail: (Google -> Manage account -> Security > App passwords) EMAIL_TRANSPORT_DEFAULT_TLS: true EMAIL_DEFAULT_FROM: "mas4525@gmail.com" # Your gmail address # Allows org admins to invite users, even when signups are disabled INVITATIONS_ALLOWED: true # Name shown in the invitation emails that don't come from a specific organization INVITATION_ORG_NAME: Vaultwarden-MxS volumes: - ./data/:/data/ volumes: vaultwarden: # === The OG File === docker-compose file