← Archive

Deploy Vaultwarden with Postgres (on your Synology)

Archived post · originally published · may be out of date

Docker Containers & Applications · #Docker #SQLite #Postgres #Synology #Vaultwarden


Introduction

Initially when you spin-up a Vaultwarden instance, the container itself deploys a SQLite database which works for the majority of use cases however in certain circumstances, such as a larger organization, it is more preferable to have a separate database that Vaultwarden connects to. Originally based on the guide provided by the Vaultwarden team, my guide is more in-depth and designed for a beginner.

How To

My environment consists of my Synology that is utilizing Portainer to manage my containers.

Deploy Portainer

I highly recommend using Portainer to manage and deploy your containers on your Synology (instead of Container Manager) but you can skip this step if you are comfortable with the command line (we will be using a docker compose file). Here is a quick guide on how to install Portainer on your Synology.

Create new folders on your Synology

Create a new vaultwarden folder located in your docker shared folder, then create two subfolders:

In my case, my folder path is /docker/storage/vaultwarden because I like having an additional sub-folder to store all of my container data instead of putting it in the root of docker:

vaultwarden-1

Deploy Vaultwarden with Postgres

Deploy the following compose file as a stack to Portainer:

version: "3.9"
services:
  db:
    image: postgres:16
    container_name: Vaultwarden-DB
    hostname: vaultwarden-db
    security_opt:
      - no-new-privileges:true
    healthcheck:
      test: ["CMD", "pg_isready", "-q", "-d", "vaultwarden", "-U", "vaultwardenuser"]
      timeout: 45s
      interval: 10s
      retries: 10
    volumes:
      - /volume1/docker/storage/[YOUR VAULTWARDEN FOLDER]/db:/var/lib/postgresql/data:rw
    environment:
      POSTGRES_DB: vaultwarden
      POSTGRES_USER: vaultwardenuser
      POSTGRES_PASSWORD: [CHANGE ME]
    restart: on-failure:5
  vaultwarden:
    image: vaultwarden/server:latest
    container_name: Vaultwarden
    hostname: vaultwarden
    security_opt:
      - no-new-privileges:true
    ports:
      - 4020:4020
    volumes:
      - /volume1/docker/storage/[YOUR VAULTWARDEN FOLDER]/app:/data:rw
    environment:
      ROCKET_PORT: 4020
      SIGNUPS_ALLOWED: false
      DATABASE_URL: postgresql://vaultwardenuser:[POSTGRES_PASSWORD]@vaultwarden-db:5432/vaultwarden
      ADMIN_TOKEN: [CHANGE ME]
      DISABLE_ADMIN_TOKEN: false
      DOMAIN: [YOUR URL]
      SMTP_HOST: [CHANGE ME]
      SMTP_FROM: [CHANGE ME]
      SMTP_PORT: 587
      SMTP_SECURITY: starttls
      SMTP_USERNAME: [CHANGE ME]
      SMTP_PASSWORD: [CHANGE ME]
    restart: on-failure:5
    depends_on:
      db:
        condition: service_started

If you are successful with your deployment then you will be greeted with a login page at HTTP://CONTAINER HOST IP:PORT:

vaultwarden-2

To begin creating users and customizing your experience, navigate to the admin portal at HTTP://CONTAINER HOST IP:PORT/admin then use the previously created ADMIN_TOKEN value to sign-in: