Skip to content

For Vaultwarden

Vaultwarden on Edge, Bitwarden you control

A single Rust binary and a SQLite file on a small VM. The official Bitwarden apps connect over HTTPS, vault data is encrypted on each device before it arrives, and a copy lands in Edge Storage every night.

Free to sign up. No egress fees on any product.

Why Vaultwarden on Edge

The Bitwarden experience, on a server you own

Your team keeps the apps they know. You keep the server, the backups and the bill.
  • Official Bitwarden apps

    Point the Bitwarden browser extensions, desktop and mobile apps at your server URL. Same apps, your server.
  • A Rust binary on a small VM

    Vaultwarden is light on memory and CPU. A small VM idles along with a whole team on it.
  • Organisations and sharing

    Organisations, collections, Send and emergency access, with no paid plan to unlock them.
  • Two-factor built in

    TOTP, FIDO2 WebAuthn, YubiKey OTP, Duo and email codes are all supported.
  • Only ciphertext on the server

    Vault items are encrypted on the device before they reach the server. The database holds ciphertext, not passwords.
  • TLS at the edge, API uncached

    The CDN issues the certificate the Bitwarden apps require. Vault API calls are never cached; they go straight to your VM.

Reference architecture

How Vaultwarden maps to Edge

One container, one SQLite file. The CDN terminates TLS and passes vault traffic through untouched; a nightly job copies the database and attachments to a private bucket.
  • Compute

    Runs the Vaultwarden container, with its SQLite database on the VM's NVMe disk.

  • Storage

    A private bucket for nightly database snapshots and attachment backups.

  • CDN

    Issues and renews TLS, passes WebSocket sync through, and never caches vault API responses.

  • DNS

    Anycast DNS for vault.acme.com.

Deploy

A team vault in five steps

Docker Compose, a hashed admin token, a CDN domain with cache bypass rules, and a nightly backup.
  1. 01

    Create the VM and a private bucket

    Generate the admin token hash once on the VM with: docker run --rm -it vaultwarden/server /vaultwarden hash. Store it in .env as ADMIN_TOKEN, in single quotes.

    shell
    $ edge compute create --name vault --size s-2vcpu-4gb \
        --image ubuntu-24 --region london --script docker
    $ edge storage create vault-backups
  2. 02

    Write the compose file

    Sign-ups are off; invite people from the admin page. Add SMTP_* settings so invitation emails can be sent.

    docker-compose.yml
    services:
      vaultwarden:
        image: vaultwarden/server:latest
        env_file: .env   # ADMIN_TOKEN='$argon2id$...' and SMTP_*
        environment:
          DOMAIN: https://vault.acme.com
          SIGNUPS_ALLOWED: "false"
          INVITATIONS_ALLOWED: "true"
        ports: ["127.0.0.1:8080:80"]
        volumes: ["./vw-data:/data"]
        restart: always
  3. 03

    Start it and put the CDN in front

    Proxy :443 on the VM to port 8080. The Bitwarden apps need the HTTPS certificate the CDN issues.

    shell
    $ docker compose up -d
    $ edge cdn create --name vault
    $ edge cdn domains add cdn-a1b2c3 \
        --domain vault.acme.com \
        --origin https://<vm-ip>
  4. 04

    Make sure vault traffic is never cached

    Most vault calls are POSTs or authenticated, which the CDN won't cache anyway. These rules make it explicit.

    CDN configuration (JSON)
    {
      "caching": {
        "respectOriginHeaders": true,
        "rules": [
          { "path": "/api/**", "bypassCache": true },
          { "path": "/identity/**", "bypassCache": true },
          { "path": "/notifications/**", "bypassCache": true },
          { "path": "/admin/**", "bypassCache": true }
        ]
      }
    }
  5. 05

    Back up every night

    SQLite's .backup command takes a consistent copy while the server runs. The bucket stays private.

    /etc/cron.daily/vault-backup
    #!/bin/sh
    set -e
    . /etc/edge.env   # exports EDGE_API_KEY for the Edge CLI
    cd /srv/vault
    sqlite3 vw-data/db.sqlite3 ".backup '/tmp/db.sqlite3'"
    tar czf /tmp/vw.tgz --exclude='db.sqlite3*' vw-data -C /tmp db.sqlite3
    edge storage cp /tmp/vw.tgz "vault-backups/$(date +%F).tgz"

Prefer to hand it off? Give the job to your AI agent or have our engineers do it.

What it costs

A team vault without per-user pricing

Password managers charge per seat. Vaultwarden needs a small VM, and the backups fit inside the free storage tier.
  • No per-user pricing, for a team or a family
  • Organisations and 2FA without a paid plan
  • Room on the same VM for other small tools
  • Zero egress on sync and backups
See compute pricing

Estimated monthly bill on Edge

25-person team vault · nightly backups

USD
  • Compute$19.24Standard VM · 2 vCPU · 4 GiB · 80 GB NVMe
  • Storage$0.0030 nightly backups, inside the 5 GB free tier
  • CDN$0.00~300k requests from the apps, inside 500k free
  • DNS$0.00Zone and records for vault.acme.com
  • Egress$0.00
Total$19.24

Indicative monthly cost · 25-person team vault

  • 1Password Business (25 seats)~$200/mo
  • Bitwarden Enterprise (25 seats)~$150/mo
  • Edge (Standard VM)~$19/mo

Competitor figures are indicative, based on public per-seat pricing. The Edge figure is the bill above, and it doesn't change as you add people.

FAQ

Vaultwarden on Edge, answered

Something else? Ask an engineer.
How does this compare to Bitwarden's own cloud?
Same apps, your server. Vaultwarden is an independent, community-built implementation of the Bitwarden server API, not an official Bitwarden product. It supports organisations, sharing and two-factor without a paid plan.
Is it safe to self-host a password manager?
Vault items are encrypted on each device before they reach the server, and your master password never leaves the device. Someone with the database would see ciphertext. Keep the VM patched, sign-ups off and the admin token hashed.
Will the official Bitwarden apps work?
Yes. The browser extensions, desktop and mobile apps all let you set a self-hosted server URL. Point them at https://vault.acme.com.
Does the CDN ever cache vault data?
No. Vault traffic is mostly POSTs and authenticated API calls, which the Edge CDN doesn't cache, and the bypass rules in step four cover /api, /identity, /notifications and /admin explicitly.
How do I back it up and restore?
The nightly job copies a consistent SQLite snapshot plus attachments and keys to a private bucket. To restore, unpack the latest archive into vw-data on a fresh VM and start the container.

Stand up your vault

Start free. A team or family vault on one small VM, backed up every night.

Free tiers hard-cap. Nothing bills until you add a card.