Skip to content

Vaultwarden (Bitwarden) in Docker on a Synology NAS

Last updated on 29 August 2024

Please note if you are using DSM7.2 or higher you should use the Container Manager version of this guide from the menu.
UpdateDate
Adjusted the Reverse Proxy for WebSockets28/08/2023
Historic updates now at the end of the guide.


What is Vaultwarden/Bitwarden?

Vaultwarden is a rewrite of the official Bitwarden server using the Rust language, it was created to reduce the need for the number of containers required for the official server.

It is compatible with all the official Bitwarden apps and Browser extensions. It is a great way to self-host a password manager it gives you complete control over your passwords and allows you to have automatic syncing across web, desktop and mobile apps.

Let’s Begin

This guide contains three parts:

  • Part 1 — Setting up the container via the DSM GUI
  • Part 2 — Setting up DDNS, Reverse Proxy and SSL
  • Part 3 — Setting up the Bitwarden Clients

Before we start head over to the short guide below to set up a Bridge Network

Part 1 — Container Set up (DSM GUI)

Downloading the Vaultwarden Image

Open up Docker within DSM and navigate to the ‘Registry’ section and search for ‘vaultwarden’ in the search box and download the ‘vaultwarden/server’ version

The pop-up box will ask which version you want to download, make sure you choose ‘Latest’ from the list of available versions.

Select ‘Latest’ from the tags

You can check the status of the download over on the ‘Image’ tab.

Setting up the container

In Docker click on the ‘Image’ tab, in the list of your containers select the ‘vaultwarden/server’ image and click on ‘Launch’

You will be greeted with the Network screen, we will be using the ‘synobridge’ network we created earlier select it from the list and click Next.

General Settings

Next you will be greeted with the General Settings screen, this is where you can start specifying some of your preferences.

You can change the name of the container to anything you like, and you may want to enable Auto Restart as this will ensure the container starts automatically if you reboot your NAS.

You will also notice a Configure capabilities button — don’t change anything in here!

Next up we are going to click on the ‘Advanced Settings’ button, this will take you to a new window with a number of tabs which we are going to work through.

Environment

We need to add two additional variables, the first disables any random person signing up for an account on your personal hosted version, the second enables the Admin panel which allows you to invite users.

Argon2 Hashing

As of version 1.28 of Vaultwarden it is recommended to create an Argon2 hashed admin token rather than using a plaintext one. We will be doing this via the Argon2 Hash Generator online if you wish to do this via SSH follow the instructions here.

Go to https://argon2.online/ and enter the following variables into the form and then press ‘Generate Hash’.

OptionVariable to Select or Enter
Plain Text InputEnter either a long string of characters or a secure long ‘password’ aka token, you will use this to log in to your admin panel, so it needs to be secure, and you must remember it!
SaltPress the Cog it will generate a random string of characters
Parallelism Factor4
Memory Cost65540
Iterations3
Hash Length64
Three Argon VersionsSelect Argon2id

As you can see above we have generated our hash.

We can now enter the amended hash into our Environment section.

VariableValue
SIGNUPS_ALLOWEDFALSE
ADMIN_TOKENYour hashed admin token from above
You must come and change this to false later

You do not need to set up anything on these tabs.

Press ‘Save’ to go back to the initial setup screen, then press ‘Next’

Port Settings

As Vaultwarden uses port 80 for its web interface by default we need to change this to ensure we don’t have any conflicts with DSM’s web functions.

You will see the Container Port section prefilled you must not change these ports. Change the ‘Local ports’ from ‘Auto’ to the values below.

Local PortContainer PortType
30123012TCP
812280TCP
Port Settings

Volume Settings

We will now be specifying the directories where Vaultwarden will store its configuration files and database.

Click on Add Folder, click on the ‘docker’ share and create a new sub-folder called ‘vaultwarden’ click on this folder and click ‘select’

In the Mount path section for this folder enter ‘/data’ it should now look like the screenshot below, click next.

Summary

You have now completed the setup of the container.

You will be shown an overall summary of the settings we have specified, this is a good time to double-check everything is correct. Finally, click on Done and the container should start to boot.

You should now be able to access the web interface via the IP of your NAS followed by the port 8122

e.g 192.168.0.40:8122

Successful start up

You will not be able to register an account yet, as you must have a valid SSL certificate in place.

External Access

You have some choices when it comes to making your new container accessible from outside your home network, these come with different levels of security and convenience. This mini section is generic but covers the basics of getting this guide up and running and is entirely optional.

  • Synology’s DDNS (Dynamic Domain Name System) with a TLS Certificate and Reverse Proxy
    This is useful if you have some family members or friends that need access to something like Overseerr or Jellyseer and is covered below.

  • Tailscale or Wireguard VPN
    If just you are accessing these services, and you don’t want to expose them to the internet this would be the more secure choice. See my other separate guides.

  • Cloudflare Tunnels
    I don’t currently use these, so I would recommend watching the Wundertech guide on how they work.

A note on Double NAT or CGNAT
Unfortunately more ISPs are moving to these methods of address allocation as the IPv4 address space is getting low on available addresses. If your ISP is doing this your choices are more limited.

You can test if this is the case by checking the WAN IP on your Router/Modem settings and then comparing it to the one shown on portchecker.co. If they are different you are likely Double NAT and will either need to see if you can pay your ISP for a standard IPv4 address or use Tailscale or Cloudflare Tunnels for access.

Using the built-in tools on DSM

The first step of this process is to forward port 443 on your Router to your NAS IP Address, how you do this will depend on your router model, so please refer to its manual.

Router (External):443 > NASIP (Internal):443

Next make sure you have registered for a Synology Account as we are going to be using their DDNS service. https://account.synology.com/en-uk/register/ If you already have this set up move to the next step.

DDNS (Dynamic Domain Name System)

A DDNS address allows you to get external access to your container via an address provided by Synology, this is useful on home internet connections where your ISP will change your IP address on a semi-regular basis.

In the DSM Control panel go to ‘External Access’ and then to the ‘DDNS’ tab

Click on ‘Add’, then fill out the following sections.

SectionValue
Service ProviderSynology
HostnameThis will be the unique address just for you so keep the name generic.
minecraft.synology.me = BAD
myawesomenas.synology,me =GOOD
Email:Log into your Synology account
External Address (IPv4)This should be filled in automatically
External Address (IPv6)This should be filled in automatically if your ISP is using IPv6
Get a Cert from Let’s EncryptTick this box
Enable HeartbeatTick this box

Now press OK, DSM will apply your settings. It can take a few moments to set up and the DSM interface will refresh. You will likely receive a certificate error which you will need to accept to get back into DSM.

Reverse Proxy

We are going to set up a reverse proxy subdomain for the address you just register. This means you and your users can access the container without using a port number as it will route all traffic through the secure 443 port.

Go back into the Control Panel and access the ‘Login Portal’ then in the ‘Advanced’ tab click ‘Reverse Proxy’ and then click on ‘Create’.

We are now going to enter some rules, so when you or your users access the URL specified the request will automatically be sent to the containers web UI.

Use the settings below, you will need to amend the Hostname sections in line with the hostname you registered earlier, and the IP of your NAS.

SettingValue
Reverse Proxy Name:Give it a meaningful name in line with the container you are setting up.
Protocol:HTTPS
Hostname:containername.xxx.synology.me
containername‘ will be the name you want to use to access this container
.xxx.synology.me‘ will be the exact name you registered earlier
Port:443
Protocol:HTTP
Hostname:‘localhost’ or your NAS IP address
Port:The UI Port Number from the yaml in the guide you are following

On the second tab ‘Custom Header’ click on Create then WebSocket, this will add two entries for WebSockets to function correctly, you can now press save.

You should now be able to access the web UI of the container by going to the address you just set up in the reverse proxy, it will be a secure connection, and you should have no certificate errors.

You should now be able to access the Bitwarden (Vaultwarden) web UI by going to https://bitwarden.yourhostname it will be a secure connection, and you should have no SSL errors.

SSL Working

Setting up the Admin Settings

As we disabled sign-ups via the main log in screen you will need to invite yourself and any other users from the admin panel.

Go to bitwarden.yourhostname.me/admin

Enter the admin token which is the string of text or ‘password’ you used to create the Argon2 token (you don’t use the actual Argon2 string).

Admin Token

We need to change a few options to enable user sign up emails. (Please note that you will not be able to use Gmail SMTP in this step as they have disabled ‘unsecure’ 3rd party application login. Also, if you plan on using Yahoo you will need to set up an app specific password – as shown in this guide)

In General Settings. Amend the Domain URL to your own.

Domain URL

Next you will need to amend your own email settings in the SMTP Email Settings section.

This will need to be in line with your email provider, once you have entered the details click Save at the bottom of the screen, you can then send a test email to yourself to ensure its working.

The final step will be to send yourself an invitation email via the Users’ panel at the top of the page. This allows you to create an account by clicking the link in the email.

Users settings screen

You have now successfully set up Vaultwarden.

Part 3 — Setting Up the Bitwarden Clients.

Now you have set up Vaultwarden you can use the various Mobile, Desktop or Browser Add-ons.

It’s very easy to point these to your personal self-hosted version. In the main login screen click the ‘Logging in on:’ and select ‘Self-hosted’

In the pop-up screen enter your full address for the server e.g. https://vaultwarden.xyz.synology.me

You have now completed the guide.

FAQ

Q) I am receiving the notice “You are using a plain text ADMIN_TOKEN which is insecure.”

A) A recent update changed the Admin Token used to access the admin panel to make it more secure. You can follow the next steps to migrate over.

  1. Follow the section of the guide to create the Argon2 token, you can use the existing ‘password’ aka admin token for this as it will still be used for the actual admin login screen, Important: when you get to the part that asks you to add the additional $ into the token skip that and come back here.
  2. Stop the Project and then edit the yaml and completely remove the existing ADMIN_TOKEN variable.
  3. Start the container again and login to the admin panel with your usual admin password. Scroll down to the bottom of the General Settings section and paste your Argon2 hash into the Admin token/Argon2 PHC option and save the settings.
  4. Restart the project again, and you will now be using the new hash and can log in with your usual password

Looking for some help, join our Discord community

If you are struggling with any steps in the guides or looking to branch out into other containers join our Discord community!

Buy me a beverage!

If you have found my site useful please consider pinging me a tip as it helps cover the cost of running things or just lets me stay hydrated. Plus 10% goes to the devs of the apps I do guides for every year.

Historic UpdatesDate
New guide Published29/12/2021
Updated with Admin Panel Options30/12/2021
Changed the port number from 8112 to 8122 so it doesn’t conflict with Deluge01/01/2021
Updated screenshots and steps for DSM7.1 17/06/2022
Added new port settings and Docker Bridge Network23/07/2022
Note added about not using gmail/google/ email for setup and a note about a app specific password for yahoo05/12/2022
Compose version number removed and small wording amendments09/04/2023
Amended the path to save the compose file – this is for security, so the container has no access to the file contents.14/04/2023
Update to Admin_Token to use Argon2 Hash24/04/2023
Historic Updates
Published inDockerOther Tools 7.1Synology

123 Comments

  1. S_K_1 S_K_1

    Hi,
    I have Quickconnect enabled on my NAS and everytime I try to connect to my Valut, somehow the port gets remapped from 443 to 5001 (I assume Quickconect is somehow doing this) I have tried switching Quickconnect off, but it still ends up redirecting to 5001 and then timing out.

    • Dr_Frankenstein Dr_Frankenstein

      Hey try this
      Control Panel > Login Portal > Disable Redirect HTTP connections to HTTPS
      Also make sure you are entering HTTPS:// when entering the URL

  2. chris chris

    Great guide! It helped me get Vault Warden running securely after banging my head against the problem for hours. I run a small business and want to allow employees to connect remotely, but following your guide I can only connect locally. Is there any way to connect to https://bitwarden.xxxx.synology.me/ remotely?

    • Dr_Frankenstein Dr_Frankenstein

      Hey Chris, that address should work remotely as well if you did all the steps including the reverse proxy settings. Just leave port 443 Forwarder from your Router to the NAS.

  3. KW KW

    rather than open up my NAS to the internet directly, I’d like to limit use of the local install of bitwarden/vaultwarden to the LAN only. if i need to sync while away, i’d prefer to VPN in and then sync that way.

    the problem i’m having is trying to get the vaultwarden container to be served via SSL to a LAN device. I’ve forced SSL for access to the synology desktop, but i don’t see how to force the synology to run access to the vaultwarden instance through an SSL connection (using a self-signed cert).

    i can manipulate local DNS (router, or even a hosts file) to link (for example) vault.synology to 192.168.xxx.xxx (my sonology LAN ip), so would that work in conjunction with a self-signed cert for vault.synology generated in the Security tab of the Control Center? Would I still need a Reverse Proxy setup linking that to the 192.168.xxx.xxx:vaultPort#?

    thanks for any help. i just feel much safer relying on my vpn setup to manage remote access for syncing to a locally hosted bitwarden vault.

    • KW KW

      well, i posted too soon. i just edited my hosts file as noted abo ve, with the reverse proxy linking that name to the synology IP:portnum, and it allowed me to create an account – which was where the non-ssl connection would block account creation.

      now, on to seeing if i can get the web browser and iOS clients to link to it over the LAN, and then finally to confirm they can link over VPN.

      thanks for the site!

      • KW KW

        Arg. The Bitwarden iOS client doesn’t seem to want to allow a user to login to a server behind a self-signed certificate. Seeing if I can tweak my way through that or not.

        • KW KW

          ha! so, the client will accept a non-https numerical server ip address with port number, at least for now. so, a bit less flexible and harder to config for users, but works. now to test through VPN.

  4. Flavio Flavio

    Hi. Thanks for your article.
    Question: how do you manage to take backups of your vault and eventually save them outside the Synology?

    • Dr_Frankenstein Dr_Frankenstein

      Hey, good question, personally I do a hyperbackup of my Docker share nightly to another NAS and an encrypted one to Storj. It means if there is ever a need to restore the vault I can easily pull back into Docker. I recently used my backup for a migration to another system so it works well.

  5. Ensar Ensar

    hello and thank you for this great tutorials!

    unfortunately i am not able to open ports because of ISP

    do you have any suggestion for me ?

    • Dr_Frankenstein Dr_Frankenstein

      Some ISP’s do have port 443 blocked for inbound connections – make sure they don’t have an option to disable that, I have seen some Australian ISPs who will unblock them in their control panel or by contacting them.

        • Dr_Frankenstein Dr_Frankenstein

          OK so you can try using an alternative port, however you will need to specify that port after the URL when accessing Vaultwarden
          e.g vaultwarden.yourdscloud.dscloud.me:8443
          Have you managed to obtain an SSL certificate at all though? It might be worth jumping on Discord as trying this out via the comments might be tricky as I have not personally done it and can get some others to input. Alternatively posting over on SynoForum.com again good to get some others to input.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

drfrankenstein.co.uk – writing Synology Docker Guides since 2016 – Join My Discord!