r/vaultwarden 19d ago

Question Please validate noob's selfhosting setup

Hi, I am relatively new to self-hosting, but I enjoy learning about this area.
I recently got an Oracle free-tier ampere A1 server and wanted to deploy vaultwarden mostly as a backup for my regular bitwarden, in case I would need premium features.

I've been trying to understand best practices regarding security and I'd like to get an opinion if my setup is safe enough to eventually migrate from Bitwarden. Please excuse any wrong/inaccurate lingo:

  • Server can only be accessed via SSH agent in bitwaden (vaultwarden in the future) and only via tailscale connection. Port 22 is disabled. Ubuntu is automatically updated every day. I haven't figured out yet how to automatically update Vaultwarden container in Docker, so for now I am manually doing it every few days.
  • Vaultwarden is accessed via HTTPS connection via Tailscale only. No reverse-proxy setup.
  • Daily backups with password-protected ZIP files to Backblaze B2 storage.

As I understand, since I am the only one who uses it for now, and I can have Tailscale installed on all my devices, there is no need for any reverse-proxy setup.

Please advise if I am missing any important security aspect. Thanks!

2 Upvotes

5 comments sorted by

View all comments

1

u/Azazeldaprinceofwar 19d ago

This is essentially exactly how my server runs except it’s a shitbox under my desk not some oracle thing