Sign inSign up

omfo/vaultwarden-backup

By omfo

•Updated over 1 year ago

Simple Docker container for automated Vaultwarden SQLite backups with optional GPG encryption.

Image
Security
0

1.8K

omfo/vaultwarden-backup repository overview

⁠Vaultwarden Backup (SQLite)

Simple Docker container for automated Vaultwarden SQLite backups with optional GPG encryption, cron scheduling, and retention policy.


⁠🔧 Features

  • Backs up:
    • db.sqlite3 using SQLite .backup (safe during operation)
    • config.json
    • RSA keys (e.g., rsa_key.pem)
    • attachments/ and sends/ directories
  • Archives as .tar.gz
  • Optional GPG encryption
  • Configurable retention policy (KEEP)
  • Cron support for scheduling
  • Customizable timezone

⁠📦 Environment Variables

VariableDefaultDescription
DATA_DIR/dataPath to Vaultwarden data directory
BACKUP_DIR/backupPath where backups will be saved
ARCHIVE_PREFIXvaultwarden-backupPrefix for the archive filename
ENABLE_GPGfalseEnable GPG encryption (true/false)
GPG_RECIPIENT(empty)Email or ID of GPG recipient
GPG_KEY_FILE(empty)Path to GPG public key .asc file inside the container
CRON_SCHEDULE0 3 * * *Cron expression to run backup
KEEP5Number of recent backups to retain (e.g., 5)
TZUTCTimezone setting (e.g., Europe/Prague)

⁠▶️ Example Usage

docker run -d \
  -v /host/vaultwarden-data:/data:ro \
  -v /host/backup:/backup \
  -v /host/public.asc:/keys/public.asc:ro \
  -e ENABLE_GPG=true \
  -e [email protected] \
  -e GPG_KEY_FILE=/keys/public.asc \
  -e CRON_SCHEDULE="0 3 * * *" \
  -e KEEP=5 \
  -e TZ=Europe/Prague \
  omfo/vaultwarden-backup:latest

⁠🔐 GPG Encryption

  1. Generate a GPG key on your system:
    gpg --full-generate-key

  2. Export the public key:
    gpg --export -a "[email protected]" > public.asc

  3. Mount the key into the container (/keys/public.asc)

  4. Set the variables:

💡 Keep your private key secure — you’ll need it to decrypt the archive.


⁠📂 Output

Backup files are named:

vaultwarden-backup-YYYY-MM-DD_HH-MM.tar.gz

With encryption enabled:

vaultwarden-backup-YYYY-MM-DD_HH-MM.tar.gz.gpg

All logs are printed to STDOUT so they are visible in container logs.

Tag summary

Content type

Image

Digest

sha256:28e1896a0…

Size

13.3 MB

Last updated

over 1 year ago

docker pull omfo/vaultwarden-backup