Simple Docker container for automated Vaultwarden SQLite backups with optional GPG encryption.
1.8K
Simple Docker container for automated Vaultwarden SQLite backups with optional GPG encryption, cron scheduling, and retention policy.
db.sqlite3 using SQLite .backup (safe during operation)config.jsonrsa_key.pem)attachments/ and sends/ directories.tar.gzKEEP)| Variable | Default | Description |
|---|---|---|
DATA_DIR | /data | Path to Vaultwarden data directory |
BACKUP_DIR | /backup | Path where backups will be saved |
ARCHIVE_PREFIX | vaultwarden-backup | Prefix for the archive filename |
ENABLE_GPG | false | Enable GPG encryption (true/false) |
GPG_RECIPIENT | (empty) | Email or ID of GPG recipient |
GPG_KEY_FILE | (empty) | Path to GPG public key .asc file inside the container |
CRON_SCHEDULE | 0 3 * * * | Cron expression to run backup |
KEEP | 5 | Number of recent backups to retain (e.g., 5) |
TZ | UTC | Timezone setting (e.g., Europe/Prague) |
docker run -d \
-v /host/vaultwarden-data:/data:ro \
-v /host/backup:/backup \
-v /host/public.asc:/keys/public.asc:ro \
-e ENABLE_GPG=true \
-e [email protected] \
-e GPG_KEY_FILE=/keys/public.asc \
-e CRON_SCHEDULE="0 3 * * *" \
-e KEEP=5 \
-e TZ=Europe/Prague \
omfo/vaultwarden-backup:latest
Generate a GPG key on your system:
gpg --full-generate-key
Export the public key:
gpg --export -a "[email protected]" > public.asc
Mount the key into the container (/keys/public.asc)
Set the variables:
ENABLE_GPG=trueGPG_KEY_FILE=/keys/public.asc[email protected]💡 Keep your private key secure — you’ll need it to decrypt the archive.
Backup files are named:
vaultwarden-backup-YYYY-MM-DD_HH-MM.tar.gz
With encryption enabled:
vaultwarden-backup-YYYY-MM-DD_HH-MM.tar.gz.gpg
All logs are printed to STDOUT so they are visible in container logs.
Content type
Image
Digest
sha256:28e1896a0…
Size
13.3 MB
Last updated
over 1 year ago
docker pull omfo/vaultwarden-backup