All your services should be using https. Vaultwarden in particular won’t even run without https unless you bypass a bunch of security measures.
This is how to setup local only and external https, I highly recommend this as a baseline setup for every homelab. It allows you to choose how much security you want on a per app basis and makes adding new apps trivially easy.
Vaultwarden ftw
+1 for a self-hosted Vaultwarden instance. If you’re technically capable and have extra hardware laying around this is the best way to go.
Although a backup is still required or you are gambling on hardware outliving your need for your data.
100%. Make sure to follow the 3-2-1 backup rule with all things you do.
Anyone with the knowledge to self host will quickly discover 3-2-1. If they choose to follow it, that’s on them but data loss won’t be from ignorance
Exactly! Self hosted FTW. Chances of a data breach… Typically pretty minor if you are smart.
Keep vaultwarden behind wireguard for local only access then also use https certs and good master password. Very secure like this
Why https if the traffic is already encrypted by the vpn?
Security in layers.
All your services should be using https. Vaultwarden in particular won’t even run without https unless you bypass a bunch of security measures.
This is how to setup local only and external https, I highly recommend this as a baseline setup for every homelab. It allows you to choose how much security you want on a per app basis and makes adding new apps trivially easy.
https://youtu.be/liV3c9m_OX8?si=TSWXoN_8SJDpAHaW