Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For an official Bitwarden self-hosted server on Ubuntu 24.04 or 22.04, use Bitwarden’s Linux Standard Deployment. Its installation script generates and manages the Docker deployment; you do not need to copy an unofficial Compose file. Plan for a domain, TCP ports 80 and 443, HTTPS, Bitwarden installation credentials, and ongoing responsibility for SMTP, updates, backups, and recovery.

This guide uses the standard multi-container deployment, suitable for organizations and general-purpose installations. If you only need a personal home-lab server, see the distinction between Standard and Bitwarden lite below before installing.

Before you begin

Docker’s Ubuntu installation guide lists both Ubuntu 22.04 LTS (Jammy) and 24.04 LTS (Noble) as supported releases. Bitwarden’s hosting guidance requires a host operating system that remains under active mainstream support from its vendor, so keep Ubuntu and the deployment current. This is not a separate Bitwarden certification of each Ubuntu release. See Docker’s Ubuntu requirements and Bitwarden’s hosting FAQs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Resource Minimum Recommended
CPU x64, 1.4 GHz x64, 2 GHz dual-core
RAM 2 GB 4 GB
Storage 12 GB 25 GB
Docker Engine 26+ and Compose plugin Current supported Engine and Compose plugin

For a production-style installation, use the recommended resources rather than treating the minimums as a comfortable target. You will also need SSH or console access, a sudo-capable account, a DNS name such as vault.example.com, Bitwarden installation ID and key, and an SMTP relay if users need verification emails or organizations need invitations.

Set an A record for the hostname to the server’s IPv4 address. Add an AAAA record only when IPv6 works end-to-end; a broken IPv6 route can cause clients to reach the wrong path. Bitwarden’s standard deployment uses TCP 80 and 443 by default, and its networking guidance says both are required. Configure both the host firewall and any cloud firewall or router. Review Bitwarden’s networking requirements.

Self-hosting gives you control of the infrastructure and data location, but also makes you responsible for patching, availability, DNS, TLS, monitoring, backups, and disaster recovery. If that operational burden is not worth the control, Bitwarden Cloud may be a better fit.

Choose the right Bitwarden deployment

Deployment Best for What to know
Linux Standard Deployment Most Ubuntu users, including organizations Official multi-container deployment managed by bitwarden.sh.
Linux Manual Deployment Advanced administrators integrating with an existing Docker workflow You manage Compose files, environment changes, and upgrade adjustments yourself. Bitwarden labels it for advanced users; see the manual deployment guide.
Bitwarden lite Personal use, home labs, ARM or NAS devices Single-container deployment with a smaller footprint; Bitwarden describes it as unsuitable for business contexts. See the lite guide.
Vaultwarden People specifically seeking an unofficial compatible alternative It is not the official Bitwarden server. Client compatibility and support are not guaranteed by Bitwarden.

The standard deployment uses MSSQL Express by default; Bitwarden documents a 10 GB maximum relational database size for that default database. An external MSSQL server is an option when needed. Bitwarden lite, renamed from Unified in December 2025, uses the ghcr.io/bitwarden/lite image and supports several database choices, but it is a separate deployment path—not a lighter setting to mix into these instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Update Ubuntu

sudo apt update
sudo apt full-upgrade -y
sudo reboot

A reboot is a safe default after a fresh server update, particularly if the kernel changed. If no update requires a restart, it may not be necessary.

2. Install Docker Engine from Docker’s APT repository

Use Docker’s official repository rather than its convenience script for a production server; Docker describes that script as primarily for testing and development. The commands below install Docker Engine, CLI, containerd, Buildx, and the Compose plugin.

sudo apt update
sudo apt install -y ca-certificates curl

sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL 
  https://download.docker.com/linux/ubuntu/gpg 
  -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

sudo tee /etc/apt/sources.list.d/docker.sources > /dev/null <<EOF
Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: $(. /etc/os-release && echo "${UBUNTU_CODENAME:-$VERSION_CODENAME}")
Components: stable
Architectures: $(dpkg --print-architecture)
Signed-By: /etc/apt/keyrings/docker.asc
EOF

sudo apt update
sudo apt install -y 
  docker-ce 
  docker-ce-cli 
  containerd.io 
  docker-buildx-plugin 
  docker-compose-plugin

Enable Docker and verify that the daemon, test container, and Compose plugin work:

sudo systemctl enable --now docker
sudo systemctl status docker --no-pager
sudo docker run hello-world
docker compose version

Refer to Docker’s current Ubuntu installation guide if repository setup or package availability differs on your host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Create the dedicated Bitwarden service account

Bitwarden recommends installing and running the deployment as a dedicated bitwarden user, not root. Docker group membership is effectively root-equivalent: a user who can control Docker can often mount and change host files. Grant it only to an account you trust.

sudo adduser bitwarden
getent group docker || sudo groupadd docker
sudo usermod -aG docker bitwarden
sudo mkdir -p /opt/bitwarden
sudo chmod 700 /opt/bitwarden
sudo chown bitwarden:bitwarden /opt/bitwarden

Start a fresh login session so the supplementary Docker group takes effect, then check access:

su - bitwarden
docker ps

If you get a permission error, reconnect or start a fresh bitwarden login session. Do not work around it by running the Bitwarden installer as root.

4. Configure DNS and network access

Use the exact fully qualified domain name that users will enter, for example vault.example.com, and ensure it resolves to this server. Open inbound TCP 80 and 443 in UFW if enabled, and in any upstream cloud firewall or router. For UFW, a typical rule set is:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw status verbose

Only apply UFW rules if you understand the effect on your existing remote-access rules; do not lock out SSH. Avoid adding an IPv6 DNS record until its routing and firewall path are ready. Bitwarden recommends a domain name and suggests avoiding a hostname that visibly includes “Bitwarden”; that is a preference, not a technical requirement.

If you use a reverse proxy, it must support WebSockets and pass the Host header through unchanged. Do not restrict HTTP verbs or alter request bodies or authentication headers. See the networking requirements before putting a proxy in front of the server.

5. Get the Bitwarden installation ID and key

As the administrator, obtain the installation ID and key at bitwarden.com/host. Choose the appropriate US or EU region. The values register the installation and support push-relay and paid-feature validation; treat them as secrets, do not reuse them across installations, and do not put them in screenshots, Git repositories, shell history, or public support posts.

6. Download and run the official installer

As the bitwarden account, install under /opt/bitwarden:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
cd /opt/bitwarden
curl -Lso bitwarden.sh 
  "https://func.bitwarden.com/api/dl/?app=self-host&platform=linux"
chmod 700 bitwarden.sh
./bitwarden.sh install

The script downloads Bitwarden’s Linux Standard Deployment installer. It creates a bwdata directory beside bitwarden.sh and generates the Docker deployment files there.

Answer the installer prompts

  • Domain: Enter the FQDN that matches DNS and the certificate, such as vault.example.com.
  • Let’s Encrypt: Choose yes only when DNS points to this server and the required validation path, including port 80, is reachable. Otherwise choose no and arrange a supported certificate or HTTPS reverse proxy. Certificate issuance is not guaranteed across every network topology.
  • Installation ID and key: Enter the credentials from bitwarden.com/host.
  • Region: Select US or EU to match the account or organization region associated with relevant paid features.
  • Existing certificate: If supplying one, Bitwarden expects the required files beneath ./bwdata/ssl/your.domain. Follow the current deployment guide for exact filenames and certificate options rather than guessing.

Use HTTPS for production. A self-signed certificate is suitable only for testing. Without a certificate configured on the deployment, place it behind a properly configured HTTPS proxy; Bitwarden applications will not function correctly over an unprotected production setup.

7. Configure SMTP and administrator access

Edit the override file using an editor:

nano /opt/bitwarden/bwdata/env/global.override.env

Set the SMTP values supplied by your email provider:

globalSettings__mail__smtp__host=<smtp-host>
globalSettings__mail__smtp__port=<smtp-port>
globalSettings__mail__smtp__ssl=<true-or-false>
globalSettings__mail__smtp__username=<smtp-username>
globalSettings__mail__smtp__password=<smtp-password>

To provision access to the System Administrator Portal, add an address you control:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
[email protected]

SMTP is needed for user verification emails and organization invitations. Confirm the correct TLS mode and sender requirements with your provider; do not assume that the port alone determines whether SSL should be true. Protect this file because it contains credentials, and never commit it to source control. Apply configuration changes by restarting the deployment:

cd /opt/bitwarden
./bitwarden.sh restart

8. Start the server and verify it

cd /opt/bitwarden
./bitwarden.sh start
docker ps

The first start can take a while while Docker pulls the required images from GitHub Container Registry. Confirm the containers are running and that health checks, where provided, become healthy. Then open https://vault.example.com in a browser. Test account verification as well as loading the vault; a working login page does not prove SMTP is configured correctly.

Operate the deployment

Run these commands from /opt/bitwarden as the bitwarden user. The script is the supported control path; avoid bypassing it with an improvised Compose command.

Command Use
./bitwarden.sh start Start the containers.
./bitwarden.sh stop Stop the containers.
./bitwarden.sh restart Restart after configuration changes or as needed.
./bitwarden.sh update Update containers and database.
./bitwarden.sh rebuild Regenerate installation assets from config.yml.
./bitwarden.sh renewcert Renew certificates.
./bitwarden.sh compresslogs Export server logs.
./bitwarden.sh help Show available commands.

Take and verify a backup before updates, especially major ones. Self-hosted updates may appear several days after a cloud release, so a notice does not necessarily mean the update is immediately available for the self-hosted deployment. Check the current guide and hosting FAQs for update timing and behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Back up for recovery, not just compliance

Bitwarden documents automated nightly backups of the bitwarden-mssql database container, but that is not a complete disaster-recovery plan. You also need a protected copy of the deployment’s data and configuration, certificates where applicable, installation ID and key, and the information needed to recreate DNS, firewall, and SMTP settings.

  • Follow Bitwarden’s official backup and restore guidance; do not rely on a generic archive command in place of its documented database procedure.
  • Encrypt backups, restrict access, and store a copy away from the server.
  • Test restoration on a separate host before you depend on the backup.
  • Keep a written record of the domain, DNS, SMTP, firewall, and deployment details, stored securely.
  • Encourage users to maintain an emergency export procedure appropriate to their threat model.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common problems

Docker says permission denied

The current shell may predate Docker-group membership. Log out and back in, or run su - bitwarden, then check docker ps. Do not run the deployment as root to mask a permissions issue.

docker compose is not found

Check docker compose version and verify the docker-compose-plugin package is installed. The current Docker method uses the Compose plugin and the command with a space; do not assume the older standalone docker-compose binary is present.

Domain validation or HTTPS fails

Check DNS, firewall rules, and whether another service already owns ports 80 or 443. Also confirm that the installer hostname matches the requested certificate name, the system clock is correct, and any IPv6 record has working routing. Useful diagnostics include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
dig +short vault.example.com
sudo ss -tulpn
sudo ufw status verbose
curl -I http://vault.example.com
curl -I https://vault.example.com

Bitwarden warns that mixing HTTP and HTTPS access can cause connection, authentication, and synchronization errors; use the same HTTPS hostname consistently.

Containers run, but the vault will not load

Inspect generated deployment status and logs rather than replacing Bitwarden’s generated setup with a generic Compose command:

docker ps
docker compose -f /opt/bitwarden/bwdata/docker/docker-compose.yml ps
docker logs <container-name>

Use the actual container name shown by docker ps. If the host has another web server or a proxy, verify it is not intercepting requests and that proxy settings meet Bitwarden’s networking requirements.

Synchronization or login breaks behind a proxy

Ensure WebSockets are enabled, the Host header is forwarded unchanged, HTTPS is consistent, HTTP verbs are not filtered, and request bodies or authentication headers are not altered. Consult Bitwarden’s reverse-proxy and networking guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verification email does not arrive

Recheck SMTP host, port, credentials, and SSL setting; provider-side sender restrictions; outbound firewall access; and relevant email DNS such as SPF, DKIM, and DMARC. Review Bitwarden logs and confirm the server is configured with an SMTP relay. Providers such as Mailgun and SparkPost are examples in Bitwarden’s hosting FAQs; confirm their current terms and settings directly.

Which option should you use?

Choose the official Standard Deployment when you need the supported general-purpose, multi-container Bitwarden server and are willing to maintain it. Choose Bitwarden lite for a lightweight personal or home-lab setup, including suitable ARM devices; it is not the recommended business path. Choose Vaultwarden only if you explicitly accept a non-official implementation and its compatibility and support limitations. Choose Bitwarden Cloud if you want to avoid administering a security-critical service. Self-hosting does not automatically make every feature or organization plan free; check current Bitwarden plans.

For private-only access, a mesh VPN such as Tailscale can be considered, but it does not replace Bitwarden, TLS planning, backups, or server maintenance, and clients must be able to reach that private network. If you need a VPS, compare live provider offerings rather than relying on a stale monthly price: Bitwarden links a DigitalOcean deployment path, and Hetzner Cloud is another infrastructure option to assess for your location and support needs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.