services: vaultwarden: # Pin the exact version; read the release notes before bumping — Bitwarden # client updates sometimes require a newer server. # https://github.com/dani-garcia/vaultwarden/releases image: vaultwarden/server:1.37.3 container_name: vaultwarden restart: unless-stopped # No published ports: only reachable through NPM on the shared `proxy` # network, so there is no plain-HTTP path to the vault. networks: - proxy environment: TZ: Europe/Vienna DOMAIN: "https://vault.home.staffenberger.at" # true only until both accounts exist, then false + `docker compose up -d`. SIGNUPS_ALLOWED: "true" SHOW_PASSWORD_HINT: "false" # No ADMIN_TOKEN: the /admin page stays disabled. volumes: # Database, attachments and the server's RSA key — back up encrypted, # never commit. - ./data:/data networks: proxy: external: true