fukuops/k8s/charts/vaultwarden
cătălin 1fd2bfef3d
feat(helm): complete chart normalization with ConfigMap, HPA, and OCI migration
- Added debug mode, structured ConfigMap pattern, and README to all charts
- Migrated all flat-structure charts to hierarchical values under chartname key
- Fixed templates to use correct hierarchical paths
- Renamed helm-rustical key to rustical, added HPA support
- Fixed ingress YAML parsing (oxicloud), nested env vars (rustical)
- Pushed all normalized charts to OCI registry as 1.0.0+ and updated ArgoCD apps
2026-08-14 09:35:19 +02:00
..
templates feat(helm): complete chart normalization with ConfigMap, HPA, and OCI migration 2026-08-14 09:35:19 +02:00
Chart.yaml feat(helm): complete chart normalization with ConfigMap, HPA, and OCI migration 2026-08-14 09:35:19 +02:00
README.md feat(helm): complete chart normalization with ConfigMap, HPA, and OCI migration 2026-08-14 09:35:19 +02:00
values.yaml feat(helm): complete chart normalization with ConfigMap, HPA, and OCI migration 2026-08-14 09:35:19 +02:00

vaultwarden

A Helm chart for Vaultwarden (formerly Bitwarden RS), a lightweight self-hosted password manager.

TL;DR

helm install vaultwarden oci://git.roboces.dev/catalin/fukuops/vaultwarden --version 1.0.2 -n apps-roboces

Prerequisites

  • Kubernetes 1.19+
  • Helm 3+
  • A NFS storage class (default: truenas-nfs-csi)
  • An existing Secret containing:
    • DATABASE_URL (if using external database)
    • ADMIN_TOKEN (optional - for admin panel)
    • SMTP_HOST and related SMTP settings (optional - for email)

Configuration

All values are nested under the vaultwarden: key. Example:

vaultwarden:
  persistence:
    enabled: true
    storageClass: "truenas-nfs-csi"
    accessMode: ReadWriteMany
    size: 5Gi
  service:
    type: ClusterIP
    port: 80
  secret:
    existingSecretName: vaultwarden-kubernetes-secrets
  config:
    database:
      url: ""
      enableWal: true
      connectionRetries: 15
    webVault:
      enabled: true

Values Reference

Key Type Default Description
vaultwarden.replicaCount int 1 Number of replicas
vaultwarden.image.repository string vaultwarden/server Image repository
vaultwarden.image.pullpolicy string Always Image pull policy
vaultwarden.image.tag string .Chart.AppVersion Image tag
vaultwarden.service.type string ClusterIP Service type
vaultwarden.service.port int 80 Service port
vaultwarden.service.targetPort int 80 Container port
vaultwarden.ingress.enabled bool false Enable ingress
vaultwarden.config.database.url string "" Database connection URL
vaultwarden.config.database.enableWal bool true Enable WAL mode
vaultwarden.config.database.connectionRetries int 15 Connection retries
vaultwarden.config.database.timeout int 30 Connection timeout
vaultwarden.config.database.idleTimeout int 600 Idle timeout
vaultwarden.config.webVault.enabled bool true Enable web vault
vaultwarden.persistence.enabled bool true Enable persistence
vaultwarden.persistence.storageClass string truenas-nfs-csi Storage class
vaultwarden.persistence.accessMode string ReadWriteMany Access mode
vaultwarden.persistence.size string 5Gi PVC size
vaultwarden.secret.existingSecretName string vaultwarden-kubernetes-secrets Existing secret name
vaultwarden.debug.enabled bool false Enable debug mode (adds init container for troubleshooting)
vaultwarden.resources object {} Container resources
vaultwarden.livenessProbe object (see values.yaml) Liveness probe
vaultwarden.readinessProbe object (see values.yaml) Readiness probe

ConfigMap

The chart creates a ConfigMap with database and web vault environment variables:

  • DATABASE_URL
  • DB_ENABLE_WAL
  • DB_CONNECTION_RETRIES
  • DB_TIMEOUT
  • DB_IDLE_TIMEOUT
  • WEB_VAULT_ENABLED
  • WEB_VAULT_FOLDER

Persistence

The chart creates a PVC named vaultwarden-data. The PVC uses the truenas-nfs-csi storage class by default with ReadWriteMany access mode.

Secret Management

The chart looks for an existing Secret with the name specified in vaultwarden.secret.existingSecretName. Required/optional secret keys depend on configuration:

  • DATABASE_URL - External database connection (if not using built-in SQLite)
  • ADMIN_TOKEN - Admin panel access token
  • SMTP_HOST, SMTP_PORT, SMTP_FROM, SMTP_USER, SMTP_PASS - Email configuration

Troubleshooting

Debug Mode

Enable debug mode to troubleshoot issues by adding an init container with a shell:

vaultwarden:
  debug:
    enabled: true

This adds an alpine:3.19 init container with sleep infinity that mounts all volumes and inherits env vars. You can exec into it to inspect the environment:

kubectl exec -it <pod-name> -c debug -- sh

When debug mode is enabled, liveness and readiness probes are disabled to prevent restarts.

Pod not starting

kubectl get pvc -n apps-roboces -l app.kubernetes.io/name=vaultwarden

Check logs

kubectl logs vaultwarden-0 -n apps-roboces

Verify configmap

kubectl get configmap vaultwarden-config -n apps-roboces -o yaml