From 3646f040c4b5b908dcc3e439e4c2f9a3f5b6cbb2 Mon Sep 17 00:00:00 2001 From: alex Date: Sat, 11 Oct 2025 19:37:55 +0200 Subject: [PATCH] Restrict Vaultwarden users --- infrastructure/roles/vaultwarden/tasks/main.yaml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/infrastructure/roles/vaultwarden/tasks/main.yaml b/infrastructure/roles/vaultwarden/tasks/main.yaml index 746696e..96eb64f 100644 --- a/infrastructure/roles/vaultwarden/tasks/main.yaml +++ b/infrastructure/roles/vaultwarden/tasks/main.yaml @@ -11,7 +11,7 @@ Exec=/start.sh EnvironmentFile=vaultwarden.environment Volume=/var/lib/vaultwarden/:/data/ - PublishPort=127.0.0.1:8080:80 + Network=host [Install] WantedBy=default.target @@ -23,6 +23,13 @@ dest: /etc/containers/systemd/vaultwarden.environment content: | DOMAIN=https://{{ public_hostname }}/vaultwarden + SIGNUPS_DOMAINS_WHITELIST=localhost + SIGNUPS_VERIFY=true + SMTP_HOST=localhost + SMTP_FROM=vaultwarden@localhost + SMTP_SECURITY=off + ROCKET_ADDRESS=127.0.0.1 + ROCKET_PORT=8080 notify: - restart quadlet - name: create storage -- 2.47.3