Phase 6 — Vaultwarden host, password vault with no open ports

Phase 6 — Vaultwarden host, password vault with no open ports A architecture diagram generated by Archify. GCP e2-micro · deny-all firewall Vault user · HTTPS · Architecture component Vault user HTTPS Cloudflare edge · vault.sreeramkr.com · Architecture component Cloudflare edge vault.sreeramkr.com cloudflared · outbound tunnel · GCP e2-micro · deny-all firewall cloudflared outbound tunnel Vaultwarden · loopback :8000 · GCP e2-micro · deny-all firewall Vaultwarden loopback :8000 SQLite · vw-data · GCP e2-micro · deny-all firewall SQLite vw-data backup.sh · nightly 03:00 · GCP e2-micro · deny-all firewall backup.sh nightly 03:00 GCS bucket · private · Architecture component GCS bucket private HTTPS tunnel state dump upload Legend Backend Database Cloud External

Ingress

  • • Only vault.sreeramkr.com via the tunnel
  • • Vaultwarden binds loopback :8000

Data

  • • State in SQLite (vw-data)
  • • Nightly backup to a private GCS bucket

Access

  • • Admin is IAP-only SSH
  • • CI writes a 0600 .env over IAP