Bitwarden Installation
Posted at July 20, 2023 12:07 pm. Last updated at May 08, 2026 03:05 pm
(Possible link may changed. Please update the documentation if there's changes)
(Use root user on doing the scripts)
Docker Installation:
For Debian Here
For Ubuntu Here
Reference Install
Create Bitwarden local user & directory
- Create a bitwarden user:
- sudo adduser bitwarden
- Set password for bitwarden user (strong password):
- sudo passwd
- Create a docker group (if it doesn’t already exist):
- sudo groupadd docker
- Add the bitwarden user to the docker group:
- sudo usermod -aG docker bitwarden
- .Create a bitwarden directory:
- sudo mkdir /opt/bitwarden
- Set permissions for the /opt/bitwarden directory:
- sudo chmod -R 700 /opt/bitwarden
- Set the bitwarden user as owner of the /opt/bitwarden directory:
- sudo chown -R bitwarden:bitwarden /opt/bitwarden
Downloading Bitwarden Scripts
- Download the Bitwarden installation script (bitwarden.sh) to your machine:
- curl -Lso bitwarden.sh "https://func.bitwarden.com/api/dl/?app=self-host&platform=linux" && chmod 700 bitwarden.sh
- If new bitwarden.sh will failed on Bitbetter use the old bitwarden.sh (2023.5.1) then apply chmod 700 bitwarden.sh Here (X:\SHARES\IT\Bitwarden\Script) or here
- Run the installer script. A ./bwdata directory will be created relative to the location of bitwarden.sh.
- ./bitwarden.sh install
- Complete the prompts in the installer:
- Enter the domain name for your Bitwarden instance:
- enter url
- In my case I use CloudFlare tunneling Here
- Do you want to use Let's Encrypt to generate a free SSL certificate? (y/n):
- y
- Database name:
- vault
- Enter your installation id:
- Get on Old Bitwarden () or create new Here (f4738808-723e-4750-9cd8-aca800c0079c)
- Enter your installation key:
- Get on Old Bitwarden () or create new Here (aDY7xhWKeVytuIhmi3Ua)
- Do you have a SSL certificate to use? (y/n):
- y
- Do you want to generate a self-signed SSL certificate? (y/n):
- y
- enter url
- Enter the domain name for your Bitwarden instance:
Post-install configuration
- Update global.override.env
- ./bwdata/env/global.override.env
- Update these following text
globalSettings__mail__replyToEmail=support@awaste.com.au
globalSettings__mail__smtp__host=awm-hq-mail.austwaste.org
globalSettings__mail__smtp__port=25
globalSettings__mail__smtp__ssl=false
globalSettings__mail__smtp__username=
globalSettings__mail__smtp__password=
-
Restart Bitwarden
-
./bitwarden.sh restart
-
-
After this procedure make sure the Bitwarden is Running Correctly if Yes take a snapshot of the VM then Proceed to the next Step
Modifying Database (If not modifying the database Proceed to Bitbetter Update)
- Copy the database to Bitwarden server thru FTP
- docker cp ./vault_FULL_20230630_000000.BAK (DBname) bitwarden-mssql:/etc/bitwarden/mssql/backups/vault_FULL_20230630_000000.BAK (DBname)
- Restore backup in this case sometimes using old database (vault) is working sometimes it causing a issue this is a trial error procedure snapshot is important
- Open Bitwarden-Mssql
- docker exec -it bitwarden-mssql /bin/bash
- Connect to SQL
- /opt/mssql-tools/bin/sqlcmd -S localhost -U sa -P Password
- Backup old DB
- Backup Database vault to disk = '/etc/bitwarden/mssql/backups/vault_FULL_20230720_000000.BAK'
- Go
- Restore the old database (vault_FULL_YYYYMMDD_000000.BAK is a file name changed it )
- Open Bitwarden-Mssql
1> use master
2> GO
1> alter database vault set offline with rollback immediate
2> GO
1> restore database vault from disk='/etc/bitwarden/mssql/backups/vault_FULL_YYYYMMDD_000000.BAK' with replace
2> GO
1> alter database vault set online
2> GO
1> exit
Restart Bitwarden and Test the Functionality, Check Also Vaults
Restoring New Database (If not modifying the database Proceed to Bitbetter Update)
- Copy the database to Bitwarden server thru FTP
- docker cp ./vault_FULL_20230630_000000.BAK (DBname) bitwarden-mssql:/etc/bitwarden/mssql/backups/vault_FULL_20230630_000000.BAK (DBname)
- Restore backup in this case sometimes using old database (vault) is working sometimes it causing a issue this is a trial error procedure snapshot is important
- Open Bitwarden-Mssql
- docker exec -it bitwarden-mssql /bin/bash
- Connect to SQL
- /opt/mssql-tools/bin/sqlcmd -S localhost -U sa -P Password
- Backup old DB
- Backup Database vault to disk = '/etc/bitwarden/mssql/backups/vault_FULL_20230720_000000.BAK'
- Go
- Restore the old database (vault_FULL_YYYYMMDD_000000.BAK is a file name changed it
- Open Bitwarden-Mssql
1> use master
2> GO
1> restore database vault_bw from disk='/etc/bitwarden/mssql/backups/vault_FULL_20230630_000000.BAK' with FILE = 1, MOVE 'vault' to '/var/opt/mssql/data/vault_bw.mdf', MOVE 'Vault_log' to '/var/opt/mssql/data/vault_bw_log.ldf'
2> GO
1> exit
- Update global.override.env
- Change DB name
- Restart Bitwarden and Test the Functionality, Check Also Vaults
Modify Backup Task
If the database is changed from the global.override.env we will need to update the backup task
- Copy the backup-db.sql from docker container to local files
- docker cp bitwarden-mssql:./backup-db.sql backup-db.sql
- Update the backup-db.sql
- nano backup-db.sql
- Change @DatabaseName value (possible Line 3)
- Change @DatabaseNameSafe value (possible Line 7)
- Copy back the sql script to docker container
- docker cp backup-db.sql bitwarden-mssql:./backup-db.sql
- Open Bitwarden-mssql
- docker exec -it bitwarden-mssql /bin/bash
- Test the script
- run ./backup-db.sh
- check the backups if they successfully created
- /etc/bitwarden/mssql/backups/
Modifying to Bitbetter
Before proceeding in this step you should take a snapshot of VM first
BitBetter is is a tool to modify Bitwarden's core dll to allow you to generate your own individual and organisation licenses. You must have an existing installation of Bitwarden for BitBetter to modify.
Please see the FAQ below for details on why this software was created.
Beware! BitBetter does janky stuff to rewrite the bitwarden core dll and allow the installation of a self signed certificate. Use at your own risk!
Dependencies
Aside from docker, which you also need for Bitwarden, BitBetter requires the following:
- Bitwarden (tested with 1.47.1, might work on lower versions)
- openssl (probably already installed on most Linux or WSL systems, any version should work)
Setting up BitBetter
- Download
- git clone https://github.com/jakeswenson/BitBetter.git
- Building
- cd BitBetter
- ./build.sh
- Configuration and code changes
- Create or Update the docker-compose.override.yml
- nano /path/bwdata/docker/docker-compose.override.yml
- Create or Update the docker-compose.override.yml
version: '3'
services:
api:
image: bitbetter/api
identity:
image: bitbetter/identity
- Update run.sh
- nano /path/to/bwdata/scripts/run.sh
- In the function restart() block, comment out the call to dockerComposePull.
- Replace dockerComposePull with #dockerComposePull
- Updating Bitwarden and BitBetter
It will rebuild the BitBetter images and automatically update Bitwarden afterwards. Docker pull errors can be ignored for api and identity images.
-
./update-bitwarden.sh param1 (bwdata directory) param2 (If you want the docker-compose file to be overwritten) param3 (If you want the bitbetter images to be rebuild )
- ./update-bitwarden.sh /home/serveradmin/ y y
-
Generating Signed Licenses
-
Go to src/licenseGen/
-
run ./build.sh
-
Note in this part is usually the errors occurs just repeat the steps if you you have the issues
-
-
Ways to Generate License
-
./src/licenseGen/run.sh /Absolute/Path/To/BitBetter/.keys/cert.pfx interactive
-
This will ask chose User or Organization
-
For Organization
-
Installation key
-
Organization
-
Username
-
Email
-
Size
-
-
Copy the json code then save then apply on the Bitwarden
-
And save it as json file
-
-
Applying Generated License
-
Go to Organization
-
On the dropdown click the Organization wants to update or create new
-
Upload the license created (json)
-
Click Submit
-
-
Updating Organization for new Version
-
Go to Admin Console
-
-
-
Add Portainer to Access docker applications to network
-
Run this command
-
docker run -d -p 8000:8000 -p 9000:9000 --name=portainer --restart=always -v /var/run/docker.sock:/var/run/docker.sock -v portainer_data:/data portainer/portainer-ce
-
Bitwarden install reference Here
BitBetter update reference Here
***Backup Files of current bitwarden were stored on X:\SHARES\IT\Bitwarden\Script zip credential are place on Bitwarden Password Manager (Secure Notes)
Comments