# Running highly-available Vaultwarden

**URL:** <https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285>\
**Category:** Feature Requests\
**Created:** [January 25, 2024, 2:13am UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285 "2024-01-25T02:13:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![guerzon](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@guerzon](https://vaultwarden.discourse.group/u/guerzon)\
**Post date:** [January 25, 2024, 2:13am UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/1 "2024-01-25T02:13:32Z")

</div>

Hello!

I’m Lester, the maintainer of the Vaultwarden Helm chart [https://github.com/guerzon/vaultwarden](https://github.com/guerzon/vaultwarden).

I keep getting approached by users who want to run multiple replicas of Vaultwarden in Kubernetes. I would like to reopen the discussion about running multiple replicas of Vaultwarden, specifically to discuss the current blockers for running Vaultwarden in Kubernetes.

1. Database - I believe there will be no issue with the database (at least in PostgreSQL).
2. Data directory containing the attachments, icons cache, and temporary files - would be great if we can use S3. Most Kubernetes users either have no way of using a shared filesystem such as NFS or are simply against it. Currently haven’t found any PR and feature requests to add S3 support.
3. ?

Anything else I’m missing?

I am aware of the workaround to disable icons and attachments, but these features might still be important to some organizations.

I would raise a feature request based on this discussion.

Thanks in advance,  
Lester

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [January 25, 2024, 7:32am UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/2 "2024-01-25T07:32:32Z")

</div>

There are several posts about this topic in regards of HA.

One item you miss from your list is websocket notifications will not work when using more then one pod since there is no internal communication between the pods and thus not all users will receive an update.

You are always allowed to open a discussion in the idea section regarding this. But from my side it’s not giving to have any priority. It takes a lot of work to build s3 support into Vaultwarden.

Maybe you can check for sidecar solutions which sync with s3 or use something like rclone. Or maybe even s3fs or something.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [January 25, 2024, 12:57pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/3 "2024-01-25T12:57:14Z")

</div>

Maybe [mountpoint-s3/docker at main · awslabs/mountpoint-s3 · GitHub](https://github.com/awslabs/mountpoint-s3/tree/main/docker) could be helpful too.

---

<div class="post-metadata">

**Author:** ![guerzon](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@guerzon](https://vaultwarden.discourse.group/u/guerzon)\
**Post date:** [January 25, 2024, 1:25pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/4 "2024-01-25T13:25:22Z")

</div>

Thanks @BlackDex, will check these out.

---

<div class="post-metadata">

**Author:** ![0x00](https://avatars.discourse-cdn.com/v4/letter/0/e79b87/32.png) [@0x00](https://vaultwarden.discourse.group/u/0x00)\
**Post date:** [February 22, 2024, 4:51pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/5 "2024-02-22T16:51:11Z")

</div>

Hi, even though I haven’t deployed Vaultwarden on Kubernetes and have only deployed Vaultwarden manually I would like to help you by offering a different point of view.

As far as the database goes it shouldn’t be a problem, I have used MariaDB with the Galera module and it worked really well, I have also used another setup with Pacemaker and DRBD to make a two node cluster which replicated the database storage.

When it comes to the data directory I think that a shared storage solution would be ideal, I don’t know the specifics of the deployments nor the technical limitations, but I would suggest something like Ceph or GlusterFS if they are are willing to manage and maintain another service, but if they are not willing to do that I think that using LINSTOR/DRBD would be a great idea, it would replicate the data directory across all nodes, I have used it in my latest project, ([https://www.youtube.com/watch?v=vyXpox\_M4hA](https://www.youtube.com/watch?v=vyXpox_M4hA)), it works 👍. I have found some resources that might help you:  
[https://blog.palark.com/kubernetes-storage-performance-linstor-ceph-mayastor-vitastor/](https://blog.palark.com/kubernetes-storage-performance-linstor-ceph-mayastor-vitastor/)  
[Using DRBD Block Devices for Kubevirt - LINBIT](https://linbit.com/blog/using-drbd-block-devices-for-kubevirt/)

And for the websocket notifications I’m afraid I cannot help you, I also had multiple instances of vaultwarden running and I couldn’t fix it, the closest thing I got was setting a session cookie stored on the client for each server on the reverse proxy, so each connection was to the same node.

Good luck! 👍

---

<div class="post-metadata">

**Author:** ![ntp](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/ntp/32/1555_2.png) [@ntp](https://vaultwarden.discourse.group/u/ntp)\
**Post date:** [October 20, 2024, 12:13pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/6 "2024-10-20T12:13:04Z")

</div>

Now that Bitwarden has officially gone commercial, maybe this would be an opportune time to revisit S3 support for Vaultwarden?

> **[Bitwarden is no longer free software](https://news.ycombinator.com/item?id=41893994)**
>
> 61 points —
> 23 comments —
> ferbivore —
> 8:51 AM - 20 Oct 2024

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [October 21, 2024, 4:40pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/7 "2024-10-21T16:40:06Z")

</div>

First, Bitwarden already was commercial, and that whole story is blown out of proportion.

Second, the one doesn’t rule out the other. S3 support is always welcome. Just not yet something which is currently developed.

---

<div class="post-metadata">

**Author:** ![guerzon](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@guerzon](https://vaultwarden.discourse.group/u/guerzon)\
**Post date:** [November 18, 2024, 12:51pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/8 "2024-11-18T12:51:21Z")

</div>

Hello,

Just an FYI: the feature to enable HA in Kubernetes environments has been added to the Helm chart: [feat: Add support for running multiple replicas by guerzon · Pull Request #131 · guerzon/vaultwarden · GitHub](https://github.com/guerzon/vaultwarden/pull/131), with a small disclaimer:

Fixes [#27](https://github.com/guerzon/vaultwarden/issues/27).

> Note: this PR does not address concurrent disk access for `data` and `attachment` volumes, which anyway is not the responsibility of the Helm chart. It is the responsibility of the Kubernetes administrator to ensure the storage class used is capable of supporting read and/or writes from multiple pods.

I also wrote a small guide about it: [Deploy Vaultwarden to Amazon EKS using Terraform, Terragrunt, and Helm | by Lester Guerzon | Nov, 2024 | Medium](https://medium.com/@sreafterhours/deploy-vaultwarden-to-amazon-eks-using-terraform-terragrunt-and-helm-69a0a7396625)

Lester

---

<div class="post-metadata">

**Author:** ![weigao](https://avatars.discourse-cdn.com/v4/letter/w/bbe5ce/32.png) [@weigao](https://vaultwarden.discourse.group/u/weigao)\
**Post date:** [April 29, 2026, 8:23pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/9 "2026-04-29T20:23:37Z")

</div>

I know this is an old topic, but still want to give it a try.

I recently installed Vaultwarden in a kubernetes cluster environment, use distributed file system (seaweedfs) for attachment, rsa keys, … use CloudNativePG for HA postgres.

The only problem is websocket notification. I’m thinking to have a sidecar to listen on postgres table events, and send a RestAPI request in vaultwarden, vaultwarden can decide if it should trigger websocket push or not depend on which client connect to it.

So I’m wondering is it possible to have Vaultwarden to implement a Rest API to trigger websocket push notification?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [May 1, 2026, 8:16pm UTC](https://vaultwarden.discourse.group/t/running-highly-available-vaultwarden/3285/10 "2026-05-01T20:16:55Z")

</div>

Depending on your uptime guarantee i wouldn’t bother with active-active, just setup active-passive in some way.
