--- vaultwarden_version: 1.27.0 vaultwarden_archive_url: https://github.com/dani-garcia/vaultwarden/archive/{{ vaultwarden_version }}.tar.gz vaultwarden_archive_sha256: d7717d3a353b72626de6d6f2dc1e7776b40b487dc813759fbcd812c709cabcd8 vaultwarden_web_version: 2023.1.0 vaultwarden_web_archive_url: https://github.com/dani-garcia/bw_web_builds/releases/download/v{{ vaultwarden_web_version }}/bw_web_v{{ vaultwarden_web_version }}.tar.gz vaultwarden_web_archive_sha256: f635d8a28c03f597ed81354cf71aa0264d05abf3fec41337b2cf4879f3b3f6fc vaultwarden_root_dir: /opt/vaultwarden vaultwarden_user: vaultwarden # Database : can be sqlite or mysql vaultwarden_db_engine: sqlite vaultwarden_db_server: "{{ mysql_server | default('localhost') }}" vaultwarden_db_port: 3306 vaultwarden_db_name: vaultwarden vaultwarden_db_user: vaultwarden # A random one will be created if not defined # bitwaren_db_pass: S3cr3t. # Port on which vaultwarden will bind vaultwarden_http_port: 8000 vaultwarden_ws_port: 8001 # List of IP addresses (can be CIDR notation) which will be able to # access vaultwarden ports vaultwarden_src_ip: [] vaultwarden_web_src_ip: [] # Public URL on which vaultwarden will be accessible vaultwarden_public_url: http://{{ inventory_hostname }}:{{ vaultwarden_http_port }} # Should registration be enabled vaultwarden_registration: False # List of domain names for which registration will be accepted # Those domains will be accepted for registration even if vaultwarden_registration is set to False vaultwarden_domains_whitelist: - "{{ ansible_domain }}" # Admin Token to access /admin. A random one is created if not defined # vaultwarden_admin_token: S3cr3t. # Or you can just disable the admin token. But you have to protect /admin yourself (eg, on a reverse proxy) vaultwarden_disable_admin_token: False # YubiKey settings # vaultwarden_yubico_client_id: XXXX # vaultwarden_yubico_secret_key: XXXX