Skip to main content
Vaultwarden is the released alternative for the optional native v2 vault workload. It is not enabled by the initial Basement or Cloud StackSpec.
The release exposes no safe public post-init command for creating the owner-bound secret custody required by a newly added Vault workload. Do not treat an opaque secret:// reference as a value or use this page as a complete installation recipe.
Create the application owner account, store recovery material separately, and choose the registration policy before adding real secrets. Confirm that your backup and recovery approach covers the Vaultwarden data volume. For an already admitted workload, change StackKits intent through the StackSpec and lifecycle commands; do not edit generated application configuration on the target.