> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kombify.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Vaultwarden

> Understand the released optional Vault workload and its current authoring boundary

Vaultwarden is the released alternative for the optional native v2 `vault` workload. It is not enabled by the initial Basement or Cloud StackSpec.

| Property                     | v0.16.0 value        |
| ---------------------------- | -------------------- |
| Workload                     | `vault`              |
| Alternative                  | `vaultwarden`        |
| Data class                   | secret               |
| Required secret reference    | `admin-token`        |
| Supported standalone adapter | `standalone-compose` |

<Warning>
  The release exposes no safe public post-init command for creating the owner-bound secret custody required by a newly added Vault workload. Do not treat an opaque `secret://` reference as a value or use this page as a complete installation recipe.
</Warning>

Create the application owner account, store recovery material separately, and choose the registration policy before adding real secrets. Confirm that your backup and recovery approach covers the Vaultwarden data volume.

For an already admitted workload, change StackKits intent through the StackSpec and lifecycle commands; do not edit generated application configuration on the target.
