Vaultwarden and Tailscale

hi all -

I used to have Tailscale and vaultwarden working with the Bitwarden app (check my post history - I made short write up on connecting the everything together).

However, it no longer will connect to Vaultwarden on umbrel. My set up has not changed. I’m still connecting via Tailscale w the Bitwarden app but now my connection is refused.

Has something changed? is it necessary to go back to TOR for Vaultwarden?

@DarthCoin any advice you have would be great. Thanks.

1 Like

Were you connecting using the tailscale IP, or how?

yep - using my Tailscale IP and Vaultwarden port (8080).

I had it working for a long time via Tailscale. and it’s only recently shit the bed and I can’t figure out why.

I even wrote up instructions on here for other folks to use. Pretty bewildering

I guess you were connecting through http instead of https, Bitwarden was never to likely to let you use http, but recently that policy was enforced even more.

If I’m not mistaken you can enable https on Tailcale ( Enabling HTTPS · Tailscale Docs ), you should try doing that and using the magic-dns address instead of the unprotected IP.

Unfortunately Umbrel still doesn’t use https by default, this is something that has been requested for years.

Well, last version of Bitwarden working without https is 2025.5.0

It’s totally understandable that an app like Vaultwarden-Bitwarden enforces the use of encrypted communication

Has anyone actually solved this yet?
I wouldn’t even have thought it was possible since it only runs over Tor.
But the description of Vaultwarden in the Umbrel App Store explicitly claims that you can also access it from the app or browser extension via the Tailscale IP.
But I can’t get it to work either — not even over HTTPS.
Neither using just the IP nor with MagicDNS.
Neither with port 8080 nor without it.
I’m at a loss.

Did you check my previous answer?
I haven’t been using Umbrel for a while, but first you should check which port Vaultwarden is using, you can do this connecting to it locally, and just read the number after “:” in the address. Then you should enable https on your tailnet. And finally you should connect Bitwarden to Vaultwarden using the magicdns address + the port using https.
As I said unfortunately I can’t verify if that works (I’m using a different setup) but that should be the way to do it.