Back to articles
Technology Insight

Securing Team Credentials: A Comprehensive Guide to Deploying Passbolt on a VPS

June 1, 2026

Introduction: The Growing Challenge of Credential Management

In the modern digital landscape, the security of administrative credentials and internal passwords is no longer just a technical concern—it is a foundational pillar of business continuity. As teams grow and the number of SaaS platforms, server environments, and database accesses multiplies, the traditional (and often insecure) methods of sharing passwords via spreadsheets or instant messaging apps become a significant risk. For organizations seeking a balance between high-level security and seamless collaboration, Passbolt has emerged as the premier solution.

Passbolt is an open-source, self-hosted password manager specifically designed for teams. Unlike consumer-focused managers, Passbolt is built on OpenPGP, providing end-to-end encryption while allowing granular access control. In this guide, we will walk through the professional implementation of Passbolt on a Virtual Private Server (VPS), ensuring your organization maintains full sovereignty over its sensitive data.

Why Choose Passbolt for Your Team?

Selecting the right password management tool requires an evaluation of security protocols, ease of use, and scalability. Passbolt excels in several key areas:

  • Self-Hosted Sovereignty: By deploying on your own VPS, you ensure that your encrypted database never leaves your controlled infrastructure.
  • Open Source Transparency: The codebase is open for audit, ensuring there are no hidden backdoors—a critical requirement for compliance-heavy industries.
  • Team-Centric Collaboration: Passbolt allows for sharing passwords with specific users or groups without compromising the integrity of the master key.
  • OpenPGP Standard: It utilizes proven cryptographic standards, ensuring that even if the server is compromised, the actual credentials remain encrypted and unreadable.

Pre-deployment Requirements

Before beginning the installation, ensure your environment meets the following professional specifications:

  1. VPS Provider: A reliable provider such as DigitalOcean, Linode, or AWS with at least 2GB of RAM and 1 CPU core.
  2. Operating System: A clean installation of Ubuntu 22.04 LTS or 24.04 LTS is highly recommended for long-term support.
  3. Domain Name: A fully qualified domain name (FQDN) pointed to your VPS IP address (e.g., passwords.yourcompany.com).
  4. SSL/TLS Certificate: Passbolt requires HTTPS to function securely. We will utilize Let's Encrypt for this purpose.

Step 1: Preparing the VPS Environment

Log in to your server via SSH and ensure all system packages are up to date. This minimizes vulnerabilities from outdated dependencies.

Security Note: Always use SSH keys for authentication and disable root password login before deploying sensitive applications like Passbolt.

Run the following commands to update the system:

sudo apt update && sudo apt upgrade -y

Step 2: Installing the Passbolt Repository

Passbolt provides an official repository for Debian-based systems, which simplifies the installation and future update processes. Start by installing the necessary dependencies to handle GPG keys and HTTPS repositories.

sudo apt install wget gpg apt-transport-https

Next, download and install the Passbolt GPG key to verify the authenticity of the packages:

wget -O- [https://download.passbolt.com/pub.key](https://download.passbolt.com/pub.key) | gpg --dearmor | sudo tee /usr/share/keyrings/passbolt-archive-keyring.gpg > /dev/null

Step 3: Configuring the Database

Passbolt utilizes MariaDB (or MySQL) to store its data. During the installation process, you will be prompted to set up a database user and password. It is imperative to use a strong, unique password for the database user, as this is the secondary layer of defense for your encrypted data blobs.

Automated Installation with the Passbolt Script

Passbolt offers an interactive installation script that handles the configuration of Nginx, MariaDB, and PHP. This is the recommended path for a standardized deployment:

sudo apt install passbolt-ce-server

During this process, the interactive installer will ask for your domain name and email address for the Let's Encrypt certificate. Ensure your DNS records have propagated before this step to avoid validation errors.

Step 4: Post-Installation Security Hardening

Once the software is installed, you must navigate to your domain in a web browser to complete the setup. However, a professional deployment does not end with a successful login. Consider the following hardening steps:

  • Configure a Firewall (UFW): Only allow traffic on ports 80 (HTTP), 443 (HTTPS), and your custom SSH port.
  • Fail2Ban Implementation: Protect your server from brute-force attacks by installing Fail2Ban to monitor failed SSH or web login attempts.
  • Regular Backups: Ensure you have a strategy for backing up both the database and the serverkey.asc and serverkey_private.asc files. Without these keys, your data is unrecoverable.

Step 5: Onboarding Your Team

With the server active, the administrator can begin inviting team members. Each user will generate their own private GPG key locally in their browser. This distributed trust model ensures that even the server administrator cannot read individual user passwords without being explicitly granted access through the Passbolt sharing interface.

The Importance of Training

Educate your team on the importance of the Master Password and the Recovery Kit. In Passbolt, the recovery kit is a downloadable file containing the user's private key. If a user loses both their password and their recovery kit, their access to the shared passwords cannot be restored by the IT department, by design.

Conclusion: Empowering a Security-First Culture

Deploying Passbolt on a VPS is a strategic move that elevates your organization's security posture. By moving away from centralized, third-party managed solutions and toward a self-hosted, OpenPGP-based system, you take control of your most sensitive assets. While the initial setup requires technical diligence, the long-term benefits of privacy, compliance, and team efficiency are invaluable.

Secure your credentials today, and provide your team with the peace of mind they need to innovate safely.

Securing Team Credentials: A Comprehensive Guide to Deploying Passbolt on a VPS | DPTCloud