AliasVault on Ubuntu 24.04 LTS
by cloudimg
Self hosted encrypted password manager with private email aliases, secured on first boot
AliasVault on Ubuntu 24.04 LTS
AliasVault is an open source, end to end encrypted password manager combined with a private email alias service that you host yourself. For every website you sign up to, AliasVault can generate a unique identity and a unique email alias, receive email for that alias through its own built in mail server, and store the login in a zero knowledge vault. Your master password never leaves your device, so the server only ever holds encrypted data.
What is included
- AliasVault v0.30.1, the full open source stack, pinned to the upstream release
- A bundled PostgreSQL database and a built in mail server, reachable only inside a private container network
- A web vault client, an admin panel and a REST API behind an nginx reverse proxy that terminates TLS
- A unique admin password, JWT signing key, data protection key and database password generated per VM on first boot
- A clean, empty instance on first boot with no default account and no shipped data
- 24/7 cloudimg support
Secure by default
AliasVault stores your most sensitive credentials, so a shipped secret would be a serious risk. This image closes that. On first boot, before the ports are reachable, a unique admin password, JWT key, data protection key and database password are generated for this VM, and a fresh self signed TLS certificate is created. The vault is zero knowledge by design: each master password derives its encryption key on the client, so no vault key is ever held by the image. PostgreSQL is never exposed on a host port.
Licensing
AliasVault is free and open source under the GNU Affero General Public License v3.0 (AGPL 3.0). The verbatim licence text and a pointer to the corresponding source at the pinned release ship inside the image. There is no per seat fee for the software. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 support. Recommended size: Standard_B2s. This image is produced by cloudimg and is not affiliated with, endorsed by, or sponsored by AliasVault.
Before you start
The web interface is served over HTTPS on port 443 with a per VM self signed certificate; the mail server listens on ports 25 and 587. To use private email domains and inbound mail you will need to point DNS at this VM and open the mail ports. Front the web interface with your own domain and a trusted certificate, and restrict the network security group, before production. Prerequisites: an Azure subscription, a VNet and an SSH key. Inbound rules: port 22 for SSH, port 443 for the web interface, and ports 25 and 587 for mail. Deployment guide: https://www.cloudimg.co.uk/guides/aliasvault-on-ubuntu-24-04-azure/ . Support: support@cloudimg.co.uk