Linux

Where Does TeamPass Store Keys and Vaults?

TeamPass keeps settings.php, saltkey, and secrets in storage volumes with vaults in MariaDB. Lose the volumes and it reinstalls.

Last updated

TeamPass splits into volumes plus database. The storage tree holds sk saltkey, config/settings.php with DB credentials, secrets master key, uploaded files, and backups. Vault contents live encrypted in MariaDB. Env (.env plus compose vars) carries passwords and URLs between recreates. Every piece is mandatory: the docs call out config and secrets volumes explicitly because missing ones trigger reinstall loops.

The saltkey path you enter at install must be the persisted one, not a container temp path. AES-256-GCM hardens new installs; upgrades keep legacy format until migrated on read. Keep a recovery admin reachable outside the vault; losing all admins plus the sk file ends restores before they start.

Where TeamPass stores this, by platform

Linux
storage/* (Docker volumes)

sk saltkey, settings.php, secrets master key, files, backups. Persist config+secrets volumes or every restart reinstalls. Saltkey path entered at install must be the persisted one.

Frequently asked questions

how do i back up teampass

Copy the storage volumes (sk saltkey, config with settings.php, secrets master key, files) plus a MariaDB dump with containers stopped. Vaults travel encrypted in the db under keys from the volumes. Restore all of them together.

why does teampass reinstall on every restart

Persist teampass-config and teampass-secrets volumes from day one. Without them TeamPass forgets install state and master key on every recreate and loops the installer. The sk saltkey path (/var/www/html/sk or storage/sk) must survive too.

Notice an outdated path? Let us know.