Where Does TeamPass Store Keys and Vaults?
TeamPass keeps settings.php, saltkey, and secrets in storage volumes with vaults in MariaDB. Lose the volumes and it reinstalls.
Last updated
TeamPass splits into volumes plus database. The storage tree holds sk saltkey, config/settings.php with DB credentials, secrets master key, uploaded files, and backups. Vault contents live encrypted in MariaDB. Env (.env plus compose vars) carries passwords and URLs between recreates. Every piece is mandatory: the docs call out config and secrets volumes explicitly because missing ones trigger reinstall loops.
The saltkey path you enter at install must be the persisted one, not a container temp path. AES-256-GCM hardens new installs; upgrades keep legacy format until migrated on read. Keep a recovery admin reachable outside the vault; losing all admins plus the sk file ends restores before they start.
Where TeamPass stores this, by platform
storage/* (Docker volumes)
sk saltkey, settings.php, secrets master key, files, backups. Persist config+secrets volumes or every restart reinstalls. Saltkey path entered at install must be the persisted one.
Frequently asked questions
how do i back up teampass
Copy the storage volumes (sk saltkey, config with settings.php, secrets master key, files) plus a MariaDB dump with containers stopped. Vaults travel encrypted in the db under keys from the volumes. Restore all of them together.
why does teampass reinstall on every restart
Persist teampass-config and teampass-secrets volumes from day one. Without them TeamPass forgets install state and master key on every recreate and loops the installer. The sk saltkey path (/var/www/html/sk or storage/sk) must survive too.
Notice an outdated path? Let us know.