Skip to content

Latest commit

 

History

57 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

bitwarden-cli

bitwarden-cli docker image

this is based on the code in the external-secrets documentation.

both the Dockerfile and entrypoint.sh are a near-identical copy/paste.

the only changes are to the Dockerfile to convert BW_CLI_VERSION from an ENV to an ARG, so that the official upstream version can be read from the VERISON file for the ARG as well as the image tag

contributions

contributions are welcome! however, before opening PRs here for changes to files in the external-secrets docs, please open a PR to their docs first. when you open a PR here, please include a link to the changes there.

tag convention

docker pull ghcr.io/charlesthomas/bitwarden-cli:<official bitwarden cli version>

check VERSION to see what the actual value is. when this doc was created it was 2023.12.1 so the full image was:

ghcr.io/charlesthomas/bitwarden-cli:2023.12.1

hostname

bw serve 2026.6.0 added a Host header allowlist on top of its existing Origin header check. with --hostname 0.0.0.0 the allowlist only contains localhost, 127.0.0.1, [::1] and 0.0.0.0 at the serve port, so reaching the container over a docker or kubernetes service name (e.g. bitwarden-cli.my-namespace.svc:8087) is rejected with:

Blocking request with disallowed Host "..."

this image runs bw serve --hostname all, which binds every interface and skips the Host allowlist while leaving the Origin header check active. older cli releases accept all too, so the same entrypoint works either side of 2026.6.0.

this is preferable to --disable-origin-protection, which turns off both checks.

About

bitwarden-cli docker image

Resources

Stars

7 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages