This note is qutie
Ingredients:
- Tailscale
- KeePassXC
- hacdias/webdav
- Keepassium
Configuration for webdav:
address: 0.0.0.0
port: 87
tls: false
behindProxy: true
directories:
- name: passwords
path: "/Users/denis/path/to/my/password-db/"
users:
- username: denis
password: "Eu28TUNwscPtmWdnmDhd" # not my real one
permissions: CRUD
runit1 configuration:
#!/bin/sh -e
export PATH=/opt/homebrew/bin:$PATH
cd /opt/webdav
exec 2>&1
exec webdav --config config.yaml
Tailscale setup (part of it, at least):
tailscale serve \
--service=svc:webdav \
--https=443 \
localhost:87
With Tailscale set up on my macBook and my phone, I can now connect to Keepassium.
Alternatives
This approach works well for me, but it’s certainly not the only one:
-
Use macOS’ built-in WebDAV server support. I couldn’t get it to work (it’s complicated).
-
Use launchd instead of runit.
-
Use a dedicated server rather than my laptop. (But how can I use KeePassXC reliably with a remote database?)
-
Use a file sync service (probably not nearly as reliable!).
-
I find runit to be so much simpler to deal with than launchd. ↩︎