Community Edition overview
Understand the operator responsibilities, included security plane, Cloud feature differences, and lack of a hosted admin panel.
VaultGuard Self-Hosted Community Edition
Community Edition is the self-hosted product for teams that choose to operate VaultGuard in their own AWS account. It is not the default Cloud setup path and it is not a free tier of VaultGuard Cloud.
Read this first
Community Edition requires an infrastructure operator. Your team owns the AWS deployment, KMS keys, Cognito configuration, storage, transactional email, monitoring, backups, upgrades, availability, and AWS bill.
If you want VaultGuard without running infrastructure, use VaultGuard Sync (Cloud) instead.
What Community Edition includes
- The VaultGuard Sync Obsidian plugin.
- Client-side encrypted file bodies under KMS-backed, server-managed keys in your AWS account.
- Multi-vault membership and per-path permissions.
- Time-bounded key leases and access revocation.
- Local at-rest protection for supported paths.
- Basic audit history.
- In-Obsidian organization administration.
- Permission-aware AI Chat and optional agent tools when configured.
What it does not include
Community Edition has no hosted web admin panel. Do not send self-hosted
administrators to admin.vaultguard.cloud.
It also excludes the managed Cloud conveniences and Pro-gated surfaces:
- hosted share links and the share-bridge service;
- advanced audit dashboards, anomaly alerts, and CSV reports;
- Stripe billing;
- managed infrastructure, backups, monitoring, and uptime targets; and
- managed support response targets.
Community collaboration uses vault membership and permissions. Administration happens through VaultGuard Sync: Manage organization inside Obsidian.
Who should use it
Community Edition is suitable when your organization:
- has an AWS operator who can own the deployment lifecycle;
- accepts responsibility for backup and incident response;
- needs the service resources and KMS key in its own AWS account; and
- can validate upgrades before applying them to production.
It is not the simpler choice for an ordinary Obsidian team. The managed Cloud path removes the operational work and provides the hosted administration experience.
Community Edition documentation
- Deploy Community Edition
- Administer Community Edition in Obsidian
- Review the security boundary in the deployment guide before adding real content.
The public deployment manual deliberately contains terminal and Terraform commands because Community Edition operators must run the backend. Those commands never apply to VaultGuard Sync (Cloud).
Support boundary
Use the public repository for Community Edition issues and discussions. Do not publish AWS account identifiers, Terraform state, credentials, recovery material, protected note content, or unredacted logs.
Commercial managed service, enterprise controls, and response commitments are separate offerings available through vaultguard.cloud.