Documentation home
Self-Hosted Community Edition

Community Edition overview

Understand the operator responsibilities, included security plane, Cloud feature differences, and lack of a hosted admin panel.

8 min readOperator-owned AWS deploymentView source

VaultGuard Self-Hosted Community Edition

Community Edition is the self-hosted product for teams that choose to operate VaultGuard in their own AWS account. It is not the default Cloud setup path and it is not a free tier of VaultGuard Cloud.

Read this first

Community Edition requires an infrastructure operator. Your team owns the AWS deployment, KMS keys, Cognito configuration, storage, transactional email, monitoring, backups, upgrades, availability, and AWS bill.

If you want VaultGuard without running infrastructure, use VaultGuard Sync (Cloud) instead.

What Community Edition includes

  • The VaultGuard Sync Obsidian plugin.
  • Client-side encrypted file bodies under KMS-backed, server-managed keys in your AWS account.
  • Multi-vault membership and per-path permissions.
  • Time-bounded key leases and access revocation.
  • Local at-rest protection for supported paths.
  • Basic audit history.
  • In-Obsidian organization administration.
  • Permission-aware AI Chat and optional agent tools when configured.

What it does not include

Community Edition has no hosted web admin panel. Do not send self-hosted administrators to admin.vaultguard.cloud.

It also excludes the managed Cloud conveniences and Pro-gated surfaces:

  • hosted share links and the share-bridge service;
  • advanced audit dashboards, anomaly alerts, and CSV reports;
  • Stripe billing;
  • managed infrastructure, backups, monitoring, and uptime targets; and
  • managed support response targets.

Community collaboration uses vault membership and permissions. Administration happens through VaultGuard Sync: Manage organization inside Obsidian.

Who should use it

Community Edition is suitable when your organization:

  • has an AWS operator who can own the deployment lifecycle;
  • accepts responsibility for backup and incident response;
  • needs the service resources and KMS key in its own AWS account; and
  • can validate upgrades before applying them to production.

It is not the simpler choice for an ordinary Obsidian team. The managed Cloud path removes the operational work and provides the hosted administration experience.

Community Edition documentation

  1. Deploy Community Edition
  2. Administer Community Edition in Obsidian
  3. Review the security boundary in the deployment guide before adding real content.

The public deployment manual deliberately contains terminal and Terraform commands because Community Edition operators must run the backend. Those commands never apply to VaultGuard Sync (Cloud).

Support boundary

Use the public repository for Community Edition issues and discussions. Do not publish AWS account identifiers, Terraform state, credentials, recovery material, protected note content, or unredacted logs.

Commercial managed service, enterprise controls, and response commitments are separate offerings available through vaultguard.cloud.