I had a Raspberry Pi 1 Model B sitting in a drawer for a long time, and I wanted to give it a second life with something lightweight that it could run 24/7 without wasting electricity.
Cloud password managers (Google, Apple, etc.) are great, but what about having your own private one, on your own hardware? That is why I decided to run TeamPass on this old Pi.
Why TeamPass on a Pi 1?
TeamPass is an open source, self-hosted password and credential manager written in PHP. It is old school, but that is exactly the point: it is light enough to live on a Pi 1 Model B, and it keeps your data entirely on your network.
One catch: the Pi 1 is an armv6 device, and most modern Docker images only support armv7 or arm64. To keep things simple and not touch the system too much, I built a dedicated Docker image for TeamPass v2 on armv6. You can find it in my repository. The original installation instructions from the TeamPass docs are still a good reference.
Prerequisites
You will need:
A Raspberry Pi 1 Model B (or any armv6 Pi) with an operating system installed and working network access.
Docker Engine and the Docker Compose plugin installed on the Pi. Follow the official docs for your distro, and run the post-install steps so you can use docker without sudo.
Create the docker-compose
TeamPass needs a database, so the compose file below starts two containers: web (TeamPass) and db (MariaDB). When you start it, the compose file creates the folders ./teampass-html (the web files) and ./teampass-db/mysql (the database) next to itself.
Replace the placeholders with your own values: use your own password, and your user ID for PUID/GUID (id -u, usually 1000). The GIT_TAG pins the TeamPass version so the image does not change under you; to update later, get a new tag from the repository and change it here.
version: "3"
services:
web:
image: ghcr.io/cumal/rpi-teampass:arm
restart: always
environment:
VIRTUAL_HOST: localhost
VIRTUAL_PORT: 80
CERT_NAME: YOUR_CERTIFICATE
GIT_TAG: 2.1.27.36
volumes:
- ./teampass-html:/var/www/html
ports:
- 8899:80
depends_on:
- db
db:
restart: always
image: webhippie/mariadb:latest-arm
environment:
MARIADB_ROOT_USERNAME: root
MARIADB_ROOT_PASSWORD: {{YOURPASSWORD}}
MARIADB_DATABASE: teampass
MARIADB_PASSWORD: {{YOURPASSWORD}}
MARIADB_USERNAME: teampass
PUID: 1000
GUID: 1000
volumes:
- ./teampass-db/mysql:/var/lib/mysql
By default the ports section is active, so TeamPass is reachable directly on port 8899. If you run a reverse proxy (the VIRTUAL_HOST, VIRTUAL_PORT and CERT_NAME variables are for that kind of setup), set your domain instead of localhost, point CERT_NAME to your certificate, and comment out the ports block.
Start it up
From the folder that contains the compose file:
docker compose up -d
docker compose ps
docker logs web
Wait until both containers are healthy. The first start can take a minute while the database initializes.
First run
Open http://{{PIIP}}:8899 in your browser (or https://yourdomain/ if you are using a reverse proxy). The setup wizard will ask for the database connection: use db (the compose service name, not localhost) as the host, teampass as the user, teampass as the database, and the password you set in the compose file.
After that, create your admin account and you are done: your private password manager is running on the oldest Raspberry Pi you own.
If anything goes wrong, start with the logs: docker logs web and docker logs db. And remember both the teampass-html and teampass-db folders are your backup: if you lose them, you lose your credentials.

