Skip to content

Passbolt — IT Team Password Manager

Basic Information

FieldValue
CategorySystem Tools
OwnerSergej Vdovičenko
DeputyArtem Ryzhkov
Management Level5
SLA8x5
LoginGPG key (browser extension)
DeploymentOn-prem VM (Proxmox cluster)

Description

Passbolt is an open-source password manager for team credential sharing. It encrypts passwords end-to-end using GPG keys — no one (including admins) can read a password without the user's private key.

What we store here:

  • Infrastructure system credentials (Proxmox, FortiGate, Windows Server…)
  • SaaS platform admin accounts (Google Workspace, ESET Protect, Hexnode…)
  • API keys and tokens
  • Network passwords (RADIUS secrets, VPN PSK)

Warning

Passbolt is the most security-critical system. Access is restricted to IT team members only. Never share Passbolt passwords outside the approved circle.

Access and Login

  • URL: https://[passbolt-vm-ip] (internal network or VPN)
  • Login: browser extension (Chrome/Firefox) with GPG key
  • New users must go through the onboarding process (GPG key generation + admin approval)

Procedure — Add New Password

  1. Passbolt → Passwords → Create new password (+)
  2. Fill in: Name, URL, Username, Password, Description
  3. Save to the correct Folder

Procedure — Share Password with a Colleague

  1. Click on password → Share (share icon)
  2. Search for user or group
  3. Set permission: Can read / Can update / Is owner
  4. Click Save — password is encrypted with the recipient's public key

Procedure — Onboard New IT Team Member

  1. Admin invites user: Passbolt → Users → Invite User
  2. User clicks invitation → installs Passbolt browser extension
  3. Extension generates GPG key or imports an existing one
  4. Admin approves key fingerprint and confirms onboarding

Warning — GPG Key Loss

If you lose your private GPG key without a backup, you cannot access passwords shared exclusively with you. Always back up your GPG key.

Folder Structure

IT-Shared/
  ├── Infrastructure/     — servers, network, Proxmox
  ├── Cloud-Services/     — SaaS admin accounts
  ├── Networking/         — FortiGate, switches, RADIUS secrets
  ├── Active-Directory/   — AD admin, service accounts
  └── VPN/               — VPN keys, PSK

Troubleshooting

ProblemSolution
Passbolt not opening in browserCheck browser extension; verify Passbolt VM accessibility via VPN
Forgotten GPG key passphraseAdmin must recover access — delete key, generate new one, admin re-approves (passwords remain)
Cannot share passwordVerify recipient has an active GPG key in Passbolt

Contact

  • Owner: Sergej Vdovičenko — Slack @sergej
  • Deputy: Artem Ryzhkov — Slack @artem
  • Access issues: Slack #it-help (be careful — never quote passwords)

Etnetera a.s. — IT Team