Skip to content
BotServBotServ
OllamaRemoteAPINetworkSecurity

Use Ollama Remotely

Share Ollama across your network or internet. Secure remote access, reverse proxy, and authentication.

S

schutzgeist

3 min read
Use Ollama Remotely

Using Ollama Remotely

What this article covers

  • How to expose Ollama on your local network.
  • Secure access over the internet.
  • Reverse proxies, TLS, and authentication.
  • Docker setup.
  • Tips to prevent unauthorized use.

Introduction: Accessing Ollama remotely

By default, Ollama runs only locally. If you need to access it from another device, a server, or while traveling, you’ll need to make Ollama reachable over the network. Security is essential here: an unprotected Ollama API can be exploited quickly. With the right setup, though, you can safely use Ollama across your network or over the internet.

This article walks through the main approaches for secure remote access to Ollama.

Key concepts

  • HOST: Ollama environment variable for the bind address.
  • Reverse Proxy: Forwards external requests to your local service.
  • TLS: Encrypted connection protocol.
  • Authentication: User verification.
  • Tailscale: Mesh VPN without requiring public IPs.
  • WireGuard: VPN tunnel protocol.
  • CORS: Cross-Origin Resource Sharing rules.
  • API Key: Secret token for API access.

Local network

Ollama normally starts on 127.0.0.1:11434. To make it accessible on your network:

export OLLAMA_HOST=0.0.0.0:11434
ollama serve

On some systems, edit the systemd service:

sudo systemctl edit ollama
[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"
sudo systemctl daemon-reload
sudo systemctl restart ollama

Testing access

curl http://ollama-server:11434/api/tags

Reverse proxy with nginx

server {
    listen 443 ssl;
    server_name ollama.example.com;

    location / {
        proxy_pass http://localhost:11434;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_read_timeout 300s;
    }
}

API key protection

Ollama has no built-in API key support. Place a reverse proxy in front that enforces authentication. Here’s an example using nginx and Lua:

location / {
    if ($http_authorization != "Bearer MEIN_KEY") {
        return 401;
    }
    proxy_pass http://localhost:11434;
}

A proper proxy solution like Authelia or Traefik with middleware is more robust.

Tailscale

Tailscale creates a secure mesh VPN. Ollama doesn’t need to be publicly exposed:

tailscale up

Keep Ollama listening only locally on the target device and access it via the Tailscale IP:

curl http://100.x.x.x:11434/api/tags

WireGuard

For fixed site-to-site connections, WireGuard is a solid choice. Ollama remains private in this setup too.

Docker

services:
  ollama:
    image: ollama/ollama
    ports:
      - "11434:11434"
    environment:
      - OLLAMA_HOST=0.0.0.0
    volumes:
      - ollama:/root/.ollama

volumes:
  ollama:

Security tips

  • Never expose to the internet without protection.
  • TLS is mandatory for external access.
  • Set up API keys or authentication.
  • Restrict firewall access to port 11434.
  • Monitor logs regularly.
  • Limit available models or restrict access by user.
  • Enable rate limiting.

CORS

If a web frontend connects directly to Ollama, you might hit CORS issues. Solutions include:

  • Serve the frontend and Ollama from the same host.
  • Run Ollama behind a CORS-friendly proxy.

Tips

  • Prefer VPN access over public exposure.
  • Test whether your firewall allows the ports.
  • Run Ollama on a dedicated server or Docker container.
  • Pre-load important models on the server.

Common pitfalls

  • Ollama listens on 127.0.0.1: Missing OLLAMA_HOST setting.
  • Firewall blocks it: Port not opened.
  • No authentication: Public API gets abused.
  • CORS errors: Frontend can’t reach the service directly.
  • Timeout: Long responses need higher proxy_read_timeout.
  • Unencrypted connection: TLS missing.

Further reading and resources

FAQ: Using Ollama remotely

Can I expose Ollama to the internet? Yes, but only with TLS, authentication, and strong rate limiting.

What’s the safest approach? A VPN like Tailscale or WireGuard, where Ollama remains private and never exposed publicly.

Does Ollama need to listen on 0.0.0.0? Only if other devices need direct access to the port.

Can I set API keys in Ollama? No. Use an external proxy or API gateway instead.

What’s the default port? 11434.

Sources and further reading

Summary

Remote access to Ollama requires both network exposure and security measures. On your local network, OLLAMA_HOST=0.0.0.0 is enough. Over the internet, you’ll need TLS, authentication, and ideally a VPN. Tailscale and WireGuard are safer alternatives to public exposure. If you pay attention to firewall rules, logs, and stable DNS names, you can safely use Ollama from anywhere.

Back to Blog
Share:

Related Posts