Using Ollama Remotely
What this article covers
- How to expose Ollama on your local network.
- Secure access over the internet.
- Reverse proxies, TLS, and authentication.
- Docker setup.
- Tips to prevent unauthorized use.
Introduction: Accessing Ollama remotely
By default, Ollama runs only locally. If you need to access it from another device, a server, or while traveling, you’ll need to make Ollama reachable over the network. Security is essential here: an unprotected Ollama API can be exploited quickly. With the right setup, though, you can safely use Ollama across your network or over the internet.
This article walks through the main approaches for secure remote access to Ollama.
Key concepts
- HOST: Ollama environment variable for the bind address.
- Reverse Proxy: Forwards external requests to your local service.
- TLS: Encrypted connection protocol.
- Authentication: User verification.
- Tailscale: Mesh VPN without requiring public IPs.
- WireGuard: VPN tunnel protocol.
- CORS: Cross-Origin Resource Sharing rules.
- API Key: Secret token for API access.
Local network
Ollama normally starts on 127.0.0.1:11434. To make it accessible on your network:
export OLLAMA_HOST=0.0.0.0:11434
ollama serve
On some systems, edit the systemd service:
sudo systemctl edit ollama
[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"
sudo systemctl daemon-reload
sudo systemctl restart ollama
Testing access
curl http://ollama-server:11434/api/tags
Reverse proxy with nginx
server {
listen 443 ssl;
server_name ollama.example.com;
location / {
proxy_pass http://localhost:11434;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_read_timeout 300s;
}
}
API key protection
Ollama has no built-in API key support. Place a reverse proxy in front that enforces authentication. Here’s an example using nginx and Lua:
location / {
if ($http_authorization != "Bearer MEIN_KEY") {
return 401;
}
proxy_pass http://localhost:11434;
}
A proper proxy solution like Authelia or Traefik with middleware is more robust.
Tailscale
Tailscale creates a secure mesh VPN. Ollama doesn’t need to be publicly exposed:
tailscale up
Keep Ollama listening only locally on the target device and access it via the Tailscale IP:
curl http://100.x.x.x:11434/api/tags
WireGuard
For fixed site-to-site connections, WireGuard is a solid choice. Ollama remains private in this setup too.
Docker
services:
ollama:
image: ollama/ollama
ports:
- "11434:11434"
environment:
- OLLAMA_HOST=0.0.0.0
volumes:
- ollama:/root/.ollama
volumes:
ollama:
Security tips
- Never expose to the internet without protection.
- TLS is mandatory for external access.
- Set up API keys or authentication.
- Restrict firewall access to port 11434.
- Monitor logs regularly.
- Limit available models or restrict access by user.
- Enable rate limiting.
CORS
If a web frontend connects directly to Ollama, you might hit CORS issues. Solutions include:
- Serve the frontend and Ollama from the same host.
- Run Ollama behind a CORS-friendly proxy.
Tips
- Prefer VPN access over public exposure.
- Test whether your firewall allows the ports.
- Run Ollama on a dedicated server or Docker container.
- Pre-load important models on the server.
Common pitfalls
- Ollama listens on 127.0.0.1: Missing
OLLAMA_HOSTsetting. - Firewall blocks it: Port not opened.
- No authentication: Public API gets abused.
- CORS errors: Frontend can’t reach the service directly.
- Timeout: Long responses need higher
proxy_read_timeout. - Unencrypted connection: TLS missing.
Further reading and resources
- BotServ.de Ollama API troubleshooting
- BotServ.de Ollama REST API
- BotServ.de Docker reverse proxy
- BotServ.de Tailscale basics
FAQ: Using Ollama remotely
Can I expose Ollama to the internet? Yes, but only with TLS, authentication, and strong rate limiting.
What’s the safest approach? A VPN like Tailscale or WireGuard, where Ollama remains private and never exposed publicly.
Does Ollama need to listen on 0.0.0.0? Only if other devices need direct access to the port.
Can I set API keys in Ollama? No. Use an external proxy or API gateway instead.
What’s the default port? 11434.
Sources and further reading
- Ollama Docker: https://ollama.com/blog/ollama-is-now-available-as-an-official-docker-image
- Tailscale: https://tailscale.com/
- WireGuard: https://www.wireguard.com/
Summary
Remote access to Ollama requires both network exposure and security measures. On your local network, OLLAMA_HOST=0.0.0.0 is enough. Over the internet, you’ll need TLS, authentication, and ideally a VPN. Tailscale and WireGuard are safer alternatives to public exposure. If you pay attention to firewall rules, logs, and stable DNS names, you can safely use Ollama from anywhere.


