Skip to content
appsgit

Deploy guide

How to self-host Open WebUI with Docker Compose

Deploy Open WebUI with Docker Compose and connect it to Ollama or any OpenAI-compatible API: secret key, admin account, HTTPS, backups and safe upgrades.

  • Updated
  • Beginner
  • About 15 minutes

You will need

  • 2 vCPU / 4 GB RAM (plus model memory if Ollama runs on the same host)
  • Docker + Docker Compose v2
  • Ollama or an OpenAI-compatible API key
  • A domain name (optional, for HTTPS)

What is Open WebUI?

Open WebUI is a self-hosted chat interface for large language models that looks and works much like ChatGPT. It is open source, published under a BSD-3-Clause-based license with a branding clause, and connects to local models through Ollama or to any OpenAI-compatible API. It adds multi-user accounts, document chat (RAG), web search, tools and pipelines on top.

Requirements

  • A Linux server with 2 vCPU and 4 GB of RAM for Open WebUI itself.
  • Docker Engine and Docker Compose v2.
  • A model backend: Ollama on the same or another machine, or an API key for an OpenAI-compatible provider.

Running local models needs far more resources than the UI: plan for 8 GB of RAM or VRAM for a 7-8B model. See our Ollama guide for sizing.

Step 1: Prepare the server

This guide assumes Ubuntu 24.04 with Docker installed. If you need Docker, follow the official install guide. Create a project folder:

mkdir -p ~/open-webui && cd ~/open-webui

Step 2: Create the Docker Compose file

This stack runs Open WebUI and Ollama together. If you only want to use a cloud API, delete the ollama service and the OLLAMA_BASE_URL line. Save as docker-compose.yml:

services:
  ollama:
    image: ollama/ollama:latest
    restart: unless-stopped
    volumes:
      - ollama:/root/.ollama
    # Uncomment for NVIDIA GPUs (requires the NVIDIA Container Toolkit):
    # deploy:
    #   resources:
    #     reservations:
    #       devices:
    #         - driver: nvidia
    #           count: all
    #           capabilities: [gpu]

  open-webui:
    image: ghcr.io/open-webui/open-webui:main
    restart: unless-stopped
    depends_on:
      - ollama
    ports:
      - "3000:8080"
    environment:
      OLLAMA_BASE_URL: http://ollama:11434
      WEBUI_SECRET_KEY: ${WEBUI_SECRET_KEY}
      WEBUI_URL: https://chat.example.com
    volumes:
      - open-webui:/app/backend/data

volumes:
  ollama:
  open-webui:

Create .env:

WEBUI_SECRET_KEY=CHANGE_ME

Generate it with openssl rand -hex 32. Open WebUI signs login tokens with this key. If you do not set it, it generates one on first run and stores it in the data volume, but an explicit key keeps sessions valid across container rebuilds. Ollama is not published to the host at all: only Open WebUI talks to it over the internal Docker network, which matters because Ollama has no authentication. The main tag tracks the latest release. To pin, use a version tag such as v0.11.4 from the releases page.

Step 3: Start and open the app

docker compose up -d
docker compose exec ollama ollama pull llama3.2

The second command downloads a small model to test with. Open http://YOUR_SERVER_IP:3000 and create an account: on a fresh install the first account becomes the admin. Pick the model from the dropdown and start chatting. To add OpenAI or another provider, go to Admin Panel, Settings, Connections and enter the base URL and API key.

Step 4: Put it behind HTTPS

With Caddy:

chat.example.com {
    reverse_proxy 127.0.0.1:3000
}

Open WebUI streams responses over WebSockets, which Caddy handles automatically. In Nginx Proxy Manager, enable "Websockets Support" and raise timeouts for long generations. Once HTTPS works, map the port as "127.0.0.1:3000:8080". Under Admin Panel, Settings, General, review whether new sign-ups are allowed and which role they get.

Backups and upgrades

All Open WebUI state is in the open-webui volume: the SQLite database with users and chats, uploaded documents, and the vector store used for RAG. Back it up with a temporary container:

docker run --rm -v open-webui_open-webui:/data -v "$PWD":/backup alpine tar czf /backup/open-webui-$(date +%F).tgz -C /data .

Models in the ollama volume can be re-downloaded, so backing them up is optional. Upgrade with:

docker compose pull && docker compose up -d

Troubleshooting

  • No models in the dropdown: Open WebUI cannot reach Ollama. Check OLLAMA_BASE_URL and run docker compose logs ollama. If Ollama runs on the host, use http://host.docker.internal:11434 and add extra_hosts: ["host.docker.internal:host-gateway"].
  • Logged out after every update: WEBUI_SECRET_KEY changed or was not set. Set a fixed value in .env.
  • Responses stop mid-stream behind a proxy: raise proxy read timeouts and enable WebSockets.
  • Very slow answers: the model is running on CPU or does not fit in memory. Use a smaller model or add a GPU.

Next steps

Upload documents to a knowledge base for RAG, enable web search, create user groups with model permissions, and connect additional providers for comparison.

Spotted something out of date? Tell us and we will update the guide.

FAQ

Open-WebUI questions

Still curious? Email info@appsgit.com.

What port does Open WebUI use?

Open WebUI listens on port 8080 inside the container. The common setup, used in this guide, maps it to port 3000 on the host.

Is Open WebUI free?

Yes, Open WebUI is free to self-host. Its license is based on BSD-3-Clause with an added branding clause, which requires keeping the Open WebUI branding in larger deployments unless you have an enterprise license.

How do I connect Open WebUI to Ollama?

Set OLLAMA_BASE_URL to the address of your Ollama server, for example http://ollama:11434 when both run in the same Compose stack. You can also add or change connections later under Admin Panel, Settings, Connections.

Who becomes admin in Open WebUI?

The first account created on a fresh install becomes the administrator. Later sign-ups are set to pending until an admin approves them, unless you change the default role.

Does Open WebUI work with OpenAI or other providers?

Yes. Any OpenAI-compatible API works, including OpenAI, OpenRouter, vLLM, LM Studio and LiteLLM. Add the base URL and API key under the connection settings.