# How to self-host Open WebUI with Docker Compose

> Deploy Open WebUI with Docker Compose and connect it to Ollama or any OpenAI-compatible API: secret key, admin account, HTTPS, backups and safe upgrades.

## Key facts

| Fact | Value |
|---|---|
| App | Open-WebUI (https://appsgit.com/apps/open-webui) |
| Difficulty | beginner |
| Time | about 15 minutes |
| Requirements | 2 vCPU / 4 GB RAM (plus model memory if Ollama runs on the same host); Docker + Docker Compose v2; Ollama or an OpenAI-compatible API key; A domain name (optional, for HTTPS) |
| Last updated | 2026-10-06 |

## What is Open WebUI?

Open WebUI is a self-hosted chat interface for large language models that looks and works much like ChatGPT. It is open source, published under a BSD-3-Clause-based license with a branding clause, and connects to local models through Ollama or to any OpenAI-compatible API. It adds multi-user accounts, document chat (RAG), web search, tools and pipelines on top.

## Requirements

- A Linux server with 2 vCPU and 4 GB of RAM for Open WebUI itself.
- Docker Engine and Docker Compose v2.
- A model backend: Ollama on the same or another machine, or an API key for an OpenAI-compatible provider.

Running local models needs far more resources than the UI: plan for 8 GB of RAM or VRAM for a 7-8B model. See our Ollama guide for sizing.

## Step 1: Prepare the server

This guide assumes Ubuntu 24.04 with Docker installed. If you need Docker, follow the [official install guide](https://docs.docker.com/engine/install/ubuntu/). Create a project folder:

```bash
mkdir -p ~/open-webui && cd ~/open-webui
```

## Step 2: Create the Docker Compose file

This stack runs Open WebUI and Ollama together. If you only want to use a cloud API, delete the `ollama` service and the `OLLAMA_BASE_URL` line. Save as `docker-compose.yml`:

```yaml
services:
  ollama:
    image: ollama/ollama:latest
    restart: unless-stopped
    volumes:
      - ollama:/root/.ollama
    # Uncomment for NVIDIA GPUs (requires the NVIDIA Container Toolkit):
    # deploy:
    #   resources:
    #     reservations:
    #       devices:
    #         - driver: nvidia
    #           count: all
    #           capabilities: [gpu]

  open-webui:
    image: ghcr.io/open-webui/open-webui:main
    restart: unless-stopped
    depends_on:
      - ollama
    ports:
      - "3000:8080"
    environment:
      OLLAMA_BASE_URL: http://ollama:11434
      WEBUI_SECRET_KEY: ${WEBUI_SECRET_KEY}
      WEBUI_URL: https://chat.example.com
    volumes:
      - open-webui:/app/backend/data

volumes:
  ollama:
  open-webui:
```

Create `.env`:

```bash
WEBUI_SECRET_KEY=CHANGE_ME
```

Generate it with `openssl rand -hex 32`. Open WebUI signs login tokens with this key. If you do not set it, it generates one on first run and stores it in the data volume, but an explicit key keeps sessions valid across container rebuilds. Ollama is not published to the host at all: only Open WebUI talks to it over the internal Docker network, which matters because Ollama has no authentication. The `main` tag tracks the latest release. To pin, use a version tag such as `v0.11.4` from the [releases page](https://github.com/open-webui/open-webui/releases).

## Step 3: Start and open the app

```bash
docker compose up -d
docker compose exec ollama ollama pull llama3.2
```

The second command downloads a small model to test with. Open `http://YOUR_SERVER_IP:3000` and create an account: on a fresh install the first account becomes the admin. Pick the model from the dropdown and start chatting. To add OpenAI or another provider, go to Admin Panel, Settings, Connections and enter the base URL and API key.

## Step 4: Put it behind HTTPS

With [Caddy](https://caddyserver.com/docs/):

```caddyfile
chat.example.com {
    reverse_proxy 127.0.0.1:3000
}
```

Open WebUI streams responses over WebSockets, which Caddy handles automatically. In Nginx Proxy Manager, enable "Websockets Support" and raise timeouts for long generations. Once HTTPS works, map the port as `"127.0.0.1:3000:8080"`. Under Admin Panel, Settings, General, review whether new sign-ups are allowed and which role they get.

## Backups and upgrades

All Open WebUI state is in the `open-webui` volume: the SQLite database with users and chats, uploaded documents, and the vector store used for RAG. Back it up with a temporary container:

```bash
docker run --rm -v open-webui_open-webui:/data -v "$PWD":/backup alpine tar czf /backup/open-webui-$(date +%F).tgz -C /data .
```

Models in the `ollama` volume can be re-downloaded, so backing them up is optional. Upgrade with:

```bash
docker compose pull && docker compose up -d
```

## Troubleshooting

- **No models in the dropdown:** Open WebUI cannot reach Ollama. Check `OLLAMA_BASE_URL` and run `docker compose logs ollama`. If Ollama runs on the host, use `http://host.docker.internal:11434` and add `extra_hosts: ["host.docker.internal:host-gateway"]`.
- **Logged out after every update:** `WEBUI_SECRET_KEY` changed or was not set. Set a fixed value in `.env`.
- **Responses stop mid-stream behind a proxy:** raise proxy read timeouts and enable WebSockets.
- **Very slow answers:** the model is running on CPU or does not fit in memory. Use a smaller model or add a GPU.

## Next steps

Upload documents to a knowledge base for RAG, enable web search, create user groups with model permissions, and connect additional providers for comparison.

## FAQ

### What port does Open WebUI use?

Open WebUI listens on port 8080 inside the container. The common setup, used in this guide, maps it to port 3000 on the host.

### Is Open WebUI free?

Yes, Open WebUI is free to self-host. Its license is based on BSD-3-Clause with an added branding clause, which requires keeping the Open WebUI branding in larger deployments unless you have an enterprise license.

### How do I connect Open WebUI to Ollama?

Set OLLAMA_BASE_URL to the address of your Ollama server, for example http://ollama:11434 when both run in the same Compose stack. You can also add or change connections later under Admin Panel, Settings, Connections.

### Who becomes admin in Open WebUI?

The first account created on a fresh install becomes the administrator. Later sign-ups are set to pending until an admin approves them, unless you change the default role.

### Does Open WebUI work with OpenAI or other providers?

Yes. Any OpenAI-compatible API works, including OpenAI, OpenRouter, vLLM, LM Studio and LiteLLM. Add the base URL and API key under the connection settings.

Prefer not to do it yourself? [appsgit installation help](https://appsgit.com/services/install) installs it on your server for a fixed quote.

---

Canonical page: https://appsgit.com/guides/open-webui
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
