Before you let other computers reach Ollama: a security note
Making Ollama listen on the network lets any device that can reach that port use your models. Ollama’s documentation describes no sign-in for it, so keep it on a network you trust.
Last checked against the app on · View as Markdown
Steps
- Know what the setting does. OLLAMA_HOST set to 0.0.0.0 makes Ollama accept connections on every network address of that machine, not only from itself.
- Ollama’s documentation describes no username or key for its local server. Treat anything that can reach the port as able to use the models and to see what you send. That is an inference from the documentation, not a statement Ollama makes.
- Keep it to a network you trust, such as your home or office network. Do not forward the port from your router to the internet.
- If you need access from elsewhere, Ollama’s FAQ describes putting a proxy server such as Nginx in front, or a tunnel. Those add their own steps and risks that are outside this guide.
- To undo it, remove the OLLAMA_HOST setting, or set it back to 127.0.0.1:11434, restart Ollama, and put NeuralVault’s address back to http://localhost:11434.
How to tell it worked
From another computer, http://your-address:11434/api/tags no longer answers once you have undone the setting and restarted Ollama.
If it does not work
- You are not sure whether Ollama is exposed.
- From a different computer on the network, open http://the-machine-address:11434/api/tags. If it lists models, it is exposed.