Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (main, 2026-09-14), podman (main, 2026-09-14); Proxmox VM: docker (main, 2026-09-14), podman (main, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
open-webui:
container_name: njorddeploy-open-webui
image: "ghcr.io/open-webui/open-webui:main"
volumes:
- "./data/open-webui/data:/app/backend/data"
ports:
- "3000:8080"
environment:
- "OLLAMA_BASE_URL=http://ollama:11434"
- "WEBUI_SECRET_KEY=njorddeploy_secret_key_openwebui_2026"
- "OPENAI_API_KEY="
networks:
- njorddeploy_net
restart: unless-stopped
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
OPEN_WEBUI_PORT |
3000 |
The port on the host to access the Open WebUI interface. |
OLLAMA_BASE_URL |
http://ollama:11434 |
URL of the Ollama server (e.g. http://ollama:11434 for local Ollama, or http://<IP>:11434 for remote). |
WEBUI_SECRET_KEY |
njorddeploy_secret_key_openwebui_2026 |
A secret key for Open WebUI sessions. Generate a strong, random string. |
OPENAI_API_KEY |
*None* |
Optional: Your OpenAI API key for OpenAI API usage. Leave empty if not using OpenAI. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.