diff --git a/README.md b/README.md index 8df6113..dbe161b 100644 --- a/README.md +++ b/README.md @@ -83,6 +83,7 @@ Each links to its own README for variables, ports, and storage. | [gitea-mirror](gitea-mirror/README.md) | Gitea + PostgreSQL + gitea-mirror, mirroring GitHub repos | | [goclaw](goclaw/README.md) | Multi-tenant AI agent gateway, with pgvector PostgreSQL | | [litellm](litellm/README.md) | LiteLLM proxy in front of many LLM providers, with PostgreSQL and Redis | +| [open-webui](open-webui/README.md) | Open WebUI chat interface for OpenAI-compatible and Ollama providers | | [opencode](opencode/README.md) | opencode coding agent, served as a browser UI | | [paseo](paseo/README.md) | Paseo coding-agent daemon and web UI | | [traffmonetizer](traffmonetizer/README.md) | TraffMonetizer bandwidth-sharing client | diff --git a/open-webui/.env.example b/open-webui/.env.example new file mode 100644 index 0000000..6918673 --- /dev/null +++ b/open-webui/.env.example @@ -0,0 +1,15 @@ +# Copy to .env and fill in. Never commit .env. +# +# cp .env.example .env + +# Signs login sessions and encrypts stored secrets. Keep it stable. +# Generate one with: openssl rand -hex 32 +WEBUI_SECRET_KEY= + +# Let every user see every model, without per-model access grants. +BYPASS_MODEL_ACCESS_CONTROL=true + +# Connections seeded on first start; afterwards they are managed in the admin UI. +# OPENAI_API_BASE_URL= +# OPENAI_API_KEY= +# OLLAMA_BASE_URL= diff --git a/open-webui/README.md b/open-webui/README.md new file mode 100644 index 0000000..f76cf7b --- /dev/null +++ b/open-webui/README.md @@ -0,0 +1,49 @@ +# open-webui + +[Open WebUI](https://docs.openwebui.com): a chat UI for OpenAI-compatible and +Ollama model providers, with users, chat history, documents and RAG. + +One container, serving on port `8080`. It stores everything in SQLite and a +local vector database under `/app/backend/data`. + +## Setup + +1. Set `WEBUI_SECRET_KEY`. +2. Map the domain to port `8080` and deploy. +3. Open the domain. The first account to sign up becomes the admin. +4. Add model connections in **Admin Settings → Connections**. + +Health check: `GET /`, also the compose healthcheck. + +## Environment + +| Variable | Default | Purpose | +| --- | --- | --- | +| `WEBUI_SECRET_KEY` | — | Signs login tokens and encrypts stored secrets | +| `BYPASS_MODEL_ACCESS_CONTROL` | `true` | Every user sees every model | +| `OPENAI_API_BASE_URL` / `OPENAI_API_KEY` | optional | OpenAI-compatible connection seeded on first start | +| `OLLAMA_BASE_URL` | optional | Ollama connection seeded on first start | + +`WEBUI_SECRET_KEY` is required. Without it, `start.sh` generates a key into +`/app/backend/.webui_secret_key`, outside the data volume, so every +recreated container gets a new key: everyone is logged out, and anything +encrypted with the old key can no longer be read. + +`BYPASS_MODEL_ACCESS_CONTROL` is on because this is a single-person instance: +models do not need to be shared with users one by one. + +The connection variables are optional because Open WebUI keeps its +connections in the database. They seed it only on first start, so once +connections exist the admin UI is where they change. + +## Storage + +| Volume | Mount | Holds | +| --- | --- | --- | +| `open-webui` | `/app/backend/data` | `webui.db`, uploads, the vector database, and model cache | + +## Image + +`ghcr.io/open-webui/open-webui:latest` is the latest release. Upstream +publishes no major tag; `main` is built from every commit on the development +branch, so `latest` is the stable moving tag. diff --git a/open-webui/compose.yml b/open-webui/compose.yml new file mode 100644 index 0000000..02932ad --- /dev/null +++ b/open-webui/compose.yml @@ -0,0 +1,20 @@ +services: + open-webui: + image: ghcr.io/open-webui/open-webui:latest + restart: unless-stopped + environment: + - WEBUI_SECRET_KEY=${WEBUI_SECRET_KEY:?required} + - BYPASS_MODEL_ACCESS_CONTROL=${BYPASS_MODEL_ACCESS_CONTROL:-true} + # - OPENAI_API_BASE_URL=${OPENAI_API_BASE_URL:-} + # - OPENAI_API_KEY=${OPENAI_API_KEY:-} + # - OLLAMA_BASE_URL=${OLLAMA_BASE_URL:-} + volumes: + - open-webui:/app/backend/data + healthcheck: + test: ["CMD", "curl", "-f", "http://127.0.0.1:8080"] + interval: 5s + timeout: 30s + retries: 10 + +volumes: + open-webui: