Skip to main content

Open WebUI

Open WebUI is an AI workspace for chatting with Ollama and compatible model providers. Moltern deploys it with a protected administrator account, persistent workspace data and a live HTTPS address.

Connect a private Ollama service from the same environment to keep its model API off the public internet while making selected models available in Open WebUI.

Before You Start​

You need:

  • a Moltern workspace and environment;
  • permission to create services and private connections;
  • an administrator name, email and strong password;
  • at least 100 mCPU and 512 MiB of available runtime capacity;
  • workspace storage for conversations, settings and uploaded content;
  • an Ollama service with a downloaded model for private inference.

The Open WebUI administrator is separate from your Moltern account. Store the password in your organisation's password manager.

Deploy Open WebUI​

  1. Open Services and select Open WebUI.
  2. Enter a unique service name.
  3. Select the project and environment.
  4. Review the initial capacity.
  5. Enter the initial administrator details.
  6. Select Preview deploy.
  7. Review the workload and storage impact.
  8. Select Confirm deploy and wait for Running.

Open WebUI deployment form with protected administrator fields

Open WebUI deployment preview

This profile has no managed database dependency. A separately deployed Ollama service provides private models only after you attach it explicitly.

Moltern prepares the protected first owner before reporting the service ready. Do not expose or share the generated address while deployment is still in progress.

Sign In​

  1. Open the service from Moltern.
  2. Enter the administrator email and password configured during deployment.
  3. Select Sign in.
  4. Dismiss upstream release notes when they appear.

Protected Open WebUI administrator sign-in

An authorised workspace member can use Moltern's protected connection-details flow when the original managed credential must be recovered. Credentials do not belong in browser screenshots, source control or chat prompts.

Connect Private Ollama​

Deploy Ollama in the same environment and pull a model before connecting it.

  1. Open Open WebUI in Moltern.
  2. Open Access or Private service connections.
  3. Select Connect service.
  4. Choose the Ollama service.
  5. Confirm the connection.
  6. Wait for Open WebUI to return to Running.

Moltern updates only the Open WebUI workload and grants it scoped access to the selected Ollama service. Ollama remains private and can be shared only with other workloads that receive their own explicit connection.

Select A Model And Chat​

  1. Open a new chat.
  2. Open the model selector.
  3. Choose a model returned by the private Ollama service.
  4. Send a short controlled prompt.
  5. Confirm a visible assistant response appears.

Open WebUI chat with a visible private Ollama response

The first response can be slower while model weights load. If the model appears but does not answer, test it directly in Ollama and compare its memory needs with the available Ollama capacity.

Add Compatible Providers​

Open WebUI can use additional provider endpoints. Before adding one:

  • create a least-privilege provider credential;
  • keep it in protected configuration;
  • review the provider's data processing and retention terms;
  • test with non-sensitive content;
  • document credential ownership and rotation.

The validated Moltern workflow in this guide uses private Ollama. Other providers require separate testing for authentication, networking and billing.

Data And Persistence​

Open WebUI stores accounts, conversations, settings and supported local content in its assigned workspace path. The runtime sees only the path assigned to this service, not the complete team filespace.

Moltern does not request a separate cloud disk for this profile. Storage is measured under the Open WebUI workload.

Production validation performs Stop service and Start service, signs in again, rediscovers the attached model and requires another visible response.

Open WebUI chat after runtime replacement

Stop/Start validates runtime replacement and workspace persistence. It is not an independent backup restoration test.

Capacity And Metering​

The validated baseline is:

ResourceValidated value
Instances1
CPU request100 mCPU
Memory request512 MiB
Dedicated volume0 GiB

Open WebUI files and Ollama model files are measured under separate workload paths. Review both when estimating the complete private-chat cost.

Resize Open WebUI when its web process is constrained. Resize Ollama when model loading or inference is constrained.

Operate Open WebUI​

Use the Moltern service page for:

  • Overview to open the workspace and review health;
  • Live Logs to diagnose startup, sign-in and provider errors;
  • Capacity to adjust CPU and memory;
  • Access to add or revoke private service connections;
  • Settings to review protected configuration;
  • Stop service and Start service to replace the runtime without deleting workspace data.

Delete Open WebUI​

  1. Export conversations or content that must be retained.
  2. Revoke provider credentials that are no longer needed.
  3. Open the Open WebUI service in Moltern.
  4. Select Delete Service.
  5. Select Delete stored data only when the workspace may be removed.
  6. Complete protected confirmation.
  7. Confirm the service, address, assigned path and active allocation are gone.

A separately created Ollama service is not deleted with Open WebUI.

Frequently Asked Questions​

Does Open WebUI include a model?​

No. Attach a private Ollama service with a downloaded model or configure an approved compatible provider.

Why can the first startup take longer?​

Open WebUI may download and prepare supported local assets during its first startup. Moltern retains supported cache data in the service's assigned path so later runtime replacements do not need to repeat every download.

Does private Ollama receive a public URL?​

No. Open WebUI receives a scoped internal connection. Other workloads need their own explicit attachment.

Troubleshooting​

SymptomWhat to check
Sign-in page does not accept the ownerUse the exact email and password entered during deployment and confirm the service is Running.
No models appearConfirm Ollama is Running, contains a model and is connected in the same environment. Wait for the Open WebUI rollout to finish.
A model is visible but does not answerTest the same model through Ollama, check Ollama logs and verify the model fits available memory.
The first response is slowAllow for cold model loading, then compare a second prompt. Use a smaller model when necessary.
Release notes cover the chatComplete or dismiss the upstream release-note dialog once per browser profile.
Workspace storage grows quicklyReview uploaded content and conversations, then check Billing → Storage by workload.
Data disappeared after deletionDelete stored data is destructive. Restore only from an independently tested export or backup.

Validated Scope​

The production customer E2E covers UI deployment, protected administrator authentication, private Ollama attachment, model discovery, direct completion, model selection in the browser, a visible assistant response, runtime replacement, post-restart inference, point-in-time metering and protected cleanup.

Large uploads, external providers, multiple concurrent users, GPU behavior, sustained load, high availability, independent restore and elapsed invoice reconciliation remain outside this validation.

Official Resources​