otari-openwebui-k8s logo

otari-openwebui-k8s

Free

An easy guide on how to securely deploy Otari (from mozilla-ai) and Open WebUI on k8s cluster.

Quick Facts

Pricing
Free
6
views
0
favorites
Added
Aug 2026
Official URL
szwendacz99.github.io

Tool overview

Overview

The "Secure Otari + Open WebUI Kubernetes Setup" is a guide that demonstrates how to install and configure Otari and Open WebUI securely in a Kubernetes cluster, using the self-hosted k3s distribution as an example. Otari is described as "an OpenAI-compatible LLM gateway you own and run yourself," while Open WebUI is "an extensible, feature-rich, and user-friendly self-hosted AI platform." The guide aims to have both applications installed and configured securely in a k8s cluster. The setup applies several security features, including "network policies together with tinyproxy for connection logging and allowing only outbound https (port 443)," "read-only pods with volumes for storing persistent data," "non-root UID/GID," "custom SELinux MCS labels," "default seccomp profile (RuntimeDefault) and dropped Linux capabilities," "sensitive values kept in Kubernetes Secrets," and "memory limits." These measures are intended to harden the deployment. The guide covers the necessary Kubernetes objects: namespace configuration, persistent storage via PersistentVolumeClaims for Otari's SQLite database and Open WebUI's data, deployments for Otari, Open WebUI, and Tinyproxy, services, network policies, ingress, and kustomization. It also outlines initial deployment steps and how to set up the Otari connection in Open WebUI, including creating an API key in Otari, creating an admin account in Open WebUI, adding the Otari connection, and verifying it.

Features

  • AI assistant
  • Natural language interface
  • Workflow automation

Tags

ai-tools
ai
containers
deployment
kubernetes
ai assistant
automation

Use Cases

  • Teams use this guide to deploy Otari and Open WebUI securely on Kubernetes.

  • Teams use network policies and tinyproxy to log connections and restrict outbound traffic to HTTPS.

  • Teams use read-only pods with persistent volumes to store data securely.

  • Teams use non-root UID/GID and SELinux MCS labels to enforce pod security.

  • Teams use Kubernetes Secrets to manage sensitive values.

  • Teams use memory limits to control resource consumption.

User Reviews

No reviews yet. Be the first to share your experience!

Rankings & collections