Sitemap

Securely Expose Remote Ollama Endpoints to your Development Machine

6 min readJul 1, 2025

--

Press enter or click to view image in full size

Be aware that this blueprint may incur additional costs related to ingress and egress data.

If you don’t currently have an Ollama setup, please refer to the official guide for both manual and automated installation options available at this link.

Make sure you add Ollama as a startup service.

Although we configured Ollama service to listen to any interface, we want to restrict access to the Ollama endpoint only to resources that reside inside the same VPC and not to anyone that might potentially reach this VM, 0.0.0.0/0.

The VPC CIDR for this lab was 192.168.10.0/24, this might differ in your environment given your individual configuration of the VPC and its Subnets so adjust the Source of the Inbound Rule accordingly.

Once the P2S VPN connection is established, your development machine will technically be part of this VPC and will be able to access the Ollama endpoint.

Ensure that the VPN connection is already established.192.168.10.183 is the private IP address assigned by the DHCP server of our VPC to the ECS Server that Ollama is installed on. Remember from the step before that the VPC CIDR for this lab was 192.168.10.0/24, this might differ in your environment given your individual configuration of the VPC and its Subnets.

Press enter or click to view image in full size

--

--

Akriotis Kyriakos
Akriotis Kyriakos

Written by Akriotis Kyriakos

Talking about: Kubernetes, Golang, T Cloud Public (fka Open Telekom Cloud), AWS, OpenStack, CloudStack and Proxmox.