mirror of
https://github.com/open-webui/helm-charts.git
synced 2026-07-22 09:55:25 -04:00
How to configure the helm chart include TLS termination (https) into OWUI pod #31
Closed
opened 2026-02-15 19:15:36 -05:00 by yindo
·
7 comments
No Branch/Tag Specified
main
gh-pages
feat-oikb
feat-release-v0.10.2
automation/open-webui-0.10.2
feat-release-v0.10.1
automation/open-webui-0.10.1
feat-release-v0.10.0
automation/open-webui-0.10.0
feat-terminals-security
fix-openai-base-urls
v6.0.0
revert-196-issue-184/add-milvus
release-pipelines-v0.1.0
open-webui-15.2.1-dev.94.1
open-webui-15.2.1-dev.93.1
open-webui-15.2.1-dev.92.1
open-webui-15.2.1-dev.88.1
open-webui-15.2.1-dev.89.1
open-webui-15.2.1-dev.90.1
open-webui-15.2.1-dev.91.1
open-webui-15.2.1-dev.87.1
open-webui-15.2.1-dev.85.1
open-webui-15.2.1-dev.86.1
open-webui-15.2.1-dev.84.1
open-webui-15.2.1-dev.69.1
open-webui-15.2.1-dev.70.1
open-webui-15.2.1-dev.71.1
open-webui-15.2.1-dev.72.1
open-webui-15.2.1-dev.73.1
open-webui-15.2.1-dev.74.1
open-webui-15.2.1-dev.75.1
open-webui-15.2.1-dev.76.1
open-webui-15.2.1-dev.77.1
open-webui-15.2.1-dev.78.1
open-webui-15.2.1-dev.79.1
open-webui-15.2.1-dev.80.1
open-webui-15.2.1-dev.81.1
open-webui-15.2.1-dev.82.1
open-webui-15.2.1-dev.83.1
open-webui-15.2.1-dev.66.1
open-webui-15.2.1-dev.67.1
open-webui-15.2.1-dev.68.1
open-webui-15.2.1-dev.55.1
open-webui-15.2.1-dev.56.1
open-webui-15.2.1-dev.57.1
open-webui-15.2.1-dev.58.1
open-webui-15.2.1-dev.59.1
open-webui-15.2.1-dev.60.1
open-webui-15.2.1-dev.61.1
open-webui-15.2.1-dev.62.1
open-webui-15.2.1-dev.63.1
open-webui-15.2.1-dev.64.1
open-webui-15.2.1-dev.65.1
open-webui-15.2.1-dev.49.1
open-webui-15.2.1-dev.50.1
open-webui-15.2.1-dev.51.1
open-webui-15.2.1-dev.52.1
open-webui-15.2.1-dev.53.1
open-webui-15.2.1-dev.54.1
open-webui-15.2.1-dev.39.1
open-webui-15.2.1-dev.40.1
open-webui-15.2.1-dev.41.1
open-webui-15.2.1-dev.42.1
open-webui-15.2.1-dev.43.1
open-webui-15.2.1-dev.44.1
open-webui-15.2.1-dev.45.1
open-webui-15.2.1-dev.46.1
open-webui-15.2.1-dev.47.1
open-webui-15.2.1-dev.48.1
open-webui-15.2.1-dev.26.1
open-webui-15.2.1-dev.27.1
open-webui-15.2.1-dev.28.1
open-webui-15.2.1-dev.29.1
open-webui-15.2.1-dev.30.1
open-webui-15.2.1-dev.31.1
open-webui-15.2.1-dev.32.1
open-webui-15.2.1-dev.33.1
open-webui-15.2.1-dev.35.1
open-webui-15.2.1-dev.36.1
open-webui-15.2.1-dev.37.1
open-webui-15.2.1-dev.38.1
open-webui-15.2.1-dev.34.1
open-webui-15.2.1-dev.24.1
open-webui-15.2.1-dev.25.1
open-webui-15.2.1-dev.22.1
open-webui-15.2.1-dev.23.1
open-webui-15.2.1-dev.20.1
open-webui-15.2.1-dev.21.1
open-webui-15.2.1-dev.18.1
open-webui-15.2.1-dev.17.1
open-webui-15.2.1-dev.19.1
open-webui-15.2.1-dev.16.1
open-webui-15.2.0
open-webui-15.1.1-dev.15.1
open-webui-15.1.1-dev.14.1
open-webui-15.1.1-dev.13.1
open-webui-15.1.1-dev.12.1
open-webui-15.1.1-dev.11.1
open-webui-15.1.1-dev.10.1
open-webui-15.1.1-dev.7.1
open-webui-15.1.1-dev.6.1
open-webui-15.1.1-dev.9.1
open-webui-15.1.1-dev.8.1
open-webui-15.1.0
open-webui-15.0.0
terminals-0.5.0
open-webui-14.11.0
open-webui-14.10.0
pipelines-0.12.0
open-webui-14.9.0
open-webui-14.8.0
open-webui-14.7.0
terminals-0.4.0
open-webui-14.6.0
open-webui-14.5.0
open-webui-14.4.0
open-webui-14.3.0
terminals-0.3.0
open-webui-14.2.0
open-webui-14.1.0
open-webui-14.0.0
open-webui-13.3.1
open-webui-13.3.0
open-webui-13.2.1
open-webui-13.2.0
open-webui-13.1.2
open-webui-13.1.1
open-webui-13.1.0
open-webui-13.0.1
terminals-0.2.0
open-webui-13.0.0
terminals-0.1.0
open-webui-12.13.0
open-webui-12.12.0
open-webui-12.11.0
open-webui-12.10.0
open-webui-12.9.0
open-webui-12.8.1
open-webui-12.8.0
pipelines-0.11.0
open-webui-12.7.0
open-webui-12.6.0
open-webui-12.5.0
open-webui-12.4.0
open-webui-12.3.0
open-webui-12.2.0
open-webui-12.1.1
open-webui-12.1.0
open-webui-12.0.1
pipelines-0.10.1
open-webui-12.0.0
open-webui-11.1.0
open-webui-11.0.0
open-webui-10.2.1
open-webui-10.2.0
open-webui-10.1.0
open-webui-10.0.0
open-webui-9.0.0
open-webui-8.22.1
open-webui-8.22.0
open-webui-8.21.0
open-webui-8.20.0
open-webui-8.19.0
open-webui-8.18.0
open-webui-8.17.0
open-webui-8.16.0
open-webui-8.15.0
open-webui-8.14.0
open-webui-8.13.0
open-webui-8.12.3
open-webui-8.12.2
pipelines-0.10.0
open-webui-8.12.1
open-webui-8.12.0
open-webui-8.11.0
open-webui-8.10.0
open-webui-8.9.0
open-webui-8.8.0
open-webui-8.7.0
open-webui-8.6.0
open-webui-8.5.0
open-webui-8.4.0
open-webui-8.3.0
open-webui-8.2.0
pipelines-0.9.0
pipelines-0.8.0
open-webui-8.1.0
open-webui-8.0.0
open-webui-7.7.0
open-webui-7.6.0
open-webui-7.5.0
open-webui-7.4.0
open-webui-7.3.0
open-webui-7.2.0
open-webui-7.1.0
open-webui-7.0.1
open-webui-7.0.0
open-webui-6.29.0
open-webui-6.28.0
open-webui-6.27.0
open-webui-6.26.0
open-webui-6.25.0
open-webui-6.24.0
open-webui-6.23.0
open-webui-6.22.0
open-webui-6.21.0
open-webui-6.20.0
open-webui-6.19.0
open-webui-6.18.0
open-webui-6.17.0
pipelines-0.7.0
open-webui-6.16.0
open-webui-6.15.0
open-webui-6.14.0
open-webui-6.13.0
open-webui-6.12.0
open-webui-6.11.0
open-webui-6.10.0
pipelines-0.6.0
open-webui-6.9.0
open-webui-6.8.0
open-webui-6.7.0
open-webui-6.6.0
open-webui-6.5.0
open-webui-6.4.0
open-webui-6.3.0
open-webui-6.2.0
open-webui-6.1.0
open-webui-6.0.0
open-webui-5.26.0
open-webui-5.25.0
open-webui-5.24.0
open-webui-5.23.0
pipelines-0.5.0
open-webui-5.22.0
open-webui-5.21.0
open-webui-5.20.0
open-webui-5.19.0
pipelines-0.4.0
open-webui-5.18.0
open-webui-5.17.0
pipelines-0.3.0
open-webui-5.16.1
open-webui-5.16.0
pipelines-0.2.0
open-webui-5.15.0
open-webui-5.14.0
open-webui-5.13.0
open-webui-5.12.0
open-webui-5.11.0
open-webui-5.10.1
open-webui-5.10.0
open-webui-5.4.0
open-webui-5.3.0
pipelines-0.1.0
open-webui-5.2.0
open-webui-5.1.1
open-webui-5.1.0
open-webui-5.0.1
open-webui-5.0.0
open-webui-4.1.0
open-webui-4.0.7
pipelines-0.0.6
open-webui-4.0.6
pipelines-0.0.5
open-webui-4.0.5
open-webui-4.0.4
open-webui-4.0.3
open-webui-4.0.2
open-webui-4.0.1
v3.8.0
open-webui-3.8.0
open-webui-4.0.0
v3.7.0
v3.6.0
v1.0.0
open-webui-3.6.0
open-webui-3.5.1
open-webui-3.5.0
open-webui-3.4.3
open-webui-3.4.0
open-webui-3.3.2
open-webui-3.3.1
open-webui-3.3.0
open-webui-3.2.0
open-webui-3.1.19
open-webui-3.1.18
open-webui-3.1.17
open-webui-3.1.16
open-webui-3.1.15
open-webui-3.1.14
open-webui-3.1.13
open-webui-3.1.12
open-webui-3.1.11
open-webui-3.1.10
open-webui-3.1.9
open-webui-3.1.8
open-webui-3.1.7
open-webui-3.1.6
pipelines-0.0.4
open-webui-3.1.5
open-webui-3.1.4
open-webui-3.1.3
open-webui-3.1.2
open-webui-3.1.1
open-webui-3.1.0
open-webui-3.0.10
open-webui-3.0.9
open-webui-3.0.8
open-webui-3.0.7
open-webui-3.0.6
open-webui-3.0.5
open-webui-3.0.4
open-webui-3.0.3
open-webui-3.0.2
pipelines-0.0.3
open-webui-3.0.1
pipelines-0.0.2
open-webui-3.0.0
pipelines-0.0.1
open-webui-2.1.0
open-webui-2.0.2
open-webui-2.0.1
open-webui-1.0.1
open-webui-1.0.0
No Label
enhancement
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: open-webui/helm-charts#31
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @brokedba on GitHub (Sep 2, 2024).
I want to expose my open web ui in the cloud using TLS termination (since the Ip address is not localhost it is not recognized as safe so no mic or device can accessed from the browser).
I have the below values for the OpnWebUI helm chart and I think I secrewed it up a bit between the ingress and the loadbalancer service. I want to add a tsl secret and get the https termination accessible. I assume I need to keep the service
clusterIPand add a TLS secret to the ingress to forward http traffic to https but really benefit from your help.My K8 is in Oracle cloud OCI btw.
@westbrook-ai commented on GitHub (Sep 2, 2024):
Hey @brokedba, these are the relevant lines of the Helm chart for TLS: https://github.com/open-webui/helm-charts/blob/main/charts/open-webui/templates/ingress.yaml#L17-L21
If you have a TLS secret to use created on your cluster already, it looks like you need to set the
tlsvalue totrue, and set the.Values.ingress.existingSecretvalue to the name of that secret in your K8s cluster. This should get your TLS termination working.If you need to try a different approach, I see Oracle has a guide to set up an Nginx ingress controller on their Kubernetes service, so this might be worth the read: https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contengsettingupingresscontroller.htm. I'm doing something similar to this approach on my clusters using the AWS ALB Ingress Controller.
Please let me know if you find a fix, or any further issues with the chart while trying to implement one!
@brokedba commented on GitHub (Sep 2, 2024):
Hi @0xThresh , the ingress controller was actually the default nginx.
https actually works already as by default the ingress class chosen is nginx . The ingress controller service is a loadbalancer and the ingress of the openwebui shares the same IP.
ingress-controller has the same external IP
-I think it's probably the default ingress controller which creates a self signed certificate.
Regarding tls secret ingress cofig
when I tried to create a ingress with a tls existing secret , I had the below error . I'm probably clueless of FQDN tls fundamentals , I tried with both empty and random domain value so try resolving the HTTPS://ingress_IP, but RFC 1123 didn't like it.
@westbrook-ai commented on GitHub (Sep 2, 2024):
If you check the chart's
ingress.yamlfile, you'll see that thehostvalue is used to populate the TLS host and the typical routes host. You're trying to pass the wholehostsblock which isn't a valid value for the chart, and that explains why you're getting an error stating that the hostname is""since thehostvalue isn't being set in the values you sent.I think these values will work better:
@brokedba commented on GitHub (Sep 3, 2024):
You are right , somehow I use the syntax with hosts without knowing how it ended there . Probably a copy paste gone wrong (from another helm chart , ollama ?) .
However , even if the error is gone I now have conflict with the ingress IP with error 404.
I have to remove the tls config again and see if I can recover the TLS termination with that same IP.
@brokedba commented on GitHub (Sep 3, 2024):
@0xThresh
the only way to avoid the nginx conflict (404 not found) in my K8 config on OCI is to remove the host value all together .
This fixed it and I could use the IP of the nginx controller to access openwebui service (via redirection).
I'll leave it like this . I'm sure every cloud has it's own particularity but on OCI , I don't need to define a tls cert or host if the class is the default nginx which is fine by me .
@westbrook-ai commented on GitHub (Sep 12, 2024):
Thanks for reporting back. We can look at re-working the ingress in the template to only define the host if it's included as a value to help any future OCI users.
@brokedba commented on GitHub (Nov 30, 2024):
What I noticed in other addon helm based installation in OCI is that there if the microservice is expecting a path i.e /webui
the ingress can be created with a host matching it.
I found this in their kubernetes terraform module.
ingress_hostsvariable. (i.e ="k8sapp.28e9459d.nip.io")