Ollama and Dome
Models on your own hardware with Ollama, governed like any provider.
Ollama runs models on a workstation or a server you own. Dome treats it as one more provider, so its calls get the same rules and audit as a hosted model. The one requirement: the Gateway must be able to reach the Ollama URL.
How Dome helps
Dome provides model brokering and routing for Ollama
Any model Ollama runs
Use Dome's openai_compatible provider with Ollama's /v1 address. The model tag you pulled is the model id.
A second server behind it
Pool Ollama with a vLLM server serving the same model. When Ollama fails, the call goes to vLLM.
Development stays in development
Tag Ollama connections env: dev. A rule on each production agent refuses them.
Get started
Connect Ollama in three steps
Connect the server, expose it to the Gateway, and pool a second server if you run one.
01
Add the connection
Use the provider id openai_compatible and Ollama's /v1 URL. Ollama ignores API keys, so set no credential.
$ dome models add gpt-oss-ollama \--provider openai_compatible \--endpoint http://ollama.internal.example.com:11434/v1 \--model gpt-oss:20b \--auth-method none --credential-type none \--attributes '{"env":"dev"}' \--gateway dev-gateway02
Expose it to the Gateway
Dome's hosted gateway can't see localhost or a private network. Ollama needs an address it can reach.
03
Pool it and call the Gateway
Ollama goes first and vLLM second. Your client calls gpt-oss-20b with the agent's Dome key.
$ dome models pool create gpt-oss-20b \--failover-max all --gateway dev-gateway$ dome models pool member add gpt-oss-20b gpt-oss-ollama --priority 0$ dome models pool member add gpt-oss-20b gpt-oss-vllm --priority 1
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Ollama itself, see Ollama's documentation.
Rules
Production agents stay off dev models
Applied to a production agent with --agent, this refuses any connection tagged env: dev. A workstation model never answers a customer.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has env && resource.env == "dev" };Agent workflow
Bringing it together
Connecting Ollama to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
How does Dome connect to Ollama?
Dome's openai_compatible provider, pointed at Ollama's /v1 API. No API key, since Ollama doesn't check one.
Can a Dome-hosted gateway reach Ollama on my laptop?
No. It can't reach localhost or a private network, so expose Ollama on a URL the gateway can reach.
Which model names do I use?
Ollama's own tags, such as gpt-oss:20b or qwen3:8b. Dome passes the tag through unchanged.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Codex
Codex on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all