Dome Systems

Ollama and Dome

Models on your own hardware with Ollama, governed like any provider.

Ollama runs models on a workstation or a server you own. Dome treats it as one more provider, so its calls get the same rules and audit as a hosted model. The one requirement: the Gateway must be able to reach the Ollama URL.

PeopleAgentsDomePool: gpt-oss-20bCallersPeopleAgentsdev-agentAgentstest-writerAgentsbilling-agentGatewaysdev-gatewayOllamagpt-oss:20b, priority 0qwen3:8bOllama, no poolvLLMopenai/gpt-oss-20b, priority 1RulesGuardsAuditsaudit-trail
dev-agent→gpt-oss-20b· as s.patelAllowed

How Dome helps

Dome provides model brokering and routing for Ollama

Any model Ollama runs

Use Dome's openai_compatible provider with Ollama's /v1 address. The model tag you pulled is the model id.

A second server behind it

Pool Ollama with a vLLM server serving the same model. When Ollama fails, the call goes to vLLM.

Development stays in development

Tag Ollama connections env: dev. A rule on each production agent refuses them.

Get started

Connect Ollama in three steps

Connect the server, expose it to the Gateway, and pool a second server if you run one.

  1. 01

    Add the connection

    Use the provider id openai_compatible and Ollama's /v1 URL. Ollama ignores API keys, so set no credential.

    $ dome models add gpt-oss-ollama \
    --provider openai_compatible \
    --endpoint http://ollama.internal.example.com:11434/v1 \
    --model gpt-oss:20b \
    --auth-method none --credential-type none \
    --attributes '{"env":"dev"}' \
    --gateway dev-gateway
  2. 02

    Expose it to the Gateway

    Dome's hosted gateway can't see localhost or a private network. Ollama needs an address it can reach.

  3. 03

    Pool it and call the Gateway

    Ollama goes first and vLLM second. Your client calls gpt-oss-20b with the agent's Dome key.

    $ dome models pool create gpt-oss-20b \
    --failover-max all --gateway dev-gateway
     
    $ dome models pool member add gpt-oss-20b gpt-oss-ollama --priority 0
    $ dome models pool member add gpt-oss-20b gpt-oss-vllm --priority 1

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Ollama itself, see Ollama's documentation.

Rules

Production agents stay off dev models

Applied to a production agent with --agent, this refuses any connection tagged env: dev. A workstation model never answers a customer.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { resource has env && resource.env == "dev" };

Agent workflow

Bringing it together

Connecting Ollama to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How does Dome connect to Ollama?

Dome's openai_compatible provider, pointed at Ollama's /v1 API. No API key, since Ollama doesn't check one.

Can a Dome-hosted gateway reach Ollama on my laptop?

No. It can't reach localhost or a private network, so expose Ollama on a URL the gateway can reach.

Which model names do I use?

Ollama's own tags, such as gpt-oss:20b or qwen3:8b. Dome passes the tag through unchanged.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.