<!-- llms-explorer concept facts · https://llms-explorer.com/tree/llama-server-router-child-bind-address-versus-ro/ · pack 2026-10-05 · ~885 tokens -->

# llama-server router child bind address versus router --host

> The source defines `#define CHILD_ADDR "127.0.0.1"` for router children.

Parent: [Mac local LLMs: llama.cpp internals](https://llms-explorer.com/tree/mac-local-llms-llama-cpp-internals/) · 2 facets · 12 facts · page: https://llms-explorer.com/tree/llama-server-router-child-bind-address-versus-ro/

## Facts

- The source defines `#define CHILD_ADDR "127.0.0.1"` for router children. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- `server_model_meta::update_args` sets `LLAMA_ARG_HOST` to `CHILD_ADDR`, `LLAMA_ARG_PORT` to the instance port and `LLAMA_ARG_ALIAS` to the model name before rendering child arguments. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- RESOLVES: llama-server-router-mode-child-instance-exposure.md ("no cached source states the child bind address"): children bind 127.0.0.1 regardless of the router's `--host`. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- The router calls children with an HTTP client constructed from `CHILD_ADDR` and the child port. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- The child port is taken from `common_http_get_free_port()` at load time and the load throws "failed to get a port number" if it is not positive. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- `unset_reserved_args` removes `LLAMA_ARG_SSL_KEY_FILE`, `LLAMA_ARG_SSL_CERT_FILE`, `LLAMA_API_KEY`, `LLAMA_ARG_API_KEY_FILE`, `LLAMA_ARG_MODELS_DIR`, `LLAMA_ARG_MODELS_MAX`, `LLAMA_ARG_MODELS_PRESET` and `LLAMA_ARG_MODELS_AUTOLOAD` from every child, and also `LLAMA_ARG_MODEL`, `LLAMA_ARG_MMPROJ`, `LLAMA_ARG_ALIAS` and `LLAMA_ARG_HF_REPO` for model-level overrides. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- Children therefore never receive the router's TLS key or certificate and serve plain HTTP on loopback. — source: `asserted`
- The router takes the child environment from its own environment (`get_environment()` reading `environ`), then applies the preset overrides. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
- Measured on this Mac: the Ollama 0.34.4 Homebrew `llama-server` (build 11081, commit 161755f29) given `--models-dir <dir> --models-max 1 --host 0.0.0.0` lists the model, then exits with `failed to initialize router models: subprocess is not enabled on this build`. — source: `asserted`
- Ollama starts its single llama-server with `--host 127.0.0.1` and a free port, so a LAN-visible Ollama server is the Go front end only. — [source](https://raw.githubusercontent.com/ollama/ollama/main/llm/llama_server.go)
- Practical rule: put authentication and TLS on the router, bind the router to the LAN only when needed, and treat the router host's local users as able to reach every loaded model without a key. — source: `asserted`

## Corrections and disagreements

- CONTRADICTS: llama-server-router-mode-child-instance-exposure.md, last claim ("anyone who can reach a child port can call it with no key" on a LAN-bound router): a child port is reachable only from the router host itself, so the keyless exposure is local. — [source](https://raw.githubusercontent.com/ggml-org/llama.cpp/master/tools/server/server-models.cpp)
