llama-server router child bind address versus router --host
Parent: Mac local LLMs: llama.cpp internals · Published reference · snapshot 2026-10-05
↓ Facts as markdownall context files
The source defines `#define CHILD_ADDR "127.0.0.1"` for router children.
These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.
Facts
- The source defines `#define CHILD_ADDR "127.0.0.1"` for router children. [source]
- `server_model_meta::update_args` sets `LLAMA_ARG_HOST` to `CHILD_ADDR`, `LLAMA_ARG_PORT` to the instance port and `LLAMA_ARG_ALIAS` to the model name before rendering child arguments. [source]
- RESOLVES: llama-server-router-mode-child-instance-exposure.md ("no cached source states the child bind address"): children bind 127.0.0.1 regardless of the router's `--host`. [source]
- The router calls children with an HTTP client constructed from `CHILD_ADDR` and the child port. [source]
- The child port is taken from `common_http_get_free_port()` at load time and the load throws "failed to get a port number" if it is not positive. [source]
- `unset_reserved_args` removes `LLAMA_ARG_SSL_KEY_FILE`, `LLAMA_ARG_SSL_CERT_FILE`, `LLAMA_API_KEY`, `LLAMA_ARG_API_KEY_FILE`, `LLAMA_ARG_MODELS_DIR`, `LLAMA_ARG_MODELS_MAX`, `LLAMA_ARG_MODELS_PRESET` and `LLAMA_ARG_MODELS_AUTOLOAD` from every child, and also `LLAMA_ARG_MODEL`, `LLAMA_ARG_MMPROJ`, `LLAMA_ARG_ALIAS` and `LLAMA_ARG_HF_REPO` for model-level overrides. [source]
- Children therefore never receive the router's TLS key or certificate and serve plain HTTP on loopback. [source]
- The router takes the child environment from its own environment (`get_environment()` reading `environ`), then applies the preset overrides. [source]
- Measured on this Mac: the Ollama 0.34.4 Homebrew `llama-server` (build 11081, commit 161755f29) given `--models-dir <dir> --models-max 1 --host 0.0.0.0` lists the model, then exits with `failed to initialize router models: subprocess is not enabled on this build`. [source]
- Ollama starts its single llama-server with `--host 127.0.0.1` and a free port, so a LAN-visible Ollama server is the Go front end only. [source]
- Practical rule: put authentication and TLS on the router, bind the router to the LAN only when needed, and treat the router host's local users as able to reach every loaded model without a key. [source]
Corrections and disagreements
- CONTRADICTS: llama-server-router-mode-child-instance-exposure.md, last claim ("anyone who can reach a child port can call it with no key" on a LAN-bound router): a child port is reachable only from the router host itself, so the keyless exposure is local. [source]
Children
- No children recorded.