check_ollama_hardening
Checks whether a self-hosted model server install still matches the hardening guide's defaults, given the diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Checks: host environment variable safety, loopback-only reachability on the model server and reverse proxy ports, the reverse proxy configuration's bind directive and credential enforcement, a unique (non-shared) credential, and disk encryption - each check resolves to PASS, FAIL, or UNVERIFIABLE (never guessed), the same three per-check states the doctor script uses. The OVERALL verdict differs from the script's own stricter rule, which collapses any UNVERIFIABLE into a failed run: this tool reports an UNVERIFIABLE-only result as UNVERIFIABLE, not an asserted failure it never measured. Nothing you submit is stored, logged, or retained; each call is evaluated in isolation and returns a per-check verdict. Cannot verify mesh-only reachability (no live network probe) and cannot detect drift after the moment you ran the diagnostics. Free tool, no API key required.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| platform | No | ||
| caddyfile_text | No | ||
| ollama_host_env | No | ||
| caddy_listen_addresses | No | ||
| ollama_listen_addresses | No | ||
| disk_encryption_status_text | No |