Applies the new write_readme companion-doc convention to ai-stack, paintplus, and kyber-launcher: install-time-invariant content (usage walkthroughs, service tables, troubleshooting) moves out of the .sh heredocs into sibling services/<name>.md files, leaving only genuinely install-specific content inline. - services/paintplus.md: config/cloud/GPU/ai-stack-backend/update/Caddy sections, picked up automatically via write_readme's companion-doc support. - services/ai-stack.md: roles, GPU switcher, service URLs, cloud LLM provider setup, update, Caddy. ai-stack.sh can't use write_readme directly (its POST-INSTALL-NOTES.md filename deliberately avoids colliding with the vendored app's own README.md in the same directory), so it appends the companion file manually. - services/kyber-launcher.md: the full SWBF2 (2017) + Kyber walkthrough, moved out of the root README's "Gaming scripts" section (which now just points here). kyber-launcher.sh now calls write_readme to deploy it to ~/.local/share/kyber/README.md, fixing a stale in-script pointer to a README section that no longer exists.
3.4 KiB
Roles
- Open WebUI (chat, research, light coding) — local Ollama + any cloud providers in one model dropdown; wired to your code via the RAG + MCP servers and Gitea.
- PaintPlus (separate
paintplusservice) — the front end for all image work (inpaint / upscale / generate). Point itsAI_PROVIDERat a cloud API, or at this stack's localcomfyui/invokeaifor local image-gen. - Gitea + GitHub sync —
bash gitea-github-sync.shmirrors repos both ways (pull GitHub → local git, or push local → GitHub). - RAG / MCP / Kiwix — retrieve just the relevant context so you feed the model less text (saves tokens), for both local and cloud models.
- Web search uses DuckDuckGo (no SearXNG in this build).
GPU switcher (small local GPU only)
One small GPU can't run local chat and local image-gen at once. Swap it:
~/docker/ai-stack/gpu-mode.sh images # before generating locally in PaintPlus
~/docker/ai-stack/gpu-mode.sh llm # back to local chat in Open WebUI
~/docker/ai-stack/gpu-mode.sh status # see which is active
Cloud models work anytime and need no swap.
Service URLs
| Service | URL | Auth |
|---|---|---|
| Open WebUI | http://localhost:3000 | built-in (first visit = admin) |
| InvokeAI | http://localhost:9090 | none |
| ComfyUI | http://localhost:8188 | none |
| Kiwix | http://localhost:8181 | none |
| Gitea | http://localhost:3001 | built-in |
| Portainer | https://localhost:9443 | built-in |
Manage the stack
cd ~/docker/ai-stack
bash start.sh # pull latest images + docker compose up -d
bash stop.sh # docker compose down
bash status.sh # GPU / container / RAG health
bash pull-models.sh # pull Ollama models (run once after first install)
Also a systemd unit: sudo systemctl {start,stop,status} local-ai
Cloud LLM providers (Open WebUI)
Open WebUI uses an OpenAI-compatible connection list. The local RAG server is the
first entry; any cloud providers added at install follow it. Two semicolon-separated
lists in .env, matched by position (RAG must stay first):
# ~/docker/ai-stack/.env
OPENAI_API_BASE_URLS=http://rag-server:8001/v1;https://api.groq.com/openai/v1
OPENAI_API_KEYS=local-rag;gsk_xxx
cd ~/docker/ai-stack && docker compose up -d open-webui # apply
| Provider | Base URL | Key |
|---|---|---|
| Groq | https://api.groq.com/openai/v1 |
https://console.groq.com/keys |
| DeepInfra | https://api.deepinfra.com/v1/openai |
https://deepinfra.com/dash/api_keys |
| OpenAI | https://api.openai.com/v1 |
https://platform.openai.com/api-keys |
| OpenRouter | https://openrouter.ai/api/v1 |
https://openrouter.ai/keys |
Alternatively, add them at runtime in Open WebUI → Settings → Admin → Connections (no file edits, survives image upgrades).
Update
Re-run the ai-stack installer (refreshes vendored source, keeps your .env),
then bash ~/docker/ai-stack/start.sh. Or in place:
cd ~/docker/ai-stack && bash local-ai-setup.sh --force.
Caddy
Open WebUI is reverse-proxied as open-webui:8080 on caddy_net (or your
configured Caddy network name; attached with docker network connect after
start). Other services are LAN-only by default — add Caddy site blocks for
them if you want remote access.