Deployment guide

AnythingLLM 1.17 multi-user on VPS: complete guide

Deploy on a VPS Cloud →

Tutorial

AnythingLLM 1.17 multi-user on VPS: complete guide

Artificial Intelligence10 min read10 steps

AnythingLLM has supported multi-user mode for several versions. v1.17.0 (October 1, 2026) goes further with a dedicated Manager role, meeting diarization with Nemotron 3 and Parakeet Redux, building on the native Google Vertex AI support introduced in v1.16.2 (September 22, 2026). For an agency or developer paying for a ChatGPT Team or Claude for Teams subscription, this combination replicates that model as a self-hosted deployment: isolated workspaces per client, RAG over your own documents, and no data sent to a third party. This guide covers the working Docker Compose configuration, user creation via the Admin interface, and real errors encountered during setup.

Contents· What version v1.17.0 changes for agency use1/8
  1. 01What version v1.17.0 changes for agency use
  2. 02Prerequisites before starting
  3. 03Deploy AnythingLLM v1.17.0 with Docker Compose
  4. 04Managing workspaces and roles in practice
  5. 05Backing up and restoring the instance
  6. 06Troubleshooting: real errors encountered during setup
  7. 07AnythingLLM vs self-hosted RAG alternatives
  8. 08Going further with your AI infrastructure

What version v1.17.0 changes for agency use

AnythingLLM has supported multi-user mode for several versions. v1.17.0 (October 1, 2026) refines this system by introducing a third role — Manager — who can create workspaces, invite users and manage documents without accessing system settings such as API keys or LLM configuration. For an agency, this role allows delegating the administration of a client to a project manager without exposing the entire infrastructure. Meeting diarization now relies on Nemotron 3 for speaker recognition and Parakeet Redux for transcription — two models that can run locally on a GPU-equipped VPS, or be delegated to an Nvidia API. Google Vertex AI was already available since v1.16.2 (September 22, 2026) as an LLM provider configurable directly from the interface, without manually patching the configuration file. These recent additions make the v1.16.2 + v1.17.0 combination the most complete configuration for structured multi-client use.

Prerequisites before starting

  • VPS with at least 4 GB RAM — 2 vCPU / 4 GB for cloud APIs, 4 vCPU / 8 GB if you embed a local embedding model or Parakeet Redux
  • 20 GB of SSD disk — LanceDB vectors and the document cache grow with the corpus; leave room to expand
  • Docker and Docker Compose v2 — verify with docker compose version (no hyphen); v1 (with hyphen) does not support all healthchecks
  • A dedicated subdomain — for example chat.your-domain.com; port 3001 must not be directly exposed publicly
  • An active reverse proxy — Nginx or Caddy for Let's Encrypt TLS and document upload size limits
  • An LLM API key — OpenAI, Anthropic, Vertex AI, or a local Ollama already running on the VPS
  • Port 3001 free — AnythingLLM uses it by default; verify with ss -tlnp | grep 3001 before launching

Deploy AnythingLLM v1.17.0 with Docker Compose

  1. Create the directory structure and set permissions

    Connect via SSH and create the working directory with mkdir -p /opt/anythingllm/storage. AnythingLLM runs as UID 1000 inside the container; without correcting permissions, the volume refuses writes on the first start. Apply chown -R 1000:1000 /opt/anythingllm/storage. If you used chmod -R 777, it works but unnecessarily broadens access — prefer the targeted chown.

  2. Write the docker-compose.yml file

    Create /opt/anythingllm/docker-compose.yml with the following content. The service is named anythingllm, image mintplexlabs/anythingllm:latest, restart: unless-stopped. Volumes: ./storage:/app/server/storage. Ports: 3001:3001 (close at the firewall, only the reverse proxy accesses it). Environment variables in the env_file: .env section. Network: create a proxy network shared with your reverse proxy to avoid exposing port 3001 on the public interface.

  3. Write the .env file

    Create /opt/anythingllm/.env with at least these three variables. JWT_SECRET: a random string of at least 32 characters, generated by openssl rand -hex 32 — never change it after the first start, all session tokens are invalidated. STORAGE_DIR: /app/server/storage (must match the volume target path). SERVER_PORT: 3001. Then add the variables for your LLM provider, for example LLM_PROVIDER=openai and OPEN_AI_KEY=sk-... for OpenAI, or LLM_PROVIDER=gemini and GEMINI_API_KEY=... for Vertex AI via the Gemini adapter.

  4. Start the container and check logs

    From /opt/anythingllm, run docker compose up -d. Wait 30 seconds then verify the service is listening with docker compose logs --tail=50. You should see the line Server started on port 3001. If the log shows EACCES: permission denied, mkdir '/app/server/storage/...', the chown from step 1 was not applied to the correct path — redo step 1 then docker compose restart.

  5. Configure the reverse proxy and obtain a TLS certificate

    With Nginx, create a vhost that proxies https://chat.your-domain.com to http://127.0.0.1:3001. Add client_max_body_size 100m in the server block to allow uploading large PDFs. Request the certificate with certbot --nginx -d chat.your-domain.com. With Caddy, the directive reverse_proxy localhost:3001 is sufficient, TLS is automatic.

  6. Create the administrator account on first access

    Open https://chat.your-domain.com in a browser. The interface prompts you to create the first administrator account — this account is the only one that can modify API keys, the LLM provider and system settings. Choose a strong password; AnythingLLM does not offer email-based password reset in self-hosted mode without additional SMTP configuration.

  7. Enable multi-user mode and invite a second user

    In the Admin interface, go to Settings → Security → enable Multi-user mode. An Invite User button appears in the users menu. Enter the email address, choose the role (Default or Manager), and copy the generated invitation link. The Manager role can manage workspaces and documents; the Default role only accesses workspaces they are assigned to.

  8. Create an isolated workspace and assign it to a user

    From the dashboard, click New Workspace and name it (for example Client Dupont). Drag your PDFs into the workspace, then click Save & Embed to start vectorization. Once embedding is complete, go to the workspace settings → Manage Users and add only the authorized users. Users not assigned cannot see this workspace.

  9. Configure Google Vertex AI as the LLM provider

    In Settings → LLM Provider, select Google Gemini (which uses the Vertex AI API under the hood via the native adapter available since v1.16.2). Enter your Google API key (GEMINI_API_KEY) and choose the model. If you prefer GCP service account authentication, export GOOGLE_APPLICATION_CREDENTIALS to the JSON file path in your .env and restart the container with docker compose restart.

  10. Update without data loss

    To upgrade to a newer version, stop the container with docker compose down, update the image tag in docker-compose.yml (example: mintplexlabs/anythingllm:v1.17.0), then run docker compose pull && docker compose up -d. Your data is in ./storage mounted as a volume: it survives the update. Check the logs after restarting to ensure no schema migration failed.

Pin a specific version tag in your docker-compose.yml rather than using the latest tag. The command docker image ls mintplexlabs/anythingllm shows you the currently downloaded version. This way, an update is only applied when you decide, and you can roll back by changing only the tag and running docker compose up -d again.

Managing workspaces and roles in practice

Once multi-user mode is enabled, the Admin interface exposes three distinct views: Users (list of accounts, roles, active status), Workspaces (global list with document and conversation counts) and Invites (pending invitation links). For an agency managing ten clients, the recommended approach is to create one workspace per client, attach one Manager user per client, and keep collaborators in the Default role with access limited to only the workspaces that concern them. The Manager role cannot view API keys or change the LLM provider: this isolation prevents one client from observing another's configuration. Conversations remain in the workspace — they do not migrate if you move a document between workspaces. Name your workspaces explicitly from the start: renaming a workspace does not change the internal storage paths, but can cause confusion in logs.

Backing up and restoring the instance

The entire state of AnythingLLM fits in the ./storage volume: the LanceDB vector database, document metadata, instance configuration and conversation history. A backup consists of archiving this folder while the container is stopped, or using rsync to a remote storage while the container is running — LanceDB tolerates concurrent reads. For a programmatic backup, add a cron service in your compose that runs tar -czf /backup/anythingllm-$(date +%Y%m%d).tar.gz /opt/anythingllm/storage. Restoration follows the reverse path: copy the archive into ./storage respecting 1000:1000 permissions, then docker compose up -d. The .env contains the JWT_SECRET: back it up separately, encrypted, as losing it invalidates all active sessions and any API tokens.

Troubleshooting: real errors encountered during setup

Here are the five most common documented errors when deploying AnythingLLM v1.17.0 on a VPS, with the exact message and the correction applied. First error: EACCES: permission denied, mkdir '/app/server/storage/vector-cache' at container startup. Cause: the storage folder is owned by root but the container runs as UID 1000. Fix: chown -R 1000:1000 /opt/anythingllm/storage then docker compose restart. Second error: address already in use :::3001 in the logs. Cause: another service is using the port. Fix: ss -tlnp | grep 3001 to identify the conflicting process, then stop it or change SERVER_PORT in .env. Third error: Invalid JWT secret — all sessions invalidated after a restart. Cause: the JWT_SECRET variable was changed. Fix: restore the original value of JWT_SECRET or ask all users to log back in. Fourth error: PDF uploads blocked at 1 MB despite configuration. Cause: client_max_body_size is defined in Nginx's http block but not in the vhost's server block — the most specific wins. Verify with nginx -T | grep client_max_body_size. Fifth error: workspace returns no sourced response after embedding. Cause: the embedding model selected at ingestion differs from the active model. Vectors are incompatible. Fix: remove the documents from the workspace, change the embedding model in the workspace settings, then re-ingest.

AnythingLLM vs self-hosted RAG alternatives

Scroll the table

CriterionAnythingLLM v1.17.0Open WebUILibreChatPrivateGPT
Built-in document RAGYes — PDF, Word, URL, Notion, GitHubBasic import without RAG pipelineVia RAG plugin (manual config)Yes — optimized for confidential documents
Multi-user modeAdmin / Manager / Default — natively supported, Manager role refined in v1.17.0Basic user managementYes with roles per conversationNo — single-user by default
Isolated workspaces per clientYes — native cloisoning per workspaceNo — shared conversationsLimited — per conversation onlyNo
Supported LLM providers20+ (Ollama, OpenAI, Vertex AI, Anthropic…)Ollama + OpenAI-compatibleOpenAI, Azure, Anthropic, Ollama…Ollama and OpenAI-compatible
Meeting diarizationYes — Nemotron 3 + Parakeet Redux (v1.17.0)NoNoNo
Minimum RAM (cloud API)~512 MB~256 MB~384 MB~512 MB
No-code AI agent builderYesNoNoNo
LicenseMITMITMITApache 2.0

Going further with your AI infrastructure

AnythingLLM v1.17.0 covers the multi-client RAG use case on a single VPS. If your corpus exceeds several million vectors, consider offloading the vector database to Qdrant in a neighboring container — AnythingLLM supports it natively from the instance settings. For teams that want to compare interfaces before deciding, the article on Open WebUI, LibreChat and Dify details the selection criteria according to usage profile. If your documents are subject to strict confidentiality requirements (GDPR, medical data, sensitive contracts), the PrivateGPT article explains how to work in fully local mode without any outgoing network call. These three resources are complementary and cover the majority of self-hosted AI architectures encountered in production on a VPS.

Your AnythingLLM environment ready in minutes

The AnythingLLM VPS template in the ServOrbit catalogue pre-configures the Docker environment, volumes and permissions at startup — you arrive directly at the administrator account creation step.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab