Self-Hosting Khoj on a VPS: Building a Private AI Search Engine for Obsidian and Local Files
Introduction: The Quest for Private, Intelligent Knowledge Management
In the digital age, professionals, researchers, and creators accumulate vast amounts of data across notes, documents, and local files. Tools like Obsidian have revolutionized markdown-based knowledge management, popularized through the concept of a "Second Brain." However, as these digital archives grow, finding specific information or drawing connections between disparate notes becomes increasingly challenging.
While mainstream artificial intelligence (AI) tools offer powerful semantic search and chat capabilities, they frequently require uploading sensitive, proprietary data to third-party cloud servers. For businesses and privacy-conscious individuals, this presents a significant compliance and security risk. This is where Khoj enters the picture.
Khoj is an open-source, AI-powered personal search assistant that allows you to chat with and search through your internal data. By self-hosting Khoj on a Virtual Private Server (VPS), you maintain absolute ownership of your data while unlocking advanced AI capabilities directly inside Obsidian and your local file systems. This article provides an enterprise-grade, step-by-step blueprint to deploying and configuring Khoj on your own infrastructure.
Why Self-Host Khoj? The Strategic Advantages
Deploying Khoj on a self-managed VPS offers distinct advantages over relying on public, multi-tenant AI services:
- Data Sovereignty and Privacy: Your intellectual property, personal thoughts, and corporate data never leave your controlled infrastructure. This is critical for meeting stringent data protection regulations like GDPR or HIPAA.
- Seamless Integration: Khoj bridges the gap between your static files and active workflows, integrating natively via an Obsidian plugin, a web interface, or desktop applications.
- Semantic Search Capabilities: Unlike traditional keyword search, Khoj utilizes natural language processing (NLP) to understand the context and intent behind your queries, surfacing highly relevant results even if exact wording differs.
- Cost Optimization: Avoid unpredictable per-user SaaS subscription fees by utilizing predictable, fixed-cost VPS infrastructure.
Prerequisites for Deployment
Before initiating the installation process, ensure your environment meets the following technical baselines:
- A Virtual Private Server (VPS): A minimum configuration of 2 vCPUs, 4GB RAM, and Ubuntu 22.04 LTS or 24.04 LTS is highly recommended. If you plan to run open-source large language models (LLMs) locally on the VPS, consider configurations with higher RAM or GPU capabilities.
- A Domain Name: A registered domain or subdomain (e.g.,
khoj.yourcompany.com) configured with an A/AAAA record pointing to your VPS IP address. - Docker and Docker Compose: Installed and verified on the host machine to facilitate containerized deployment.
- Basic Command Line Proficiency: Comfort with SSH, standard Linux terminal operations, and text editors like Nano or Vim.
Step-by-Step Installation Guide
We will utilize Docker Compose for this deployment, as it isolates the application dependencies and simplifies updates. Follow these steps sequentially to configure Khoj on your VPS.
Step 1: System Preparation and SSH Access
Connect to your VPS via SSH and update the system packages to their latest stable versions:
ssh root@your_vps_ip
sudo apt update && sudo apt upgrade -y
Step 2: Define the Docker Compose Configuration
Create a dedicated directory for your Khoj deployment to keep configuration files organized:
mkdir -y ~/khoj && cd ~/khoj
Next, create a docker-compose.yml file. This configuration defines the Khoj application service, the database, and the required network environments. Below is a production-ready template:
version: '3.8'
services:
khoj:
image: ghcr.io/khoj-ai/khoj:latest
container_name: khoj-server
volumes:
- ./data:/app/data
ports:
- "8000:8000"
environment:
- KHOJ_DOMAIN=[https://khoj.yourcompany.com](https://khoj.yourcompany.com)
- ANONYMOUS_TELEMETRY=False
restart: unless-stopped
Note: Set
ANONYMOUS_TELEMETRY=Falseto ensure no analytical data is transmitted externally, preserving absolute system isolation.
Step 3: Launching the Application
Execute the docker-compose command in detached mode to pull the official images and initialize the services:
docker compose up -d
Verify that the container is running optimally by reviewing the logs:
docker compose logs -f khoj
Step 4: Configuring a Reverse Proxy and SSL with Nginx
To secure data transmission between your local devices and the VPS, you must route traffic through a reverse proxy encrypted with an SSL/TLS certificate.
Install Nginx and Certbot:
sudo apt install nginx certbot python3-certbot-nginx -y
Create a new Nginx configuration file for Khoj:
sudo nano /etc/nginx/sites-available/khoj
Insert the following configuration block, replacing placeholders with your actual domain:
server {
listen 80;
server_name khoj.yourcompany.com;
location / {
proxy_pass http://localhost:8000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
Enable the site configuration and restart Nginx:
sudo ln -s /etc/nginx/sites-available/khoj /etc/nginx/sites-enabled/
sudo systemctl restart nginx
Obtain a complimentary Let's Encrypt SSL certificate to enforce secure HTTPS traffic:
sudo certbot --nginx -d khoj.yourcompany.com
Integrating Khoj into Obsidian: Unleashing the AI Second Brain
With the self-hosted server running securely, you can now integrate it directly into your Obsidian workspace. This allows you to converse with your notes without manually copy-pasting text into web browsers.
1. Plugin Installation
Navigate to your Obsidian vault settings, select Community Plugins, click Browse, and search for Khoj. Install and enable the official community plugin.
2. Connecting to Your Self-Hosted Instance
Open the Khoj plugin settings within Obsidian. Locate the server configuration fields and modify them as follows:
- Server URL: Input your secure domain (e.g.,
[https://khoj.yourcompany.com](https://khoj.yourcompany.com)). - API Key/Authentication: Input the credentials generated during your server setup.
3. Indexing Local Files
Once connected, initialize the indexing process. Khoj will securely scan your markdown files, generate semantic embeddings, and sync them back to your self-hosted VPS database. Depending on the size of your vault, this initial indexing may take several minutes.
Advanced Configuration: Chatting with Local Files
Khoj's utility extends far beyond markdown notes. You can configure the system to index PDF reports, financial spreadsheets, and text documents stored locally on your machine or server. By accessing the Khoj web interface at your custom domain, you can configure data pipelines to automatically sync specific folders, allowing the AI to synthesize information across multiple file types concurrently.
For example, you can query the system with a complex prompt such as:
"Based on the internal financial PDFs uploaded last month and my meeting notes in Obsidian, what were our main operational bottlenecks?"
Khoj will parse your Obsidian vault and the designated PDF folders, analyze the contextually linked data points, and return a structured, comprehensive synthesis directly to your user interface.
Conclusion: True Autonomy in Digital Knowledge Management
Self-hosting Khoj on a VPS creates a paradigm shift in how we interact with personal and corporate data. By combining the organizational structural elegance of Obsidian with the advanced contextual reasoning of modern AI engines—all hosted within your own secure perimeter—you construct an intellectual ecosystem that is intelligent, secure, and entirely yours.
As AI continues to deeply integrate into professional workflows, maintaining data sovereignty will shift from a luxury to a core requirement. Implementing a self-hosted instance of Khoj ensures your organization stays ahead of the curve, optimizing productivity without ever compromising on security.
