Post

SearXNG: Private Metasearch for the Homelab and Local AI Agents

SearXNG: Private Metasearch for the Homelab and Local AI Agents

Purpose

SearXNG is a self-hosted metasearch engine. It does two jobs in the homelab: it’s a private web search for the household, which sends each query on to several upstream engines and merges the results, so the engines see the SearXNG server rather than the person searching. And it’s the web-search backend of the local AI agent (Hermes), so the agent’s searches go through a server in the homelab instead of a paid third-party search API.

Deployment

The SearXNG container runs on the Docker host that also runs the local LLM; SearXNG itself uses only the CPU. It uses image searxng/searxng:2026.9.25-12f8b6515 managed via Docker Compose, with a restart policy of unless-stopped. There is no health check configured on the container.

Configuration

SearXNG supports dozens of upstream engines across categories such as general web, images, news and code; this instance uses SearXNG’s default engine list, with the rate limiter off and public_instance: false, since it serves only the homelab. The configuration lives in a host bind mount, so it survives container updates. The container joins the proxy network of the reverse proxy, which serves its web UI (port 8080 inside the container) over HTTPS.

Logging goes through the GELF UDP driver to centralize search logs alongside every other homelab service (see the Graylog post).

Storage

The config and cache directories are bind-mounted from the host, and /etc/localtime is mounted read-only so the container uses the host’s timezone. Nothing in the container needs a backup beyond the config directory.

flowchart LR
    A["Household browser"] --> B["Traefik (HTTPS)"]
    B --> D["SearXNG"]
    C["Hermes agent"] -->|"host port, internal"| D
    D --> E["Upstream search engines"]

Access

Browsers reach the web UI through Traefik over HTTPS on the internal network. The AI agent calls SearXNG directly on a port its Docker host publishes on the internal network, which skips the proxy for machine-to-machine traffic.

Notes

Household browsers and the AI agent share this one instance, so an outage affects both. The container has no health check yet. Docker restarts it if it exits, and Traefik drops the route of a stopped container, but a container that is running and not answering stays in rotation until someone notices; a health check would let Docker report it as unhealthy.

This post is licensed under CC BY 4.0 by the author.