Agent skill

Setup Cpu Proxy Server

by drawthingsai in drawthingsai/draw-things-community

Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

GPL-3.0Auto-check passedDevOps & Cloud

Install Setup Cpu Proxy Server

skills CLI
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-server --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .claude/skills/setup-cpu-proxy-server && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
setup-cpu-proxy-server
GitHub stars
579
Token cost
~3.8k tokens
SKILL.md length
1,157 words
Files
9
Skills in repo
8
Repo updated
First seen
Licence
GPL-3.0

At a glance

Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

  • Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale
  • SKILL.md covers Files, Inputs, Initial State Check and Upload the Script Bundle, plus 7 more sections
  • Runs Shell scripts from its folder; calls ssh, openssl and scp; reaches compute.drawthings.ai; needs DATADOG_API_KEY
  • Upload model-list and envoy-config.yaml

What it does

Setup Cpu Proxy Server is an agent skill from drawthingsai/draw-things-community. Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript. Use when Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale, upload model-list and envoy-config.yaml, install Docker/Tailscale images, install or copy compute.drawthings.ai TLS certificates, launch proxyservice and envoygrpcwebproxy, and debug port 443, Envoy 8443, TLS, or gRPC Echo connectivity.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `InitCPUServer.sh`, `InitCertificate.sh` and `LaunchCPUServer.sh`).

It sits in DevOps & Cloud, covering gRPC and Protobuf, Cloud networking and Containers. It works with gRPC, Docker and Linux. The repository describes itself as: The community repository for the Draw Things app. The licence is GPL-3.0.

When your agent uses it

  • Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale
  • Upload model-list and envoy-config.yaml
  • Install Docker/Tailscale images
  • Copy compute.drawthings.ai TLS certificates

Example prompts

  • “/setup-cpu-proxy-server”

Requirements

  • A Bash shell
  • Docker
  • A credential in DATADOG_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 3cac075. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • ssh
    • openssl
    • scp
    • docker
    • curl
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • compute.drawthings.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DATADOG_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Setup Cpu Proxy Server loads about 3.8k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 1,157 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from drawthingsai/draw-things-community at commit 3cac075, republished under its GPL-3.0 licence (© drawthingsai). 1,157 words, ~3,818 tokens.

Download SKILL.mdSave it as .claude/skills/setup-cpu-proxy-server/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
setup-cpu-proxy-server
description
Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript. Use when Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale, upload model-list and envoy-config.yaml, install Docker/Tailscale images, install or copy compute.drawthings.ai TLS certificates, launch proxy_service and envoy_grpc_web_proxy, and debug port 443, Envoy 8443, TLS, or gRPC Echo connectivity.

Draw Things CPU Proxy Server Setup

Use this workflow from Scripts/ServerManagement/CPUScript.

Files

  • InitCPUServer.sh: install/update Docker, install Tailscale, run tailscale up --ssh, lock the root password, and pull drawthingsai/draw-things-proxy-server-cli:v20260928.2 plus Envoy 1.39.1 pinned to its Linux amd64 image digest.
  • InitCertificate.sh: request a Let's Encrypt cert for compute.drawthings.ai with standalone certbot on port 80, set the permissions required by the non-root proxy container, and install the renewal deploy hook.
  • restart-drawthings-tls.sh: Certbot deploy hook that repairs renewed certificate permissions and restarts proxy_service and envoy_grpc_web_proxy so both processes load the renewed certificate.
  • LaunchCPUServer.sh: start proxy_service on public 443 and Tailscale control port TS_IP:50002.
  • LaunchEnvoyServer.sh: copy the provided Envoy config into root-owned /etc/drawthings/envoy, validate it, and start envoy_grpc_web_proxy with host networking. Preserve the previous container for rollback and restore it automatically if replacement startup or readiness fails.
  • model-list: mounted through its containing directory as /app/Documents/<filename> so host-side edits and control-panel writes target the same file.
  • envoy-config.yaml: copied to a separate file per deployment and mounted read-only as /etc/envoy/envoy.yaml; uses typed CORS and upstream HTTP/2 configuration.

Inputs

Have these ready before launch:

  • New CPU server SSH target, usually root@<tailscale-ip>.
  • Datadog API key. Treat it as a secret; do not commit or echo it in summaries.
  • Let's Encrypt notification email if issuing a new cert.
  • Optional existing cert source server, if DNS is not routed to the new VM yet.
  • Updated model-list.
  • A known-good envoy-config.yaml; the admin socket must include a port, typically 127.0.0.1:9901.

Initial State Check

Check SSH, OS, Docker, Tailscale, certs, containers, and ports:

bash
ssh root@<new-ts-ip> 'hostname; uname -a; id; command -v apt || true; command -v docker || true; command -v tailscale || true; tailscale ip -4 2>/dev/null || true'
ssh root@<new-ts-ip> 'docker ps -a --format "table {{.Names}}\t{{.Image}}\t{{.Status}}\t{{.Ports}}" 2>/dev/null || true; ss -ltnp | grep -E ":(80|443|8443|50002)" || true; ls -la /etc/letsencrypt/live/compute.drawthings.ai 2>/dev/null || true'

Upload the Script Bundle

Install the CPUScript files on the new server:

bash
ssh root@<new-ts-ip> 'mkdir -p /root/CPUScript'
scp InitCertificate.sh InitCPUServer.sh LaunchCPUServer.sh LaunchEnvoyServer.sh restart-drawthings-tls.sh envoy-config.yaml model-list root@<new-ts-ip>:/root/CPUScript/
ssh root@<new-ts-ip> 'chmod +x /root/CPUScript/*.sh; wc -l /root/CPUScript/model-list; ls -la /root/CPUScript'

If the model list changes, recopy only that file and verify checksum:

bash
scp model-list root@<new-ts-ip>:/root/CPUScript/model-list
shasum -a 256 model-list
ssh root@<new-ts-ip> 'shasum -a 256 /root/CPUScript/model-list; wc -l /root/CPUScript/model-list'

If the local Envoy config is stale, copy the known-good config from the current CPU server, then upload it:

bash
scp root@<current-cpu-ts-ip>:/root/envoy/envoy-config.yaml ./envoy-config.yaml
rg -n "port_value|address:|filename:|sni:|admin:" envoy-config.yaml
scp envoy-config.yaml root@<new-ts-ip>:/root/CPUScript/envoy-config.yaml

Run CPU Server Init

Run the dependency/image setup:

bash
ssh root@<new-ts-ip> 'cd /root/CPUScript && ./InitCPUServer.sh'

Expect apt output, Docker install/update, Tailscale install/update, root password lock, and Docker image pulls. A pending kernel upgrade warning is not a launch blocker.

Certificate Strategy

The scripts expect:

text
/etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem
/etc/letsencrypt/live/compute.drawthings.ai/privkey.pem

If compute.drawthings.ai already routes to the new VM and public port 80 reaches it, run:

bash
ssh root@<new-ts-ip> 'cd /root/CPUScript && printf "%s\n" "<email>" | ./InitCertificate.sh'

If DNS is not routed to the new VM yet, certbot standalone will fail. In that case, copy only the active cert and key from the current CPU server. Do not copy the whole /etc/letsencrypt unless deliberately migrating Certbot renewal ownership; that also copies ACME account keys, renewal configs, and archived cert material.

bash
ssh root@<current-cpu-ts-ip> 'ls -l /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem; openssl x509 -in /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem -noout -subject -issuer -dates'

mkdir -p /private/tmp/cpu-cert-transfer
chmod 700 /private/tmp/cpu-cert-transfer
scp root@<current-cpu-ts-ip>:/etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem root@<current-cpu-ts-ip>:/etc/letsencrypt/live/compute.drawthings.ai/privkey.pem /private/tmp/cpu-cert-transfer/
chmod 644 /private/tmp/cpu-cert-transfer/fullchain.pem
chmod 600 /private/tmp/cpu-cert-transfer/privkey.pem

ssh root@<new-ts-ip> 'mkdir -p /etc/letsencrypt/live/compute.drawthings.ai && chmod 755 /etc/letsencrypt /etc/letsencrypt/live /etc/letsencrypt/live/compute.drawthings.ai'
scp /private/tmp/cpu-cert-transfer/fullchain.pem /private/tmp/cpu-cert-transfer/privkey.pem root@<new-ts-ip>:/etc/letsencrypt/live/compute.drawthings.ai/
ssh root@<new-ts-ip> 'chmod 644 /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem; chmod 644 /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem; openssl x509 -in /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem -noout -subject -issuer -dates'
rm -f /private/tmp/cpu-cert-transfer/fullchain.pem /private/tmp/cpu-cert-transfer/privkey.pem

Use 0644 for privkey.pem with the current Docker launch because the proxy process inside the container may not run as root. If proxy_service logs Permission denied opening privkey.pem, fix permissions and recreate the container.

Automatic Renewal and TLS Reload

Copying only fullchain.pem and privkey.pem creates usable TLS files but does not migrate Certbot renewal ownership. A managed certificate must appear in certbot certificates and have all of:

text
/etc/letsencrypt/renewal/compute.drawthings.ai.conf
/etc/letsencrypt/archive/compute.drawthings.ai/
/etc/letsencrypt/live/compute.drawthings.ai/ -> ../../archive/compute.drawthings.ai/

InitCertificate.sh installs this executable deploy hook:

text
/etc/letsencrypt/renewal-hooks/deploy/restart-drawthings-tls.sh

Certbot normally creates /etc/letsencrypt/archive as root-only and creates each renewed private key as mode 0600. The proxy runs as appuser, so following the live symlink fails unless the archive directories are searchable and the private key is readable. The hook reapplies:

bash
chmod 0711 /etc/letsencrypt/archive
chmod 0755 /etc/letsencrypt/archive/compute.drawthings.ai
chmod 0644 /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem

The proxy and the statically configured Envoy listener load the certificate into memory at process startup. After a successful renewal, the deploy hook restarts both containers so they load the new certificate:

bash
/usr/bin/docker restart proxy_service
/usr/bin/docker restart envoy_grpc_web_proxy

Verify the snap timer and the complete renewal-to-reload path:

bash
systemctl is-enabled snap.certbot.renew.timer
systemctl is-active snap.certbot.renew.timer
certbot renew --dry-run --run-deploy-hooks
docker ps --filter name=proxy_service
docker ps --filter name=envoy_grpc_web_proxy

Expected results are enabled, active, Congratulations, all simulated renewals succeeded, and both containers returning to Up. --run-deploy-hooks is needed only to make a dry run execute deploy hooks; a real successful renewal automatically executes every executable in /etc/letsencrypt/renewal-hooks/deploy.

Confirm that ports 443 and 8443 serve the same renewed certificate:

bash
openssl s_client -connect 127.0.0.1:443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -dates -serial
openssl s_client -connect 127.0.0.1:8443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -dates -serial
Show full SKILL.md (556 more words)Show less

Launch Services

Launch the CPU proxy first. Any extra arguments after the model-list path are passed through to ProxyServiceCLI, including -g GPU worker ranges:

bash
ssh root@<new-ts-ip> 'cd /root/CPUScript && ./LaunchCPUServer.sh "<DATADOG_API_KEY>" /root/CPUScript/model-list -g 100.70.225.70:40001-40008:1 -g 100.115.89.107:40001-40008:1 -g 100.102.100.71:40001-40008:1 -g 100.102.159.74:40001-40008:1 -g 100.121.197.14:40001-40008:1 -g 100.110.198.32:40001-40008:1'

Verify each host's current Tailscale address before executing this example. The rebuilt dfw-242-009 and dfw-243-010 replaced the retired 100.83.253.70 and 100.64.66.84 addresses. LaunchCPUServer.sh stops and recreates the central proxy container, which can interrupt in-flight generation requests; use a planned maintenance window. A plain restart of an existing container retains its previously saved -g arguments.

LaunchCPUServer.sh mounts the directory containing the model list as /app/Documents and passes --model-list-path /app/Documents/<filename>. It also makes that directory and file writable by the container's non-root appuser; this is required because update-model-list writes atomically by creating a temporary file in the same directory.

Do not use the old single-file read-only mount:

bash
-v /root/CPUScript/model-list:/app/model-list:ro

That mount lets the server read the file, but it prevents the control-panel update-model-list RPC from writing back. The server currently uses try? around the file write, so the CLI can appear to succeed even when the file was not updated.

Then launch Envoy:

bash
ssh root@<new-ts-ip> 'cd /root/CPUScript && ./LaunchEnvoyServer.sh /root/CPUScript/envoy-config.yaml'

Expected ports:

  • proxy_service: 0.0.0.0:443->8080/tcp and <tailscale-ip>:50002->50000/tcp.
  • envoy_grpc_web_proxy: host network, listening on 0.0.0.0:8443.
  • Envoy admin: 127.0.0.1:9901.

Verification

Verify containers, listeners, logs, TLS, and Envoy readiness:

bash
ssh root@<new-ts-ip> 'docker ps -a --format "table {{.Names}}\t{{.Image}}\t{{.Status}}\t{{.Ports}}"'
ssh root@<new-ts-ip> 'docker inspect --format "{{range .Mounts}}{{println .Source \"->\" .Destination \"RW=\" .RW}}{{end}}" proxy_service'
ssh root@<new-ts-ip> 'docker inspect --format "{{range .Args}}{{println .}}{{end}}" proxy_service | grep -E "^100\\..*:40001-40008:1$" || true'
ssh root@<new-ts-ip> 'ss -ltnp | grep -E ":(443|8443|50002|9901)" || true'
ssh root@<new-ts-ip> 'docker logs --tail 50 proxy_service 2>&1; docker logs --tail 80 envoy_grpc_web_proxy 2>&1'
ssh root@<new-ts-ip> 'openssl s_client -connect 127.0.0.1:443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -subject -dates'
ssh root@<new-ts-ip> 'openssl s_client -connect 127.0.0.1:8443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -subject -dates'
ssh root@<new-ts-ip> 'curl -fsS --max-time 5 http://127.0.0.1:9901/ready'

Verify external GCP access:

bash
curl -vk --connect-timeout 10 https://<external-ip>:443/ImageGenerationService/Echo
openssl s_client -connect <external-ip>:443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -subject -dates -ext subjectAltName
curl -vk --resolve compute.drawthings.ai:443:<external-ip> --connect-timeout 10 https://compute.drawthings.ai:443/ImageGenerationService/Echo

An HTTP 415 from a raw GET to a gRPC endpoint is acceptable; it means the request reached the service but was not a valid gRPC call.

Model List Updates

With the updated launch script, both of these update the same model-list file:

  • Editing /root/CPUScript/model-list on the CPU host.
  • Running control-panel update from a local checkout:
bash
bazel-bin/Apps/ProxyServerControlPanelCLI -h <new-ts-ip> -p 50002 update-model-list /path/to/model-list

The container should show:

text
/root/CPUScript -> /app/Documents RW= true

If this mount is not writable, update-model-list will not reliably update the host file. After a successful update, Echo and FilesExist read modelListPath on demand, so they should reflect the new file without restarting. A restart is still useful after changing launch arguments such as -g GPU workers.

DNS and App Client Notes

The copied Let's Encrypt cert is for compute.drawthings.ai, not an IP address. If the app connects with:

swift
static let host = "<external-ip>"
static let port = 443

and uses full hostname verification, TLS fails because the certificate SAN has DNS:compute.drawthings.ai and no IP SAN. Symptoms may surface as GRPC.ConnectionPoolError.shutdown, and the server logs may show no Echo call because the client fails before the RPC reaches application code.

Before DNS is updated, either:

  • connect to <external-ip> but set gRPC TLS hostnameOverride: "compute.drawthings.ai" / SNI to compute.drawthings.ai, or
  • temporarily disable hostname verification only for a controlled test path.

After DNS is updated, prefer:

swift
static let host = "compute.drawthings.ai"
static let port = 443

Then full TLS verification should pass without special handling.

Troubleshooting

  • InitCertificate.sh fails with Let's Encrypt unauthorized or 503: compute.drawthings.ai is not routed to this VM on public port 80. Copy the existing cert/key to launch now, then fix DNS/load-balancer routing for renewal.
  • proxy_service restarts with fopen(... privkey.pem ... Permission denied): make /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem readable by the container, then rerun LaunchCPUServer.sh.
  • update-model-list prints success but the host file does not change: the model-list path is probably mounted read-only or the containing directory is not writable by the container user. Relaunch with the updated LaunchCPUServer.sh directory mount.
  • Envoy restarts with validation error on AdminValidationError.Address ... port_specifier is required: update envoy-config.yaml so admin.address.socket_address includes port_value: 9901, or copy the known-good config from the current CPU server.
  • grpcurl <ip>:443 ... fails certificate verification: use -servername compute.drawthings.ai or update DNS and use the hostname.
  • No Echo log appears on the server: suspect client-side TLS/channel setup before debugging server Echo handling.

© drawthingsai, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files in Scripts/ServerManagement/CPUScript of drawthingsai/draw-things-community.

  • SKILL.md
  • InitCPUServer.sh
  • InitCertificate.sh
  • LaunchCPUServer.sh
  • LaunchEnvoyServer.sh
  • README.md
  • envoy-config.yaml
  • model-list
  • restart-drawthings-tls.sh

Open the folder on GitHubat commit 3cac075

Compare with similar skills

Setup Cpu Proxy Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Setup Cpu Proxy Server compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Setup Cpu Proxy Server this skilldrawthingsai/draw-things-community579—~3.8kAutomated safety check: PassGPL-3.0
Super Deploy Skillsjiushiwon/wg-skills110—~716Automated safety check: PassApache-2.0
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Podmansickn33/agentic-awesome-skills47k1 repos~2.2kAutomated safety check: NotesMIT
Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package187—~2.4kAutomated safety check: NotesMIT
Sshepherdsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: WarnMIT

Similar skills

  • Super Deploy Skills

    jiushiwon/wg-skills

    一键部署技能套件(父入口)。覆盖项目技术栈检测、服务器环境检测与依赖安装、前端 Nginx 托管、原生部署脚本、Docker 部署。当用户说「部署项目」「一键部署」「deploy」「帮我上线」「发布到服务器」时触发,并按意图路由到子技能 deploy-detect-skill / server-setup-skill / static-nginx-skill /…

    110 GitHub stars~716 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Podman

    sickn33/agentic-awesome-skills

    Manage containers using Podman, the daemonless container engine.

    47k GitHub starsUsed in 1 repo~2.2k tokens
    DevOps & CloudAuto-check: notes
  • Frappe Ops Deployment

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.

    187 GitHub stars~2.4k tokensUpdated 20 days ago
    DevOps & CloudAuto-check: notes
  • Sshepherd

    sickn33/agentic-awesome-skills

    Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

    47k GitHub starsUsed in 1 repo~1.6k tokens
    DevOps & CloudAuto-check: warnings
  • Podman

    BagelHole/DevOps-Security-Agent-Skills

    Manage containers using Podman, the daemonless container engine.

    1.1k GitHub stars~1.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes

More from drawthingsai/draw-things-community

All 8 skills in this repo
  • Run Longcat Avatar Video

    drawthingsai/draw-things-community

    Generate, benchmark, validate, and troubleshoot LongCat-Video-Avatar 1.5 videos with draw-things-cli.

    579 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Use Drawthings CLI

    drawthingsai/draw-things-community

    Use and troubleshoot an already installed Homebrew draw-things-cli for model discovery, authentication, local, cloud, or remote image generation, basic image-to-image and video generation, output…

    579 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Init GPU Server

    drawthingsai/draw-things-community

    Initialize a Draw Things GPU server with GPUScript, including script sync, Docker/CUDA/NVIDIA runtime setup, 7T data disk mounting, mergerfs, and end-to-end GPU verification.

    579 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • New Model Integration

    drawthingsai/draw-things-community

    Add a new image or video generative model to the Draw Things app / CLI with a compile-first, end-to-end workflow across SwiftDiffusion, tokenizer plumbing, text encoder, fixed encoder, UNet / DiT…

    579 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Train Lora

    drawthingsai/draw-things-community

    Validate Draw Things LoRA training end to end with draw-things-cli, including tiny-dataset training, loss and scaler checks, checkpoint sanity, and base-versus-LoRA generation comparison.

    579 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Trainer Integration

    drawthingsai/draw-things-community

    Add or tighten Draw Things LoRA trainer support for generative models available in the Draw Things app / CLI, covering LoRA builders, trainer dispatch, tokenizer and fixed-encoder wiring, checkpoint…

    579 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Setup Cpu Proxy Server

What does Setup Cpu Proxy Server do?

Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript. Setup Cpu Proxy Server is an agent skill from drawthingsai/draw-things-community. Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

When should I use Setup Cpu Proxy Server?

Setup Cpu Proxy Server fits situations like: Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale; upload model-list and envoy-config.yaml; install Docker/Tailscale images; copy compute.drawthings.ai TLS certificates.

How do I install Setup Cpu Proxy Server in Claude Code?

Run `npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a claude-code`. Or copy the skill folder (Scripts/ServerManagement/CPUScript in drawthingsai/draw-things-community) into .claude/skills/setup-cpu-proxy-server in your project. Claude Code loads it when a task matches its description.

How do I install Setup Cpu Proxy Server in Codex?

Run `npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a codex`. Or copy the skill folder (Scripts/ServerManagement/CPUScript in drawthingsai/draw-things-community) into .agents/skills/setup-cpu-proxy-server in your project. Codex loads it when a task matches its description.

Can I use Setup Cpu Proxy Server in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup-cpu-proxy-server, .gemini/skills/setup-cpu-proxy-server, .github/skills/setup-cpu-proxy-server and .opencode/skills/setup-cpu-proxy-server in your project.

What does Setup Cpu Proxy Server need to run?

Going by SKILL.md and its folder, Setup Cpu Proxy Server needs a shell for the scripts in its folder, the command-line tools its instructions call (ssh, openssl, scp, docker, curl and rg) and credentials named DATADOG_API_KEY. Our summary lists: A Bash shell; Docker; A credential in DATADOG_API_KEY.

Does Setup Cpu Proxy Server access the network?

SKILL.md names 1 domain. In commands or code: compute.drawthings.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Setup Cpu Proxy Server safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Setup Cpu Proxy Server use?

Setup Cpu Proxy Server is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Setup Cpu Proxy Server use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Setup Cpu Proxy Server?

Skills that share tags, products or a category with Setup Cpu Proxy Server: Super Deploy Skills (jiushiwon/wg-skills, 110 stars), Minimega (sandia-minimega/minimega, 160 stars), Podman (sickn33/agentic-awesome-skills, 47k stars) and Frappe Ops Deployment (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Setup Cpu Proxy Server?

drawthingsai (a GitHub organization) maintains it in drawthingsai/draw-things-community, which has 579 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: drawthingsai/draw-things-community on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.