Super Deploy Skills
jiushiwon/wg-skills
一键部署技能套件(父入口)。覆盖项目技术栈检测、服务器环境检测与依赖安装、前端 Nginx 托管、原生部署脚本、Docker 部署。当用户说「部署项目」「一键部署」「deploy」「帮我上线」「发布到服务器」时触发,并按意图路由到子技能 deploy-detect-skill / server-setup-skill / static-nginx-skill /…
Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-server --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .claude/skills/setup-cpu-proxy-server && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "setup-cpu-proxy-server" agent skill from https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScript into .claude/skills/setup-cpu-proxy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-cpu-proxy-server", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScriptType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-server --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .agents/skills/setup-cpu-proxy-server && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "setup-cpu-proxy-server" agent skill from https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScript into .agents/skills/setup-cpu-proxy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-cpu-proxy-server", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-server --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .cursor/skills/setup-cpu-proxy-server && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "setup-cpu-proxy-server" agent skill from https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScript into .cursor/skills/setup-cpu-proxy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-cpu-proxy-server", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/drawthingsai/draw-things-community.git --path Scripts/ServerManagement/CPUScript--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-server --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .gemini/skills/setup-cpu-proxy-server && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "setup-cpu-proxy-server" agent skill from https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScript into .gemini/skills/setup-cpu-proxy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-cpu-proxy-server", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-serverInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .github/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .github/skills/setup-cpu-proxy-server && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "setup-cpu-proxy-server" agent skill from https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScript into .github/skills/setup-cpu-proxy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-cpu-proxy-server", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install drawthingsai/draw-things-community setup-cpu-proxy-server --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/drawthingsai/draw-things-community.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Scripts/ServerManagement/CPUScript .opencode/skills/setup-cpu-proxy-server && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "setup-cpu-proxy-server" agent skill from https://github.com/drawthingsai/draw-things-community/tree/main/Scripts/ServerManagement/CPUScript into .opencode/skills/setup-cpu-proxy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-cpu-proxy-server", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
setup-cpu-proxy-serverSet up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.
Setup Cpu Proxy Server is an agent skill from drawthingsai/draw-things-community. Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript. Use when Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale, upload model-list and envoy-config.yaml, install Docker/Tailscale images, install or copy compute.drawthings.ai TLS certificates, launch proxyservice and envoygrpcwebproxy, and debug port 443, Envoy 8443, TLS, or gRPC Echo connectivity.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `InitCPUServer.sh`, `InitCertificate.sh` and `LaunchCPUServer.sh`).
It sits in DevOps & Cloud, covering gRPC and Protobuf, Cloud networking and Containers. It works with gRPC, Docker and Linux. The repository describes itself as: The community repository for the Draw Things app. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit 3cac075. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell), which the agent can run.
Shell commands in SKILL.md call:
sshopensslscpdockercurlrgFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
compute.drawthings.aiFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DATADOG_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Setup Cpu Proxy Server loads about 3.8k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 1,157 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from drawthingsai/draw-things-community at commit 3cac075, republished under its GPL-3.0 licence (© drawthingsai). 1,157 words, ~3,818 tokens.
.claude/skills/setup-cpu-proxy-server/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Use this workflow from Scripts/ServerManagement/CPUScript.
InitCPUServer.sh: install/update Docker, install Tailscale, run tailscale up --ssh, lock the root password, and pull drawthingsai/draw-things-proxy-server-cli:v20260928.2 plus Envoy 1.39.1 pinned to its Linux amd64 image digest.InitCertificate.sh: request a Let's Encrypt cert for compute.drawthings.ai with standalone certbot on port 80, set the permissions required by the non-root proxy container, and install the renewal deploy hook.restart-drawthings-tls.sh: Certbot deploy hook that repairs renewed certificate permissions and restarts proxy_service and envoy_grpc_web_proxy so both processes load the renewed certificate.LaunchCPUServer.sh: start proxy_service on public 443 and Tailscale control port TS_IP:50002.LaunchEnvoyServer.sh: copy the provided Envoy config into root-owned /etc/drawthings/envoy, validate it, and start envoy_grpc_web_proxy with host networking. Preserve the previous container for rollback and restore it automatically if replacement startup or readiness fails.model-list: mounted through its containing directory as /app/Documents/<filename> so host-side edits and control-panel writes target the same file.envoy-config.yaml: copied to a separate file per deployment and mounted read-only as /etc/envoy/envoy.yaml; uses typed CORS and upstream HTTP/2 configuration.Have these ready before launch:
root@<tailscale-ip>.model-list.envoy-config.yaml; the admin socket must include a port, typically 127.0.0.1:9901.Check SSH, OS, Docker, Tailscale, certs, containers, and ports:
ssh root@<new-ts-ip> 'hostname; uname -a; id; command -v apt || true; command -v docker || true; command -v tailscale || true; tailscale ip -4 2>/dev/null || true'
ssh root@<new-ts-ip> 'docker ps -a --format "table {{.Names}}\t{{.Image}}\t{{.Status}}\t{{.Ports}}" 2>/dev/null || true; ss -ltnp | grep -E ":(80|443|8443|50002)" || true; ls -la /etc/letsencrypt/live/compute.drawthings.ai 2>/dev/null || true'Install the CPUScript files on the new server:
ssh root@<new-ts-ip> 'mkdir -p /root/CPUScript'
scp InitCertificate.sh InitCPUServer.sh LaunchCPUServer.sh LaunchEnvoyServer.sh restart-drawthings-tls.sh envoy-config.yaml model-list root@<new-ts-ip>:/root/CPUScript/
ssh root@<new-ts-ip> 'chmod +x /root/CPUScript/*.sh; wc -l /root/CPUScript/model-list; ls -la /root/CPUScript'If the model list changes, recopy only that file and verify checksum:
scp model-list root@<new-ts-ip>:/root/CPUScript/model-list
shasum -a 256 model-list
ssh root@<new-ts-ip> 'shasum -a 256 /root/CPUScript/model-list; wc -l /root/CPUScript/model-list'If the local Envoy config is stale, copy the known-good config from the current CPU server, then upload it:
scp root@<current-cpu-ts-ip>:/root/envoy/envoy-config.yaml ./envoy-config.yaml
rg -n "port_value|address:|filename:|sni:|admin:" envoy-config.yaml
scp envoy-config.yaml root@<new-ts-ip>:/root/CPUScript/envoy-config.yamlRun the dependency/image setup:
ssh root@<new-ts-ip> 'cd /root/CPUScript && ./InitCPUServer.sh'Expect apt output, Docker install/update, Tailscale install/update, root password lock, and Docker image pulls. A pending kernel upgrade warning is not a launch blocker.
The scripts expect:
/etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem
/etc/letsencrypt/live/compute.drawthings.ai/privkey.pemIf compute.drawthings.ai already routes to the new VM and public port 80 reaches it, run:
ssh root@<new-ts-ip> 'cd /root/CPUScript && printf "%s\n" "<email>" | ./InitCertificate.sh'If DNS is not routed to the new VM yet, certbot standalone will fail. In that case, copy only the active cert and key from the current CPU server. Do not copy the whole /etc/letsencrypt unless deliberately migrating Certbot renewal ownership; that also copies ACME account keys, renewal configs, and archived cert material.
ssh root@<current-cpu-ts-ip> 'ls -l /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem; openssl x509 -in /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem -noout -subject -issuer -dates'
mkdir -p /private/tmp/cpu-cert-transfer
chmod 700 /private/tmp/cpu-cert-transfer
scp root@<current-cpu-ts-ip>:/etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem root@<current-cpu-ts-ip>:/etc/letsencrypt/live/compute.drawthings.ai/privkey.pem /private/tmp/cpu-cert-transfer/
chmod 644 /private/tmp/cpu-cert-transfer/fullchain.pem
chmod 600 /private/tmp/cpu-cert-transfer/privkey.pem
ssh root@<new-ts-ip> 'mkdir -p /etc/letsencrypt/live/compute.drawthings.ai && chmod 755 /etc/letsencrypt /etc/letsencrypt/live /etc/letsencrypt/live/compute.drawthings.ai'
scp /private/tmp/cpu-cert-transfer/fullchain.pem /private/tmp/cpu-cert-transfer/privkey.pem root@<new-ts-ip>:/etc/letsencrypt/live/compute.drawthings.ai/
ssh root@<new-ts-ip> 'chmod 644 /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem; chmod 644 /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem; openssl x509 -in /etc/letsencrypt/live/compute.drawthings.ai/fullchain.pem -noout -subject -issuer -dates'
rm -f /private/tmp/cpu-cert-transfer/fullchain.pem /private/tmp/cpu-cert-transfer/privkey.pemUse 0644 for privkey.pem with the current Docker launch because the proxy process inside the container may not run as root. If proxy_service logs Permission denied opening privkey.pem, fix permissions and recreate the container.
Copying only fullchain.pem and privkey.pem creates usable TLS files but does not migrate Certbot renewal ownership. A managed certificate must appear in certbot certificates and have all of:
/etc/letsencrypt/renewal/compute.drawthings.ai.conf
/etc/letsencrypt/archive/compute.drawthings.ai/
/etc/letsencrypt/live/compute.drawthings.ai/ -> ../../archive/compute.drawthings.ai/InitCertificate.sh installs this executable deploy hook:
/etc/letsencrypt/renewal-hooks/deploy/restart-drawthings-tls.shCertbot normally creates /etc/letsencrypt/archive as root-only and creates each renewed private key as mode 0600. The proxy runs as appuser, so following the live symlink fails unless the archive directories are searchable and the private key is readable. The hook reapplies:
chmod 0711 /etc/letsencrypt/archive
chmod 0755 /etc/letsencrypt/archive/compute.drawthings.ai
chmod 0644 /etc/letsencrypt/live/compute.drawthings.ai/privkey.pemThe proxy and the statically configured Envoy listener load the certificate into memory at process startup. After a successful renewal, the deploy hook restarts both containers so they load the new certificate:
/usr/bin/docker restart proxy_service
/usr/bin/docker restart envoy_grpc_web_proxyVerify the snap timer and the complete renewal-to-reload path:
systemctl is-enabled snap.certbot.renew.timer
systemctl is-active snap.certbot.renew.timer
certbot renew --dry-run --run-deploy-hooks
docker ps --filter name=proxy_service
docker ps --filter name=envoy_grpc_web_proxyExpected results are enabled, active, Congratulations, all simulated renewals succeeded, and both containers returning to Up. --run-deploy-hooks is needed only to make a dry run execute deploy hooks; a real successful renewal automatically executes every executable in /etc/letsencrypt/renewal-hooks/deploy.
Confirm that ports 443 and 8443 serve the same renewed certificate:
openssl s_client -connect 127.0.0.1:443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -dates -serial
openssl s_client -connect 127.0.0.1:8443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -dates -serialLaunch the CPU proxy first. Any extra arguments after the model-list path are passed through to ProxyServiceCLI, including -g GPU worker ranges:
ssh root@<new-ts-ip> 'cd /root/CPUScript && ./LaunchCPUServer.sh "<DATADOG_API_KEY>" /root/CPUScript/model-list -g 100.70.225.70:40001-40008:1 -g 100.115.89.107:40001-40008:1 -g 100.102.100.71:40001-40008:1 -g 100.102.159.74:40001-40008:1 -g 100.121.197.14:40001-40008:1 -g 100.110.198.32:40001-40008:1'Verify each host's current Tailscale address before executing this example. The rebuilt dfw-242-009 and dfw-243-010 replaced the retired 100.83.253.70 and 100.64.66.84 addresses. LaunchCPUServer.sh stops and recreates the central proxy container, which can interrupt in-flight generation requests; use a planned maintenance window. A plain restart of an existing container retains its previously saved -g arguments.
LaunchCPUServer.sh mounts the directory containing the model list as /app/Documents and passes --model-list-path /app/Documents/<filename>. It also makes that directory and file writable by the container's non-root appuser; this is required because update-model-list writes atomically by creating a temporary file in the same directory.
Do not use the old single-file read-only mount:
-v /root/CPUScript/model-list:/app/model-list:roThat mount lets the server read the file, but it prevents the control-panel update-model-list RPC from writing back. The server currently uses try? around the file write, so the CLI can appear to succeed even when the file was not updated.
Then launch Envoy:
ssh root@<new-ts-ip> 'cd /root/CPUScript && ./LaunchEnvoyServer.sh /root/CPUScript/envoy-config.yaml'Expected ports:
proxy_service: 0.0.0.0:443->8080/tcp and <tailscale-ip>:50002->50000/tcp.envoy_grpc_web_proxy: host network, listening on 0.0.0.0:8443.127.0.0.1:9901.Verify containers, listeners, logs, TLS, and Envoy readiness:
ssh root@<new-ts-ip> 'docker ps -a --format "table {{.Names}}\t{{.Image}}\t{{.Status}}\t{{.Ports}}"'
ssh root@<new-ts-ip> 'docker inspect --format "{{range .Mounts}}{{println .Source \"->\" .Destination \"RW=\" .RW}}{{end}}" proxy_service'
ssh root@<new-ts-ip> 'docker inspect --format "{{range .Args}}{{println .}}{{end}}" proxy_service | grep -E "^100\\..*:40001-40008:1$" || true'
ssh root@<new-ts-ip> 'ss -ltnp | grep -E ":(443|8443|50002|9901)" || true'
ssh root@<new-ts-ip> 'docker logs --tail 50 proxy_service 2>&1; docker logs --tail 80 envoy_grpc_web_proxy 2>&1'
ssh root@<new-ts-ip> 'openssl s_client -connect 127.0.0.1:443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -subject -dates'
ssh root@<new-ts-ip> 'openssl s_client -connect 127.0.0.1:8443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -subject -dates'
ssh root@<new-ts-ip> 'curl -fsS --max-time 5 http://127.0.0.1:9901/ready'Verify external GCP access:
curl -vk --connect-timeout 10 https://<external-ip>:443/ImageGenerationService/Echo
openssl s_client -connect <external-ip>:443 -servername compute.drawthings.ai </dev/null 2>/dev/null | openssl x509 -noout -subject -dates -ext subjectAltName
curl -vk --resolve compute.drawthings.ai:443:<external-ip> --connect-timeout 10 https://compute.drawthings.ai:443/ImageGenerationService/EchoAn HTTP 415 from a raw GET to a gRPC endpoint is acceptable; it means the request reached the service but was not a valid gRPC call.
With the updated launch script, both of these update the same model-list file:
/root/CPUScript/model-list on the CPU host.bazel-bin/Apps/ProxyServerControlPanelCLI -h <new-ts-ip> -p 50002 update-model-list /path/to/model-listThe container should show:
/root/CPUScript -> /app/Documents RW= trueIf this mount is not writable, update-model-list will not reliably update the host file. After a successful update, Echo and FilesExist read modelListPath on demand, so they should reflect the new file without restarting. A restart is still useful after changing launch arguments such as -g GPU workers.
The copied Let's Encrypt cert is for compute.drawthings.ai, not an IP address. If the app connects with:
static let host = "<external-ip>"
static let port = 443and uses full hostname verification, TLS fails because the certificate SAN has DNS:compute.drawthings.ai and no IP SAN. Symptoms may surface as GRPC.ConnectionPoolError.shutdown, and the server logs may show no Echo call because the client fails before the RPC reaches application code.
Before DNS is updated, either:
<external-ip> but set gRPC TLS hostnameOverride: "compute.drawthings.ai" / SNI to compute.drawthings.ai, orAfter DNS is updated, prefer:
static let host = "compute.drawthings.ai"
static let port = 443Then full TLS verification should pass without special handling.
InitCertificate.sh fails with Let's Encrypt unauthorized or 503: compute.drawthings.ai is not routed to this VM on public port 80. Copy the existing cert/key to launch now, then fix DNS/load-balancer routing for renewal.proxy_service restarts with fopen(... privkey.pem ... Permission denied): make /etc/letsencrypt/live/compute.drawthings.ai/privkey.pem readable by the container, then rerun LaunchCPUServer.sh.update-model-list prints success but the host file does not change: the model-list path is probably mounted read-only or the containing directory is not writable by the container user. Relaunch with the updated LaunchCPUServer.sh directory mount.AdminValidationError.Address ... port_specifier is required: update envoy-config.yaml so admin.address.socket_address includes port_value: 9901, or copy the known-good config from the current CPU server.grpcurl <ip>:443 ... fails certificate verification: use -servername compute.drawthings.ai or update DNS and use the hostname.© drawthingsai, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files in Scripts/ServerManagement/CPUScript of drawthingsai/draw-things-community.
Open the folder on GitHubat commit 3cac075
Setup Cpu Proxy Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Setup Cpu Proxy Server this skilldrawthingsai/draw-things-community | 579 | — | ~3.8k | Automated safety check: Pass | GPL-3.0 | |
| Super Deploy Skillsjiushiwon/wg-skills | 110 | — | ~716 | Automated safety check: Pass | Apache-2.0 | |
| Minimegasandia-minimega/minimega | 160 | — | ~3.2k | Automated safety check: Pass | GPL-3.0-only | |
| Podmansickn33/agentic-awesome-skills | 47k | 1 repos | ~2.2k | Automated safety check: Notes | MIT | |
| Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package | 187 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Sshepherdsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.6k | Automated safety check: Warn | MIT |
jiushiwon/wg-skills
一键部署技能套件(父入口)。覆盖项目技术栈检测、服务器环境检测与依赖安装、前端 Nginx 托管、原生部署脚本、Docker 部署。当用户说「部署项目」「一键部署」「deploy」「帮我上线」「发布到服务器」时触发,并按意图路由到子技能 deploy-detect-skill / server-setup-skill / static-nginx-skill /…
sandia-minimega/minimega
This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…
sickn33/agentic-awesome-skills
Manage containers using Podman, the daemonless container engine.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.
sickn33/agentic-awesome-skills
Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.
BagelHole/DevOps-Security-Agent-Skills
Manage containers using Podman, the daemonless container engine.
drawthingsai/draw-things-community
Generate, benchmark, validate, and troubleshoot LongCat-Video-Avatar 1.5 videos with draw-things-cli.
drawthingsai/draw-things-community
Use and troubleshoot an already installed Homebrew draw-things-cli for model discovery, authentication, local, cloud, or remote image generation, basic image-to-image and video generation, output…
drawthingsai/draw-things-community
Initialize a Draw Things GPU server with GPUScript, including script sync, Docker/CUDA/NVIDIA runtime setup, 7T data disk mounting, mergerfs, and end-to-end GPU verification.
drawthingsai/draw-things-community
Add a new image or video generative model to the Draw Things app / CLI with a compile-first, end-to-end workflow across SwiftDiffusion, tokenizer plumbing, text encoder, fixed encoder, UNet / DiT…
drawthingsai/draw-things-community
Validate Draw Things LoRA training end to end with draw-things-cli, including tiny-dataset training, loss and scaler checks, checkpoint sanity, and base-versus-LoRA generation comparison.
drawthingsai/draw-things-community
Add or tighten Draw Things LoRA trainer support for generative models available in the Draw Things app / CLI, covering LoRA builders, trainer dispatch, tokenizer and fixed-encoder wiring, checkpoint…
Categories
Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript. Setup Cpu Proxy Server is an agent skill from drawthingsai/draw-things-community. Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.
Setup Cpu Proxy Server fits situations like: Codex needs to bootstrap a root-access Linux CPU server over SSH/Tailscale; upload model-list and envoy-config.yaml; install Docker/Tailscale images; copy compute.drawthings.ai TLS certificates.
Run `npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a claude-code`. Or copy the skill folder (Scripts/ServerManagement/CPUScript in drawthingsai/draw-things-community) into .claude/skills/setup-cpu-proxy-server in your project. Claude Code loads it when a task matches its description.
Run `npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a codex`. Or copy the skill folder (Scripts/ServerManagement/CPUScript in drawthingsai/draw-things-community) into .agents/skills/setup-cpu-proxy-server in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add drawthingsai/draw-things-community --skill setup-cpu-proxy-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup-cpu-proxy-server, .gemini/skills/setup-cpu-proxy-server, .github/skills/setup-cpu-proxy-server and .opencode/skills/setup-cpu-proxy-server in your project.
Going by SKILL.md and its folder, Setup Cpu Proxy Server needs a shell for the scripts in its folder, the command-line tools its instructions call (ssh, openssl, scp, docker, curl and rg) and credentials named DATADOG_API_KEY. Our summary lists: A Bash shell; Docker; A credential in DATADOG_API_KEY.
SKILL.md names 1 domain. In commands or code: compute.drawthings.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Setup Cpu Proxy Server is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Setup Cpu Proxy Server: Super Deploy Skills (jiushiwon/wg-skills, 110 stars), Minimega (sandia-minimega/minimega, 160 stars), Podman (sickn33/agentic-awesome-skills, 47k stars) and Frappe Ops Deployment (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
drawthingsai (a GitHub organization) maintains it in drawthingsai/draw-things-community, which has 579 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.
Source: drawthingsai/draw-things-community on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.