# How to install ComfyUI on an NVIDIA GPU server securely

> Install ComfyUI in a Python virtual environment with CUDA PyTorch, run it as a systemd service on 127.0.0.1 and reach it by SSH tunnel or Caddy with a password.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 13

ComfyUI is an open-source, node-based interface and engine for diffusion models: you build image, video and audio generation pipelines by connecting nodes in a graph, save them as workflows and run them on your GPU. This guide installs ComfyUI **from the official repository in a Python virtual environment** with the CUDA build of PyTorch, runs it as a **systemd service under its own user**, and keeps it on `127.0.0.1`, because ComfyUI has **no built-in authentication**. You then reach it through an SSH tunnel or through **Caddy with HTTPS and a password**, add models and the ComfyUI-Manager, and learn how to back up, update and troubleshoot it.

> **Note**
>
> ComfyUI's documentation states that there is no official Docker image and that community images are not supported. The manual installation shown here is the documented method for Linux servers.

## Prerequisites

- A dedicated server with a supported NVIDIA GPU; see [GPU servers](/gpu-servers).
- **Ubuntu 24.04 LTS** (Python 3.12), **Ubuntu 26.04 LTS** (Python 3.14) or **Debian 13** (Python 3.13). Debian 12 ships Python 3.11, which the ComfyUI README does not list, so it is not covered here.
- A non-root user with `sudo` rights; see [Secure a new Linux server](/guides/secure-a-new-linux-server) and [Set up SSH keys](/guides/ssh-keys).
- For browser access over HTTPS: a domain such as `comfy.example.com` pointing at the server, and Caddy from [Caddy as a reverse proxy](/guides/caddy-reverse-proxy).

| Resource | Minimum (official) | Suggested starting point |
|---|---|---|
| GPU | NVIDIA GPU with a driver that supports the PyTorch CUDA build you install (the README uses cu130) | A GPU with enough VRAM to keep your chosen models loaded |
| VRAM and RAM | README: can run large open models on as little as 4 GB VRAM and 8 GB RAM | 16 GB RAM or more, so offloaded weights do not hit swap |
| Python | 3.13 well supported, 3.12 fallback, 3.14 works | The distribution's default Python 3 |
| Disk | Not published | 100 GB free; checkpoints are often several GB each |

The suggested values are a conservative starting point, not a benchmark. The low-memory figure from the README relies on offloading weights to system RAM; larger models and higher resolutions need more VRAM to run at full speed.

## Step 1 — Install the NVIDIA driver

Install the driver from NVIDIA's network repository as described in NVIDIA's driver installation guide. On Debian, the guide also requires the `contrib` component and enables it with `add-apt-repository`, which Debian 13 no longer ships, so first add `contrib` next to `main` in your APT sources yourself (the `Components:` line in `/etc/apt/sources.list.d/debian.sources`, or the `deb` lines in `/etc/apt/sources.list`):

**Ubuntu**

```bash
sudo apt update
sudo apt install linux-headers-$(uname -r)
distro=ubuntu$(. /etc/os-release && echo "$VERSION_ID" | tr -d .)
wget https://developer.download.nvidia.com/compute/cuda/repos/$distro/x86_64/cuda-keyring_1.1-1_all.deb
sudo dpkg -i cuda-keyring_1.1-1_all.deb
sudo apt update
sudo apt install nvidia-open
sudo reboot
```
**Debian**

```bash
sudo apt update
sudo apt install linux-headers-$(uname -r)
distro=debian$(. /etc/os-release && echo "$VERSION_ID")
wget https://developer.download.nvidia.com/compute/cuda/repos/$distro/x86_64/cuda-keyring_1.1-1_all.deb
sudo dpkg -i cuda-keyring_1.1-1_all.deb
sudo apt update
sudo apt -V install nvidia-open
sudo reboot
```

After the reboot, `nvidia-smi` must list your GPU. Its header shows the highest CUDA version the driver supports; the PyTorch build from the README (cu130) needs a driver that supports CUDA 13.0.

## Step 2 — Create the service user and install system packages

ComfyUI does not need root. Create a dedicated system user whose home directory holds the installation, and install Git and Python's virtual environment support:

```bash
sudo apt install git python3 python3-venv python3-pip
sudo useradd --system --create-home --home-dir /opt/comfyui --shell /usr/sbin/nologin comfyui
```

The `comfyui` user has no login shell and no password. You run commands as this user with `sudo -u comfyui`, which keeps every file it creates owned by the service account.

## Step 3 — Install ComfyUI and PyTorch

Open a shell as the `comfyui` user, clone the repository, create a virtual environment and install PyTorch with the command from the README, then ComfyUI's requirements:

```bash
sudo -u comfyui -H bash
cd /opt/comfyui
git clone https://github.com/Comfy-Org/ComfyUI.git
python3 -m venv /opt/comfyui/venv
source /opt/comfyui/venv/bin/activate
pip install torch torchvision torchaudio --extra-index-url https://download.pytorch.org/whl/cu130
cd ComfyUI
pip install -r requirements.txt
python -c "import torch; print(torch.__version__, torch.cuda.is_available())"
```

The last command should print the PyTorch version followed by `True`. If it prints `False`, see Troubleshooting before you continue. The README's portable builds use CUDA 12.6 for NVIDIA 10-series and older GPUs; for such cards install PyTorch from the `cu126` index instead of `cu130`.

> **Tip**
>
> The ComfyUI README warns that commits between stable release tags can be unstable and break custom nodes. To stay on a stable release, list recent tags with `git tag --sort=-v:refname | head -n 5` inside `ComfyUI` and run `git checkout` with the newest version before installing the requirements.

## Step 4 — Run a first test through an SSH tunnel

Still in the `comfyui` shell with the virtual environment active, start ComfyUI on the loopback address. `--listen` defaults to `127.0.0.1` and `--port` to `8188`; writing them out makes the intent clear:

```bash
python main.py --listen 127.0.0.1 --port 8188
```

The log ends with a line telling you where to open the interface. From your own computer, open an SSH tunnel to the server and browse to `http://localhost:8188`:

```bash
ssh -L 8188:127.0.0.1:8188 user@203.0.113.10
```

The ComfyUI interface loads in your browser. You need a model before a workflow can run (next step). Stop the test with `Ctrl+C` and leave the `comfyui` shell with `exit`.

## Step 5 — Add models

ComfyUI reads models from subfolders of `/opt/comfyui/ComfyUI/models`. The most common ones:

| Folder | Contents |
|---|---|
| `models/checkpoints` | Full model checkpoints (`.safetensors`, `.ckpt`) |
| `models/diffusion_models` | Standalone diffusion model weights used by newer workflows |
| `models/text_encoders`, `models/clip` | Text encoders |
| `models/vae` | VAE files |
| `models/loras` | LoRA adapters |
| `models/controlnet` | ControlNet models |
| `models/upscale_models` | Upscaler models |

Download model files as the `comfyui` user so the service can read them, for example with `wget` from the model's download link on Hugging Face:

```bash
sudo -u comfyui wget -P /opt/comfyui/ComfyUI/models/checkpoints https://huggingface.co/organisation/model/resolve/main/model.safetensors
```

Replace the URL with the real file link of the model you want. Prefer `.safetensors` files: the format stores only tensors, while older `.ckpt` and `.pt` files are Python pickles that can contain executable code. To keep models on another disk, copy `extra_model_paths.yaml.example` to `extra_model_paths.yaml`, set `base_path` and the folder mappings, and restart ComfyUI.

## Step 6 — Run ComfyUI with systemd

Create `/etc/systemd/system/comfyui.service`:

```ini
[Unit]
Description=ComfyUI
After=network-online.target
Wants=network-online.target

[Service]
User=comfyui
Group=comfyui
WorkingDirectory=/opt/comfyui/ComfyUI
ExecStart=/opt/comfyui/venv/bin/python main.py --listen 127.0.0.1 --port 8188
Restart=on-failure
RestartSec=5

[Install]
WantedBy=multi-user.target
```

```bash
sudo systemctl daemon-reload
sudo systemctl enable --now comfyui
systemctl status comfyui --no-pager
curl -I http://127.0.0.1:8188
```

The service is `active (running)` and `curl` returns `HTTP/1.1 200 OK`. Follow the log with `journalctl -u comfyui -f`. Never use `--listen` without an address or with `0.0.0.0`: the flag on its own makes ComfyUI listen on every IPv4 and IPv6 address (`0.0.0.0,::`).

## Step 7 — Add HTTPS and a password with Caddy

For daily use from a browser, put Caddy in front of ComfyUI with HTTP basic authentication. Generate a password hash; `caddy hash-password` prompts for the password twice and prints a bcrypt hash:

```bash
caddy hash-password
```

Add a site block to `/etc/caddy/Caddyfile` with your user name and the hash. Caddy proxies ComfyUI's WebSocket connection, which the interface uses for progress updates, without extra settings:

```caddyfile
comfy.example.com {
    basic_auth {
        admin $2a$14$replace-with-the-hash-from-caddy-hash-password
    }
    reverse_proxy 127.0.0.1:8188
}
```

Reload Caddy and allow only SSH and web traffic:

```bash
sudo systemctl reload caddy
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
```

Open `https://comfy.example.com`, enter the user name and password, and run a workflow. Use a long, unique password: everyone who passes the prompt has full control over ComfyUI.

> **Danger**
>
> Never expose port 8188 directly to the internet. ComfyUI has no authentication, and anyone who reaches it can run workflows on your GPU and, with the Manager enabled, install code that runs on your server.

## Step 8 — Enable ComfyUI-Manager and install custom nodes carefully

ComfyUI-Manager installs, updates and removes custom nodes from the interface. Current ComfyUI versions ship it as a Python package listed in `manager_requirements.txt` and enable it with the `--enable-manager` flag:

```bash
sudo -u comfyui /opt/comfyui/venv/bin/pip install -r /opt/comfyui/ComfyUI/manager_requirements.txt
```

Then add `--enable-manager` to the end of the `ExecStart` line in `comfyui.service` and run `sudo systemctl daemon-reload && sudo systemctl restart comfyui`. A **Manager** button appears in the interface.

Custom nodes are Python code that runs as the `comfyui` user with access to everything that user can read. The ComfyUI documentation warns that malicious plugins can exploit custom nodes; install only nodes from trusted, widely used authors and understand what a node does before you install it. ComfyUI-Manager has a `security_level` setting (`strong`, `normal`, `normal-`, `weak`) in its `config.ini` under the user directory, and it refuses installs from Git URLs and pip on non-loopback listeners. Because these restrictions depend on ComfyUI's listen address, and ComfyUI listens on `127.0.0.1` here, they do not apply to users who come in through Caddy, which is one more reason to protect the site with a strong password. After installing nodes, check the log for `import failed` messages.

## Back up and restore

ComfyUI's state lives in a few folders under `/opt/comfyui/ComfyUI`: `user` (settings and the workflows you save in the interface), `custom_nodes`, `input` and `output`. Models are large and can usually be downloaded again, so archive them separately and without compression:

```bash
sudo mkdir -p /opt/backups
sudo systemctl stop comfyui
sudo tar czf /opt/backups/comfyui-$(date +%F).tar.gz -C /opt/comfyui/ComfyUI user custom_nodes input output
sudo tar cf /opt/backups/comfyui-models-$(date +%F).tar -C /opt/comfyui/ComfyUI models
sudo systemctl start comfyui
```

If you created `extra_model_paths.yaml`, add it to the first archive. To restore, install ComfyUI with Steps 2 and 3, extract the archives into `/opt/comfyui/ComfyUI`, restore ownership and reinstall the Python requirements of your custom nodes:

```bash
sudo tar xzf /opt/backups/comfyui-YYYY-MM-DD.tar.gz -C /opt/comfyui/ComfyUI
sudo tar xf /opt/backups/comfyui-models-YYYY-MM-DD.tar -C /opt/comfyui/ComfyUI
sudo chown -R comfyui:comfyui /opt/comfyui
for f in /opt/comfyui/ComfyUI/custom_nodes/*/requirements.txt; do sudo -u comfyui /opt/comfyui/venv/bin/pip install -r "$f"; done
sudo systemctl restart comfyui
```

Copy the backups off the server as well, especially your workflows.

## Update ComfyUI

Read the release notes on the ComfyUI releases page and back up first. The documented update procedure is `git pull` in the installation directory followed by `pip install -r requirements.txt` inside the ComfyUI virtual environment:

```bash
sudo systemctl stop comfyui
sudo -u comfyui git -C /opt/comfyui/ComfyUI pull
sudo -u comfyui /opt/comfyui/venv/bin/pip install -r /opt/comfyui/ComfyUI/requirements.txt
sudo -u comfyui /opt/comfyui/venv/bin/pip install -r /opt/comfyui/ComfyUI/manager_requirements.txt
sudo systemctl start comfyui
```

Skip the `manager_requirements.txt` line if you did not enable the Manager. If you checked out a release tag in Step 3, run `git -C /opt/comfyui/ComfyUI fetch --tags` and check out the new tag instead of `git pull`. Update custom nodes from the Manager afterwards and check the log for import errors.

## Troubleshooting

### Torch not compiled with CUDA enabled

The installed PyTorch build has no CUDA support. The README's fix is to uninstall PyTorch and reinstall the CUDA build: run `sudo -u comfyui /opt/comfyui/venv/bin/pip uninstall torch` and repeat the `pip install torch torchvision torchaudio` command from Step 3.

### torch.cuda.is_available() returns False

Check `nvidia-smi` first. If it fails, fix the driver and reboot. If it works but its header shows a CUDA version lower than 13.0, the driver is too old for the cu130 build: update the driver from NVIDIA's repository, or install PyTorch from the matching older CUDA index.

### CUDA out of memory

The model, resolution or batch size needs more VRAM than is free. Lower the resolution or batch size, use a smaller or quantized model, and make sure no other process holds GPU memory (`nvidia-smi`). ComfyUI also offers `--novram` for very small GPUs; `--lowvram` has no effect when ComfyUI's dynamic VRAM management is active. Add such flags to `ExecStart` and restart the service.

### A custom node fails with import failed

Its Python dependencies are missing or conflict. Read the error in `journalctl -u comfyui`, install the node's `requirements.txt` into the virtual environment as the `comfyui` user, or remove the node folder. Starting once with `--disable-all-custom-nodes` shows whether a custom node causes a crash.

### The browser keeps asking for the password or shows a blank page

Check the hash in the Caddyfile (it must come from `caddy hash-password`, not the plain password) and run `sudo systemctl reload caddy`. If the page loads but progress never updates, test the tunnel at `http://localhost:8188` to rule out the proxy, and read `journalctl -u caddy` for errors.

## Next steps

- Serve language models next to ComfyUI with [Ollama](/guides/install-ollama) or [vLLM](/guides/install-vllm).
- Experiment with notebooks on the same GPU using [JupyterLab](/guides/install-jupyterlab).
- Choose hardware on the [ComfyUI hosting](/comfyui-hosting) and [GPU servers](/gpu-servers) pages.
- Read the official documentation at https://docs.comfy.org for workflows, nodes and models.

## Frequently asked questions

### Does ComfyUI have a login or password?

No. ComfyUI has no built-in authentication, so anyone who can reach its port can run workflows and, with the Manager, install code. Keep it on 127.0.0.1 and use an SSH tunnel or a reverse proxy with a password, such as Caddy with basic_auth.

### Is there an official ComfyUI Docker image?

No. The ComfyUI documentation states that there is no official Docker image and that community images are not supported. This guide uses the documented manual installation in a Python virtual environment.

### Are custom nodes safe to install?

Custom nodes are Python code that runs with the permissions of the ComfyUI service. The documentation warns that malicious plugins can exploit them, so install only nodes from trusted, widely used authors and read what a node does before installing it.

### How much GPU memory does ComfyUI need?

The ComfyUI README states that it can run large open models on as little as 4 GB of VRAM and 8 GB of RAM by offloading weights. More VRAM lets models stay on the GPU; check the requirements of the specific model you plan to use.

### Which Python version should I use?

The README says Python 3.13 is very well supported, 3.12 is the fallback if custom node dependencies fail, and 3.14 works with possible custom node issues. Ubuntu 24.04 ships 3.12, Debian 13 ships 3.13 and Ubuntu 26.04 ships 3.14.

---

Source: <https://hyperdc.com/guides/tutorials/install-comfyui>\
Updated: 2026-10-09
