Skip to content

TutorialsAI & LLM

How to install ComfyUI on an NVIDIA GPU server securely

Install ComfyUI in a Python virtual environment with CUDA PyTorch, run it as a systemd service on 127.0.0.1 and reach it by SSH tunnel or Caddy with a password.

  • Intermediate
  • 45 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Prerequisites
  2. Step 1 — Install the NVIDIA driver
  3. Step 2 — Create the service user and install system packages
  4. Step 3 — Install ComfyUI and PyTorch
  5. Step 4 — Run a first test through an SSH tunnel
  6. Step 5 — Add models
  7. Step 6 — Run ComfyUI with systemd
  8. Step 7 — Add HTTPS and a password with Caddy
  9. Step 8 — Enable ComfyUI-Manager and install custom nodes carefully
  10. Back up and restore
  11. Update ComfyUI
  12. Troubleshooting
  13. Torch not compiled with CUDA enabled
  14. torch.cuda.is_available() returns False
  15. CUDA out of memory
  16. A custom node fails with import failed
  17. The browser keeps asking for the password or shows a blank page
  18. Next steps

ComfyUI is an open-source, node-based interface and engine for diffusion models: you build image, video and audio generation pipelines by connecting nodes in a graph, save them as workflows and run them on your GPU. This guide installs ComfyUI from the official repository in a Python virtual environment with the CUDA build of PyTorch, runs it as a systemd service under its own user, and keeps it on 127.0.0.1, because ComfyUI has no built-in authentication. You then reach it through an SSH tunnel or through Caddy with HTTPS and a password, add models and the ComfyUI-Manager, and learn how to back up, update and troubleshoot it.

Prerequisites

  • A dedicated server with a supported NVIDIA GPU; see GPU servers.
  • Ubuntu 24.04 LTS (Python 3.12), Ubuntu 26.04 LTS (Python 3.14) or Debian 13 (Python 3.13). Debian 12 ships Python 3.11, which the ComfyUI README does not list, so it is not covered here.
  • A non-root user with sudo rights; see Secure a new Linux server and Set up SSH keys.
  • For browser access over HTTPS: a domain such as comfy.example.com pointing at the server, and Caddy from Caddy as a reverse proxy.
ResourceMinimum (official)Suggested starting point
GPUNVIDIA GPU with a driver that supports the PyTorch CUDA build you install (the README uses cu130)A GPU with enough VRAM to keep your chosen models loaded
VRAM and RAMREADME: can run large open models on as little as 4 GB VRAM and 8 GB RAM16 GB RAM or more, so offloaded weights do not hit swap
Python3.13 well supported, 3.12 fallback, 3.14 worksThe distribution's default Python 3
DiskNot published100 GB free; checkpoints are often several GB each

The suggested values are a conservative starting point, not a benchmark. The low-memory figure from the README relies on offloading weights to system RAM; larger models and higher resolutions need more VRAM to run at full speed.

Step 1 — Install the NVIDIA driver

Install the driver from NVIDIA's network repository as described in NVIDIA's driver installation guide. On Debian, the guide also requires the contrib component and enables it with add-apt-repository, which Debian 13 no longer ships, so first add contrib next to main in your APT sources yourself (the Components: line in /etc/apt/sources.list.d/debian.sources, or the deb lines in /etc/apt/sources.list):

Ubuntu

Bash
sudo apt update
sudo apt install linux-headers-$(uname -r)
distro=ubuntu$(. /etc/os-release && echo "$VERSION_ID" | tr -d .)
wget https://developer.download.nvidia.com/compute/cuda/repos/$distro/x86_64/cuda-keyring_1.1-1_all.deb
sudo dpkg -i cuda-keyring_1.1-1_all.deb
sudo apt update
sudo apt install nvidia-open
sudo reboot

Debian

Bash
sudo apt update
sudo apt install linux-headers-$(uname -r)
distro=debian$(. /etc/os-release && echo "$VERSION_ID")
wget https://developer.download.nvidia.com/compute/cuda/repos/$distro/x86_64/cuda-keyring_1.1-1_all.deb
sudo dpkg -i cuda-keyring_1.1-1_all.deb
sudo apt update
sudo apt -V install nvidia-open
sudo reboot

After the reboot, nvidia-smi must list your GPU. Its header shows the highest CUDA version the driver supports; the PyTorch build from the README (cu130) needs a driver that supports CUDA 13.0.

Step 2 — Create the service user and install system packages

ComfyUI does not need root. Create a dedicated system user whose home directory holds the installation, and install Git and Python's virtual environment support:

Bash
sudo apt install git python3 python3-venv python3-pip
sudo useradd --system --create-home --home-dir /opt/comfyui --shell /usr/sbin/nologin comfyui

The comfyui user has no login shell and no password. You run commands as this user with sudo -u comfyui, which keeps every file it creates owned by the service account.

Step 3 — Install ComfyUI and PyTorch

Open a shell as the comfyui user, clone the repository, create a virtual environment and install PyTorch with the command from the README, then ComfyUI's requirements:

Bash
sudo -u comfyui -H bash
cd /opt/comfyui
git clone https://github.com/Comfy-Org/ComfyUI.git
python3 -m venv /opt/comfyui/venv
source /opt/comfyui/venv/bin/activate
pip install torch torchvision torchaudio --extra-index-url https://download.pytorch.org/whl/cu130
cd ComfyUI
pip install -r requirements.txt
python -c "import torch; print(torch.__version__, torch.cuda.is_available())"

The last command should print the PyTorch version followed by True. If it prints False, see Troubleshooting before you continue. The README's portable builds use CUDA 12.6 for NVIDIA 10-series and older GPUs; for such cards install PyTorch from the cu126 index instead of cu130.

Step 4 — Run a first test through an SSH tunnel

Still in the comfyui shell with the virtual environment active, start ComfyUI on the loopback address. --listen defaults to 127.0.0.1 and --port to 8188; writing them out makes the intent clear:

Bash
python main.py --listen 127.0.0.1 --port 8188

The log ends with a line telling you where to open the interface. From your own computer, open an SSH tunnel to the server and browse to http://localhost:8188:

Bash
ssh -L 8188:127.0.0.1:8188 user@203.0.113.10

The ComfyUI interface loads in your browser. You need a model before a workflow can run (next step). Stop the test with Ctrl+C and leave the comfyui shell with exit.

Step 5 — Add models

ComfyUI reads models from subfolders of /opt/comfyui/ComfyUI/models. The most common ones:

FolderContents
models/checkpointsFull model checkpoints (.safetensors, .ckpt)
models/diffusion_modelsStandalone diffusion model weights used by newer workflows
models/text_encoders, models/clipText encoders
models/vaeVAE files
models/lorasLoRA adapters
models/controlnetControlNet models
models/upscale_modelsUpscaler models

Download model files as the comfyui user so the service can read them, for example with wget from the model's download link on Hugging Face:

Bash
sudo -u comfyui wget -P /opt/comfyui/ComfyUI/models/checkpoints https://huggingface.co/organisation/model/resolve/main/model.safetensors

Replace the URL with the real file link of the model you want. Prefer .safetensors files: the format stores only tensors, while older .ckpt and .pt files are Python pickles that can contain executable code. To keep models on another disk, copy extra_model_paths.yaml.example to extra_model_paths.yaml, set base_path and the folder mappings, and restart ComfyUI.

Step 6 — Run ComfyUI with systemd

Create /etc/systemd/system/comfyui.service:

INI
[Unit]
Description=ComfyUI
After=network-online.target
Wants=network-online.target

[Service]
User=comfyui
Group=comfyui
WorkingDirectory=/opt/comfyui/ComfyUI
ExecStart=/opt/comfyui/venv/bin/python main.py --listen 127.0.0.1 --port 8188
Restart=on-failure
RestartSec=5

[Install]
WantedBy=multi-user.target
Bash
sudo systemctl daemon-reload
sudo systemctl enable --now comfyui
systemctl status comfyui --no-pager
curl -I http://127.0.0.1:8188

The service is active (running) and curl returns HTTP/1.1 200 OK. Follow the log with journalctl -u comfyui -f. Never use --listen without an address or with 0.0.0.0: the flag on its own makes ComfyUI listen on every IPv4 and IPv6 address (0.0.0.0,::).

Step 7 — Add HTTPS and a password with Caddy

For daily use from a browser, put Caddy in front of ComfyUI with HTTP basic authentication. Generate a password hash; caddy hash-password prompts for the password twice and prints a bcrypt hash:

Bash
caddy hash-password

Add a site block to /etc/caddy/Caddyfile with your user name and the hash. Caddy proxies ComfyUI's WebSocket connection, which the interface uses for progress updates, without extra settings:

Caddyfile
comfy.example.com {
    basic_auth {
        admin $2a$14$replace-with-the-hash-from-caddy-hash-password
    }
    reverse_proxy 127.0.0.1:8188
}

Reload Caddy and allow only SSH and web traffic:

Bash
sudo systemctl reload caddy
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

Open https://comfy.example.com, enter the user name and password, and run a workflow. Use a long, unique password: everyone who passes the prompt has full control over ComfyUI.

Step 8 — Enable ComfyUI-Manager and install custom nodes carefully

ComfyUI-Manager installs, updates and removes custom nodes from the interface. Current ComfyUI versions ship it as a Python package listed in manager_requirements.txt and enable it with the --enable-manager flag:

Bash
sudo -u comfyui /opt/comfyui/venv/bin/pip install -r /opt/comfyui/ComfyUI/manager_requirements.txt

Then add --enable-manager to the end of the ExecStart line in comfyui.service and run sudo systemctl daemon-reload && sudo systemctl restart comfyui. A Manager button appears in the interface.

Custom nodes are Python code that runs as the comfyui user with access to everything that user can read. The ComfyUI documentation warns that malicious plugins can exploit custom nodes; install only nodes from trusted, widely used authors and understand what a node does before you install it. ComfyUI-Manager has a security_level setting (strong, normal, normal-, weak) in its config.ini under the user directory, and it refuses installs from Git URLs and pip on non-loopback listeners. Because these restrictions depend on ComfyUI's listen address, and ComfyUI listens on 127.0.0.1 here, they do not apply to users who come in through Caddy, which is one more reason to protect the site with a strong password. After installing nodes, check the log for import failed messages.

Back up and restore

ComfyUI's state lives in a few folders under /opt/comfyui/ComfyUI: user (settings and the workflows you save in the interface), custom_nodes, input and output. Models are large and can usually be downloaded again, so archive them separately and without compression:

Bash
sudo mkdir -p /opt/backups
sudo systemctl stop comfyui
sudo tar czf /opt/backups/comfyui-$(date +%F).tar.gz -C /opt/comfyui/ComfyUI user custom_nodes input output
sudo tar cf /opt/backups/comfyui-models-$(date +%F).tar -C /opt/comfyui/ComfyUI models
sudo systemctl start comfyui

If you created extra_model_paths.yaml, add it to the first archive. To restore, install ComfyUI with Steps 2 and 3, extract the archives into /opt/comfyui/ComfyUI, restore ownership and reinstall the Python requirements of your custom nodes:

Bash
sudo tar xzf /opt/backups/comfyui-YYYY-MM-DD.tar.gz -C /opt/comfyui/ComfyUI
sudo tar xf /opt/backups/comfyui-models-YYYY-MM-DD.tar -C /opt/comfyui/ComfyUI
sudo chown -R comfyui:comfyui /opt/comfyui
for f in /opt/comfyui/ComfyUI/custom_nodes/*/requirements.txt; do sudo -u comfyui /opt/comfyui/venv/bin/pip install -r "$f"; done
sudo systemctl restart comfyui

Copy the backups off the server as well, especially your workflows.

Update ComfyUI

Read the release notes on the ComfyUI releases page and back up first. The documented update procedure is git pull in the installation directory followed by pip install -r requirements.txt inside the ComfyUI virtual environment:

Bash
sudo systemctl stop comfyui
sudo -u comfyui git -C /opt/comfyui/ComfyUI pull
sudo -u comfyui /opt/comfyui/venv/bin/pip install -r /opt/comfyui/ComfyUI/requirements.txt
sudo -u comfyui /opt/comfyui/venv/bin/pip install -r /opt/comfyui/ComfyUI/manager_requirements.txt
sudo systemctl start comfyui

Skip the manager_requirements.txt line if you did not enable the Manager. If you checked out a release tag in Step 3, run git -C /opt/comfyui/ComfyUI fetch --tags and check out the new tag instead of git pull. Update custom nodes from the Manager afterwards and check the log for import errors.

Troubleshooting

Torch not compiled with CUDA enabled

The installed PyTorch build has no CUDA support. The README's fix is to uninstall PyTorch and reinstall the CUDA build: run sudo -u comfyui /opt/comfyui/venv/bin/pip uninstall torch and repeat the pip install torch torchvision torchaudio command from Step 3.

torch.cuda.is_available() returns False

Check nvidia-smi first. If it fails, fix the driver and reboot. If it works but its header shows a CUDA version lower than 13.0, the driver is too old for the cu130 build: update the driver from NVIDIA's repository, or install PyTorch from the matching older CUDA index.

CUDA out of memory

The model, resolution or batch size needs more VRAM than is free. Lower the resolution or batch size, use a smaller or quantized model, and make sure no other process holds GPU memory (nvidia-smi). ComfyUI also offers --novram for very small GPUs; --lowvram has no effect when ComfyUI's dynamic VRAM management is active. Add such flags to ExecStart and restart the service.

A custom node fails with import failed

Its Python dependencies are missing or conflict. Read the error in journalctl -u comfyui, install the node's requirements.txt into the virtual environment as the comfyui user, or remove the node folder. Starting once with --disable-all-custom-nodes shows whether a custom node causes a crash.

The browser keeps asking for the password or shows a blank page

Check the hash in the Caddyfile (it must come from caddy hash-password, not the plain password) and run sudo systemctl reload caddy. If the page loads but progress never updates, test the tunnel at http://localhost:8188 to rule out the proxy, and read journalctl -u caddy for errors.

Next steps

Frequently asked questions

Does ComfyUI have a login or password?

No. ComfyUI has no built-in authentication, so anyone who can reach its port can run workflows and, with the Manager, install code. Keep it on 127.0.0.1 and use an SSH tunnel or a reverse proxy with a password, such as Caddy with basic_auth.

Is there an official ComfyUI Docker image?

No. The ComfyUI documentation states that there is no official Docker image and that community images are not supported. This guide uses the documented manual installation in a Python virtual environment.

Are custom nodes safe to install?

Custom nodes are Python code that runs with the permissions of the ComfyUI service. The documentation warns that malicious plugins can exploit them, so install only nodes from trusted, widely used authors and read what a node does before installing it.

How much GPU memory does ComfyUI need?

The ComfyUI README states that it can run large open models on as little as 4 GB of VRAM and 8 GB of RAM by offloading weights. More VRAM lets models stay on the GPU; check the requirements of the specific model you plan to use.

Which Python version should I use?

The README says Python 3.13 is very well supported, 3.12 is the fallback if custom node dependencies fail, and 3.14 works with possible custom node issues. Ubuntu 24.04 ships 3.12, Debian 13 ships 3.13 and Ubuntu 26.04 ships 3.14.

Sources

Wachtwoord genereren

Please confirm