AI Agent Hub
Back to skills
Frp-cli Intranet Tunneling icon

Frp-cli Intranet Tunneling

IT Ops & Security Updated 2026.08.29

Paste the following prompt into your AI chat to install this skill:

Please install @user_2ea8b68d/frp-cli according to https://skillhub.cn/install/skillhub.md.

About this skill

Problem

Running frp tunnels often becomes less about reachability and more about state management: frpc and frps configs get scattered, TOML edits are easy to get wrong, tunnel status is opaque, firewall rules are missed, and client/server environments get mixed together. This skill uses frp-cli as a consistent operations surface, relying on profiles, structured JSON output, daemon management, and admin/dashboard API passthrough instead of hand-editing TOML or invoking raw frpc/frps repeatedly.

How It Works

  • Idempotent initialization: a .setup-done marker tells whether first-time setup has already happened, preventing repeated installs or profile creation.
  • Full setup path: it moves from deciding whether a public frps exists to deploying the server, connecting the client, adding the first tunnel, and then managing updates.
  • Recipe-style tunnels: SSH, Web, RDP, MySQL, Minecraft, NAS, and temporary Webhook use cases are treated as role- and port-based flows.
  • Engineering-oriented operations: tunnels can be added, changed, or removed; profiles can be switched; status and diagnostics can be read with stable --json output.
  • P2P handling: home NAS or large-file cases can use xtcp / stcp to avoid consuming public bandwidth.

Limits

This is best for engineers maintaining long-lived intranet tunnels. It does not replace network policy: exposing databases or RDP still requires strong credentials and firewall allowlists; new remotePort mappings require matching cloud security-group and local firewall rules. It does not cover alternatives such as ngrok or cpolar. Stop, delete, or uninstall actions against production-like state should be confirmed first.

Use Cases

  • Run frpc locally to expose lab SSH to public 7022, then verify firewall rules and client status.
  • After deploying frps on a VPS, add a Web tunnel for the team and check dashboard, token, and profile.
  • Switch between production and test profiles, then confirm proxy counts and running state via JSON.
  • Use xtcp for NAS P2P access so large transfers avoid sustained public bandwidth usage.

Best For

  • Ops engineers maintaining lab SSH/Web tunnels who need stable frp tunnel add, update, and status checks.
  • Backend developers using a VPS relay who need to deploy frps, open ports, and debug connection timeouts.
  • Platform engineers managing multiple environments who need to switch profiles and export config backups.
  • Home NAS or game-server operators who need to add tunnels by recipe and align firewall rules.