proxy-aiops
Use this skill whenever the user needs to operate a Traefik, Caddy or HAProxy reverse proxy / load balancer — a one-shot overview, routes (routers / caddy routes / frontends) with host/path matching, services and server-level upstream health, middlewares, TLS certificate inventory with an expiry sweep, traffic and 5xx error counters, config snapshot/search, four flagship RCAs (backend health, cert expiry, error rate, route conflicts), and governed writes (caddy config set/delete/load with prior-config capture; haproxy server drain/maint/ready and weight). Always use this skill for "Traefik", "Caddy", "HAProxy", "reverse proxy", "load balancer", "upstream down", "502/503/504 errors", "bad gateway", "cert expiring", "TLS certificate", "route not matching", "which route serves this host", "drain a server", "server weight", "redirect loop" when the context is a Traefik/Caddy/HAProxy edge. Do NOT use when the target is something other than a Traefik/Caddy/HAProxy proxy (a hypervisor, storage appliance, backup product, container-orchestration cluster, multi-vendor router/switch config, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Do NOT use for firewall rules — use firewall-aiops. Managed cloud load balancers are out of scope. Governed proxy operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Behaviour is validated by a mock-based test suite; see docs/VERIFICATION.md for the live-verification checklist.
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
0.9.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.9.4release · observed Sep 16, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:proxy-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:proxy-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/proxy-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-proxy-aiops/snapshot"
Documentation
CLAWHUB
148,966 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: proxy-aiops
slug: proxy-aiops
displayName: "Proxy AIops"
summary: "Governed Traefik + Caddy + HAProxy ops: routes, upstreams, certs, 5xx RCA. 28 tools."
license: MIT
homepage: https://github.com/AIops-tools/Proxy-AIops
tags: [aiops, mcp, governance, proxy]
description: >
Use this skill whenever the user needs to operate a Traefik, Caddy or HAProxy reverse proxy / load balancer — a one-shot overview, routes (routers / caddy routes / frontends) with host/path matching, services and server-level upstream health, middlewares, TLS certificate inventory with an expiry sweep, traffic and 5xx error counters, config snapshot/search, four flagship RCAs (backend health, cert expiry, error rate, route conflicts), and governed writes (caddy config set/delete/load with prior-config capture; haproxy server drain/maint/ready and weight).
Always use this skill for "Traefik", "Caddy", "HAProxy", "reverse proxy", "load balancer", "upstream down", "502/503/504 errors", "bad gateway", "cert expiring", "TLS certificate", "route not matching", "which route serves this host", "drain a server", "server weight", "redirect loop" when the context is a Traefik/Caddy/HAProxy edge.
Do NOT use when the target is something other than a Traefik/Caddy/HAProxy proxy (a hypervisor, storage appliance, backup product, container-orchestration cluster, multi-vendor router/switch config, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Do NOT use for firewall rules — use firewall-aiops. Managed cloud load balancers are out of scope.
Governed proxy operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Behaviour is validated by a mock-based test suite; see docs/VERIFICATION.md for the live-verification checklist.
installer:
kind: uv
package: proxy-aiops
argument-hint: "[a route/service/backend name, a hostname, or describe your proxy task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["proxy-aiops","uvx"]},"optional":{"env":["PROXY_AIOPS_CONFIG","PROXY_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Proxy-AIops","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed reverse-proxy operations across Traefik (API /api/..., metrics-text counters via /metrics), Caddy (admin API, default localhost:2019 — carries the write surface) and HAProxy (Data Plane API v2 /v2/..., HTTP Basic auth). Each target in the config names its own platform, and a name-keyed platform registry selects the API shape; an explicit support matrix raises teaching errors for ops a platform cannot do (traefik writes → its providers; caddy error counters → access logs; haproxy certs → the .pem pipeline), never a silent no-op. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
All write operations are audited to a local SQLite DB under ~/.proxy-aiops/ (relocatable_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "proxy-aiops",
"version": "0.9.4",
"publishedAt": 1789601191173
}references/agent-guardrails.md
# Agent guardrails — running proxy-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## Authorization is not this tool's job — decide it where it belongs
Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:
- **The account you connect with.** Give the HAProxy Data Plane API a read-only
role, or point the tool at a Traefik/Caddy admin API you have scoped down. A
write then fails at the server, which is the only place the permission actually
lives — a revoked permission cannot be argued around by a model, but a skill-side
flag can.
- **Your agent's system prompt.** If you want an observe-only session, tell the
model not to call the write tools (they are clearly tagged `[WRITE]`).
What the tool *does* guarantee is that you can always see what happened:
## What the tool enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Don't invent a value when a field is missing" | Traefik, Caddy and HAProxy express the same concepts differently, so a field one platform has and another does not comes back as `null`, never as `""`. A Caddy route's `raw` rule string is `null` — Caddy matches on a match list and has no such string — rather than a misleading empty rule. |
| "Tell me if the output was cut off" | `search_config`, `traffic_stats` and `error_counters` return `{"matches"/"services": [...], "returned": N, "limit": L, "truncated": true/false}` — one convention across the repo. Truncation is measured (the config walk deliberately overshoots by one) and not guessed from the count reaching the cap. |
| "Make it show the number it judged on" | `error_rate_rca` returns `errorRatePct`, `vsBaselineX` against the fleet baseline and a `severity` of `critical`/`warning` on every flagged service; `cert_expiry_sweep` returns `daysToExpiry` and a `bucket` per certificate, and orders by `daysToExpiry`. Both orderings are therefore checkable from the payload itself. |
| "Confirm before anything destructive" | `delete_config_path` and `load_config` require a `--dry-run`-able preview plus double confirmation at the CLI. Config writes capture the prior value so the undo token can restore it. |
| "Log what you did" | Every governed call is audited to `~/.proxy-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same roreferences/capabilities.md
# proxy-aiops — capabilities reference
## Platforms
| Platform | API | Auth | Default base_url |
|----------|-----|------|------------------|
| `traefik` | Traefik API (`/api/...`) + `/metrics` text | none, or optional HTTP Basic (username + stored secret) | `http://localhost:8080` |
| `caddy` | Admin API (`/config/`, `/load`, `/reverse_proxy/upstreams`) | none, or optional HTTP Basic | `http://localhost:2019` |
| `haproxy` | Data Plane API v2 (`/v2/...`) | HTTP Basic (username + stored secret, **required**) | `http://localhost:5555` |
A per-target `platform` field selects the shape; the ops/CLI/MCP layers are
platform-neutral. Unsupported ops raise **teaching errors** (what to use
instead), never silent empties.
## Support matrix
| Capability | traefik | caddy | haproxy |
|------------|:-------:|:-----:|:-------:|
| version_info | ✅ `/api/version` | teaching note (no version endpoint) | ✅ `/v2/info` |
| list_entrypoints | ✅ `/api/entrypoints` | ✅ server listen addresses | ✅ frontends |
| list_routes / route_detail / find_route | ✅ routers (rule parsed) | ✅ routes (name = config path) | ✅ frontends (ACLs not parsed) |
| list_services / service_detail | ✅ services + serverStatus | ✅ reverse_proxy routes + upstreams | ✅ backends + stats |
| list_upstreams / upstream_detail | ✅ serverStatus map | ✅ `/reverse_proxy/upstreams` (fails→down) | ✅ stats server rows (status + check_status) |
| list_middlewares | ✅ | teaching (inline handlers) | teaching (haproxy.cfg) |
| list_certificates / cert_expiry_sweep | ✅ TLS routers + tls.domains | ✅ TLS listeners + automation subjects | teaching (.pem files) |
| traffic_stats / error_counters | ✅ `/metrics` per-code | teaching (no per-route counters) | ✅ stats (`req_tot`, `hrsp_*`) |
| config_snapshot / search_config | ✅ `/api/rawdata` (read-only) | ✅ `/config/` | teaching |
| get/set_config_value, delete_config_path, load_config | teaching (edit the provider) | ✅ (the write surface) | teaching (use runtime writes) |
| set_server_state / set_server_weight | teaching (provider) | teaching (config tree) | ✅ runtime servers |
## MCP tools (28)
### Reads (21)
| Tool | Returns |
|------|---------|
| `proxy_overview` | platform/version + route/service counts + upstream up/down |
| `version_info` | version/build info |
| `list_entrypoints` | listeners: {name, address} |
| `list_routes(host?)` | normalised routes: {name, hosts, paths, priority, service, tls, enabled, redirectTo} |
| `route_detail(name)` | one route's full detail |
| `find_route(host, path)` | routes that would serve a host/path, best first |
| `list_services` | services/backends: {name, serversTotal, serversUp} |
| `service_detail(name)` | one service's detail (+ haproxy servers) |
| `list_upstreams(service?)` | server rows: {service, server, address, status up/down/maint/drain, checkInfo, weight} |
| `upstream_detail(service, server)` | one server row |
| `list_middlewares` | traefik middlewares (teaching elsewhere) |
| `list_certificates(probe?,references/cli-reference.md
# proxy-aiops — CLI reference Global option on most commands: `--target/-t <name>` (default: first target in config). ## Setup & health ```bash proxy-aiops init # interactive wizard: platform, base_url, TLS verify, encrypted secret proxy-aiops doctor # config + secrets + connectivity (probe per platform) proxy-aiops doctor --skip-auth # skip the connectivity probe proxy-aiops overview # one-shot: version + routes/services + upstream health ``` ## Reads ```bash proxy-aiops routes list [--host app.example.com] proxy-aiops routes show <name> # traefik router name / caddy config path / haproxy frontend proxy-aiops routes find <host> [--path /] # which routes would serve host/path proxy-aiops services list proxy-aiops services show <name> proxy-aiops services upstreams [--service <name>] proxy-aiops certs [--sweep] [--warn-days 30] [--critical-days 7] [--port 443] proxy-aiops config snapshot proxy-aiops config search <query> proxy-aiops config get <path> ``` ## Flagship analyses ```bash proxy-aiops analyze health [--service <name>] # backend/upstream health RCA proxy-aiops analyze errors [--rate 5.0] [--min-requests 30] # 5xx error-rate RCA proxy-aiops analyze conflicts # shadowed/dead routes, redirect loops ``` ## Governed writes (dry-run + double-confirm; audited + undo-recorded) ```bash # caddy config (teaching error on traefik/haproxy targets) proxy-aiops config set <path> '<json>' [--dry-run] proxy-aiops config delete <path> [--dry-run] # risk=high, double-confirm # haproxy runtime servers (teaching error on traefik/caddy targets) proxy-aiops server state <backend> <server> ready|drain|maint [--dry-run] proxy-aiops server weight <backend> <server> <0-256> [--dry-run] ``` High-risk writes prompt for double confirmation at the CLI. Optionally export `PROXY_AUDIT_APPROVED_BY` (and `PROXY_AUDIT_RATIONALE`) to annotate the audit row with who/why — never required. ## Secrets ```bash proxy-aiops secret set <target> # store encrypted (hidden prompt) proxy-aiops secret list # names only, never values proxy-aiops secret rm <target> proxy-aiops secret migrate # import legacy plaintext .env proxy-aiops secret rotate-password # re-encrypt under a new master password ``` ## MCP server ```bash proxy-aiops mcp # stdio transport (or: proxy-aiops-mcp) ``` ## Environment variables | Variable | Purpose | |----------|---------| | `PROXY_AIOPS_MASTER_PASSWORD` | unlock secrets.enc non-interactively (MCP/CI) | | `PROXY_AIOPS_CONFIG` | alternate config.yaml path (MCP server) | | `PROXY_AIOPS_HOME` | relocate config/audit/undo state dir | | `PROXY_AUDIT_APPROVED_BY` / `PROXY_AUDIT_RATIONALE` | optional approver/rationale annotations recorded on the audit row | | `PROXY_MAX_TOOL_CALLS` / `PROXY_MAX_TOOL_SECONDS` | per-process budget ceilings | | `PROXY_RUNAWAY_MAX` / `PROXY_RUNAWAY_WINDOW_SEC` | runaway circuit-breaker tuning | | `P
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/proxy-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/proxy-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T17:07:11.725Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-proxy-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-proxy-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T17:07:11.725Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/zw008/proxy-aiops",
"sourceUrl": "https://clawhub.ai/zw008/proxy-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T17:07:11.725Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.9.4",
"href": "https://clawhub.ai/zw008/proxy-aiops",
"sourceUrl": "https://clawhub.ai/zw008/proxy-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:26:31.173Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-proxy-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-proxy-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.9.4",
"description": "proxy-aiops 0.9.4 - Updated agent-guardrails documentation. - Removed the skill-card.md file.",
"href": "https://clawhub.ai/zw008/proxy-aiops",
"sourceUrl": "https://clawhub.ai/zw008/proxy-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:26:31.173Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
