doca-flow-grpc-server
Where to start: This is a tool skill for standing up and operating `doca_flow_grpc`, the DOCA-shipped gRPC remote- control surface for `doca-flow`.
Install / Use
npx skills add NVIDIA/skills --skill doca-flow-grpc-serverInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of doca-flow-grpc-server
doca-flow-grpc-server scores 88/100 on our quality scale, 481st of 790 Security skills we index.
Its SKILL.md is 16 KB long, well organised into 9 sections and no code examples: a thorough specification that gives an agent plenty to work with.
With 3,421 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 5 days ago, so doca-flow-grpc-server is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
doca-flow-grpc-server compared with similar skills
All 4 of these similar skills score higher than doca-flow-grpc-server; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| doca-flow-grpc-server (this skill)by NVIDIA | 88 | 3.4k | 5d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.0k | 13d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | today | CLAUDE.md |
| crawl4aiby unclecode | 100 | 84.4k | 3d ago | MCP Server |
| Scraplingby D4Vinci | 100 | 84.4k | today | MCP Server |
Frequently asked questions
- How do I install doca-flow-grpc-server?
- Run
npx skills add NVIDIA/skills --skill doca-flow-grpc-server. The install tabs above show the steps for each supported agent. - Which AI agents does doca-flow-grpc-server work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is doca-flow-grpc-server safe to use?
- It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is doca-flow-grpc-server still maintained?
- The repository was last updated 5 days ago, so doca-flow-grpc-server is actively maintained.
Skill content
View source on GitHublicense: Apache-2.0
name: doca-flow-grpc-server
description: >
PLAINTEXT-ONLY: the shipped doca_flow_grpc server uses
grpc::InsecureServerCredentials() with NO TLS / mTLS / token-auth
knob on the binary — transport security must come from external
infrastructure (e.g. an mTLS proxy / sidecar) on a trusted segment.
Use this skill when bringing up, configuring, hardening, or
debugging doca_flow_grpc — the DOCA-shipped gRPC remote-control
surface in front of doca-flow that lets non-C++ clients (Python,
Go, Rust, Java) program Flow pipes and entries over RPC instead of
linking libdoca_flow.so directly. Trigger even when the user
doesn't say 'doca-flow-grpc-server' or 'gRPC' — e.g. 'program Flow
rules from Python on another host', 'remotely configure pipes on the
BlueField', 'client times out connecting to the Flow server', 'where
is the .proto for Flow', 'UNAUTHENTICATED / FAILED_PRECONDITION on a
Flow RPC'. Route elsewhere for the underlying doca-flow API, generic
gRPC tooling (protoc, language bindings), or DOCA install / BFB
bring-up.
metadata:
kind: tool
compatibility: >
Requires DOCA on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a
BlueField DPU or ConnectX NIC. The doca_flow_grpc binary is a build
artifact (install: false in tools/flow_grpc_server/meson.build, gated by
flag_enable_grpc_support + flag_enable_grpc_flow_library) — NOT
installed under a default DOCA path; build it from the DOCA source tree
with gRPC enabled. Its .proto lives under libs/doca_flow/grpc/.
Confirm Flow via pkg-config doca-flow.
DOCA Flow gRPC Server (doca_flow_grpc)
CRITICAL transport-security correction (Run-12 + R13). The shipped
doca_flow_grpc/doca_flow_grpc_clientbinaries hard-code the gRPC plaintext credentials surface: the server usesgrpc::InsecureServerCredentials()(the C++ gRPC server-side API intools/flow_grpc_server/server/); the C++ client usesgrpc::InsecureChannelCredentials()(the C++ gRPC client-side API; the client lives inlibs/doca_flow/grpc/client/, compiled into thedoca_flowlibrary, NOT undertools/flow_grpc_client/); the Python client usesgrpc.aio.insecure_channel(...). Do NOT cite the server-side string asgrpc::InsecureChannelCredentials()— that is the client-side API name and a Grep-against-source verification will fail. There is no TLS, no mTLS, and no token-auth knob on the shipped control plane today. Any prose below (or inCAPABILITIES.md/TASKS.md) that frames "mTLS / token auth / TLS posture" as a configurable knob on this server is the bundle's previous aspirational framing and is wrong against the shipped source. Treat the server as plaintext-on-a-trusted-segment only: it MUST be bound on a control-plane-only network segment behind an external proxy, sidecar, or VPN that itself enforces TLS + identity. Any "TLS / mTLS / token- auth" discussion below is about the operator's external hardening layer, NOT a knob on this binary. Routing for an TLS / identity design discussion must stay on the selected external proxy, sidecar, or VPN; never route it to a shipped-today binary knob.
Where to start: This is a tool skill for standing up and
operating doca_flow_grpc, the DOCA-shipped gRPC remote-
control surface for doca-flow. Open TASKS.md and
start at ## configure to decide whether a
remote control plane is the right answer at all (vs talking to
libdoca_flow.so directly), then ## run for
the start → bind → one-client-smoke sequence, then
## test for the smoke-before-bulk loop that
gates any RPC that mutates Flow / dataplane state. Open
CAPABILITIES.md when the question is what
the gRPC contract surface looks like (the .proto files shipped
under the tool's source tree on the user's install), which
external proxy / sidecar / VPN protects the plaintext server, which language bindings
the gRPC ecosystem covers, or how to interpret the server's
own logs alongside the live Flow application's logs. If DOCA is
not installed, route to
doca-setup first; if the user has
not stood up doca-flow yet, route to
doca-flow FIRST — the gRPC
server is a remote control plane on top of the Flow library, not
a replacement for it.
Example questions this skill answers well
The CLASSES of doca_flow_grpc questions this skill is
built to answer, each with one worked example. The class is the
load-bearing piece; the worked example is one instance.
- "Do I actually need a remote control plane for my Flow
pipeline, or should my client just link
libdoca_flow.sodirectly?" — worked example: "my client is a Python service on a different host; can it program Flow rules remotely?". Answered by the when-to-use-gRPC decision inCAPABILITIES.md ## Capabilities and modes- the routing into
doca-flowwhen a direct library link is the better answer.
- the routing into
- "Where is the gRPC contract surface actually defined on my
install?" — worked example: "I want to generate a Python
client; where do I get the
.protofile?". Answered by the the-.proto-file-is-the-source-of-truth rule inCAPABILITIES.md ## Capabilities and modes- the language-bindings discussion of standard gRPC tooling
(
protoc+ the language-specific gRPC plugin per the official gRPC docs ongrpc.io).
- the language-bindings discussion of standard gRPC tooling
(
- "How do I harden the gRPC endpoint so it isn't an open
door into my dataplane?" — worked example: "the server is
bound on
0.0.0.0; what should I do before exposing it?". Answered by the admin attack surface posture inCAPABILITIES.md ## Safety policy- the external protection / network-segment decision in
TASKS.md ## configure.
- the external protection / network-segment decision in
- "How do I smoke ONE client end-to-end before opening the
server to the fleet?" — worked example: "my Python client
can dial the endpoint; what is the first RPC I run to prove
it talks to the live Flow application?". Answered by the
smoke-before-bulk loop in
TASKS.md ## test+CAPABILITIES.md ## Safety policysmoke-before-bulk rule. - "My client cannot reach the server — is the server down,
the wrong endpoint, an external-proxy mismatch, or a version
mismatch?" — worked example: "the client times out
connecting". Answered by the layered error taxonomy in
CAPABILITIES.md ## Error taxonomy- the layered ladder in
TASKS.md ## debug.
- the layered ladder in
- "Is my non-C++ client (Python / Go / Rust) actually the
right shape for the gRPC contract, or is there a cleaner
path?" — worked example: "I want a Rust client; what
does the
.proto-generated API look like?". Answered by the language-bindings discussion inCAPABILITIES.md ## Capabilities and modes- the routing through standard gRPC tooling.
Audience
This skill serves external operators, control-plane developers,
and AI agents who need to program a running DOCA Flow pipeline
from a non-C++ process across a network boundary instead of
linking libdoca_flow.so directly into the controlling process.
Concretely:
- A control-plane engineer writing a Python / Go / Rust client that programs Flow rules on a BlueField from outside the BlueField's address space.
- A platform operator running a Flow-using service on BlueField who wants to expose a remote-control surface to a centralized control plane.
- An AI agent driving the "can I program these Flow rules from this client / this network position" triage step before recommending a code change to the surrounding doca-flow application.
It is not for users debugging the gRPC server's source code,
not a substitute for the live public DOCA Flow gRPC Server
guide on docs.nvidia.com, and not the place to learn the
doca-flow API — that audience belongs in
doca-flow.
doca_flow_grpc is a single CLI binary built from the DOCA
source tree (executable('doca_flow_grpc', ..., install: false)
in tools/flow_grpc_server/meson.build, gated by
flag_enable_grpc_support), plus its companion .proto
contract files under libs/doca_flow/grpc/; per the tool's
source tree (server/, dpa_device/, packet_buffering/) the
tool can also be paired with a packet-buffering / DPA-side
helper on configurations that need them. The skill uses the
same kind: tool three-file shape (SKILL.md + CAPABILITIES.md + TASKS.md) the rest of the bundle's tool slot uses — front matter at the top of this file already says kind: tool. (Prior bundle revisions said "library three-file shape" here; that wording was internally inconsistent with the front matter and is corrected.)
Language scope
This skill governs deployment, configuration, hardening, and
client-side bring-up across the languages standard gRPC tooling
covers — Python, Go, C++, Rust, Java, Node.js, C#, Kotlin, Ruby,
PHP, Dart — via the language-specific gRPC plugin generated
from the shipped .proto files (see the
gRPC language support index
on grpc.io). The server itself is C++ + DOCA; the client
languages are open, gated only by the standard protoc plugin
set. For the doca-flow API the server programs, see
doca-flow — that surface is
C-language.
When to load this skill
Load this skill when the user is — or the agent needs to — bring
up doca_flow_grpc against a running doca-flow
application (or its preconditions) and connect a non-C++ client
to it. Concretely:
- Deciding whether a remote gRPC control plane is the right
surface (vs a direct
libdoca_flow.solink in the client process). - Locating the
.protofiles on the user's install so a language-binding client can generate the appropriate stubs. - Deciding the deployment's transport-security posture and
network segment. NOTE: the shipped server is plaintext-only
(
grpc::InsecureServerCredentials()); TLS / mTLS / token-auth are NOT binary configuration knobs — they are external infrastructure concerns handled by a capable proxy, sidecar, or VPN, and the plaintext endpoint must stay on a trusted, isolated segment. - Standing up the server alongside a known-good Flow setup and smoke-testing one client end-to-end before exposing the endpoint to the fleet.
- Diagnosing a connect / version / RPC failure through the layered taxonomy.
Do not load this skill for general DOCA orientation,
doca-flow API work, DOCA install, or general gRPC tooling
(use the grpc.io docs directly for those).
What this skill provides
This is a thin loader. Substantive material lives in two companion files:
CAPABILITIES.md— whatdoca_flow_grpcexposes: the gRPC remote-control surface in front ofdoca-flow, the.proto-files-as-authoritative-contract rule (the shipped.protofiles under the tool's source on the user's install are the source of truth), the when-to-use- gRPC vs direct-library-link decision, the language- bindings story (any language standard gRPC tooling covers), the external proxy / sidecar / VPN and network-segment decision, the packet-buffering / DPA-side option per the shippedpacket_buffering/anddpa_device/subtrees, the version overlay (server rides thedoca-flowlibrary version it links against), the layered error taxonomy (server-not-started / server-binding-failed / external-layer- rejected / RPC-call-error / Flow-precond
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.0kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
crawl4ai
84.4kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Scrapling
84.4k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
