Sandbox & Runtimedsh-plugin

dsh-server-deployment

Server-side deployment for DeepSeek Harness: a zero-dependency Node gateway adds a multi-user login portal, per-user independent DSH instances with OS-level isolation, per-user API keys, and a delivery file drawer. File access runs through sudo helper scripts using runuser to drop privileges to dsh-<name> (fixes issue #1 TOCTOU). Not a local/desktop tool.

Stars
8
Forks
1
Open issues
0
Last push
Aug 18, 2026
Latest release
—
24h Growth
+0
7d Growth
+0

Installation

No reliable install command was detected. Check the project README for installation instructions.

Overview

Server-side deployment for DeepSeek Harness: a zero-dependency Node gateway adds a multi-user login portal, per-user independent DSH instances with OS-level isolation, per-user API keys, and a delivery file drawer. File access runs through sudo helper scripts using runuser to drop privileges to dsh-<name> (fixes issue #1 TOCTOU). Not a local/desktop tool.

  • Zero-dependency Node gateway for DeepSeek Harness Web: login portal, session management, rate limiting, CSRF checks, reverse proxy, and SPA injection.
  • Per-user independent DSH instance on its own port, run under a separate OS account dsh-<name> with DSH_HOME pointing to a 0700 private directory.
  • userctl.js command supports creating users, changing passwords, deleting users, and presetting API keys.
  • Per-user API key setup via /setup after login; credentials written to the user's private .credentials.yaml (0600, owner-only).
  • Delivery file drawer: draggable file management capsule, directory browsing, download with attachment and Chinese filenames, multi-file upload up to 100MB.
  • File access uses sudo helper scripts; root validates parameters and uses runuser to drop to dsh-<name> for file operations (fixes issue #1 TOCTOU).
  • Loopback interface fix: gateway presents Host: 127.0.0.1:<port> to backend and strips browser trust markers, so loopback-pinned privileged APIs work.
  • Includes systemd unit templates, nginx TLS reverse proxy example, loopback guard, and environment variable overrides for deployment paths.

Related plugins

dsh-approve-for-me

Unofficial DeepSeek Harness plugin for rule-gated automatic approval of Shell and PowerShell sandbox escalations. It applies fixed high-risk checks and literal command-prefix rules, optionally uses a tool-free LLM reviewer, grants only one allowed-once per decision, and returns uncertain requests to native human approval.

Sandbox & Runtimedsh-plugin
151TypeScriptSep 12, 2026
QAQ

QAQ is a launch resilience guard for DeepSeek Harness (DSH) by WTStarMark. It supervises the `dsh web` process, reads the browser's real DOM through headless Chrome + CDP, detects host crashes, Web UI red screens and plugin degradation, then restores the configuration snapshot from the last successful boot and restarts, preserving the broken config for manual recovery. It is described as non-invasive, shipped as a one-command script with structured logs, and includes a plugin hot-update guard (c

Sandbox & Runtimedsh-plugin
41TypeScriptAug 17, 2026
DSHBox

DSHBox is an Android application that lets users run the complete DeepSeek Harness locally on Android 10+ ARM64 devices by bundling Debian, Node.js, DSH, PRoot, and an embedded WebView into one APK without root or Termux.

Sandbox & Runtimedsh-plugin
30KotlinSep 9, 2026
dsh-container

Docker packaging of the npm-released DeepSeek Harness (DSH), published for linux/amd64 and linux/arm64. It preinstalls DSH and its runtime dependencies so the host needs no Node.js or npm packages, supports LAN WebUI access, offers an optional shared admin key, runs as a non-root user with recommended read-only root filesystem and dropped Linux capabilities, and keeps configuration and workspace data persistent. The README warns against exposing the service directly to the public internet.

Sandbox & Runtimedsh-plugin
10JavaScriptAug 20, 2026