dsh-server-deployment
Server-side deployment for DeepSeek Harness: a zero-dependency Node gateway adds a multi-user login portal, per-user independent DSH instances with OS-level isolation, per-user API keys, and a delivery file drawer. File access runs through sudo helper scripts using runuser to drop privileges to dsh-<name> (fixes issue #1 TOCTOU). Not a local/desktop tool.
Installation
No reliable install command was detected. Check the project README for installation instructions.
Overview
Server-side deployment for DeepSeek Harness: a zero-dependency Node gateway adds a multi-user login portal, per-user independent DSH instances with OS-level isolation, per-user API keys, and a delivery file drawer. File access runs through sudo helper scripts using runuser to drop privileges to dsh-<name> (fixes issue #1 TOCTOU). Not a local/desktop tool.
- Zero-dependency Node gateway for DeepSeek Harness Web: login portal, session management, rate limiting, CSRF checks, reverse proxy, and SPA injection.
- Per-user independent DSH instance on its own port, run under a separate OS account dsh-<name> with DSH_HOME pointing to a 0700 private directory.
- userctl.js command supports creating users, changing passwords, deleting users, and presetting API keys.
- Per-user API key setup via /setup after login; credentials written to the user's private .credentials.yaml (0600, owner-only).
- Delivery file drawer: draggable file management capsule, directory browsing, download with attachment and Chinese filenames, multi-file upload up to 100MB.
- File access uses sudo helper scripts; root validates parameters and uses runuser to drop to dsh-<name> for file operations (fixes issue #1 TOCTOU).
- Loopback interface fix: gateway presents Host: 127.0.0.1:<port> to backend and strips browser trust markers, so loopback-pinned privileged APIs work.
- Includes systemd unit templates, nginx TLS reverse proxy example, loopback guard, and environment variable overrides for deployment paths.