DeepSeek Harness (DSH) binds its Web server to the loopback address by default and refuses to listen on 0.0.0.0 to avoid network exposure. This limits the ability to access the Harness Web UI from phones or external networks. The deepseek-harness-relay plugin runs as a second-layer listener, terminating TLS for the untriggered Harness frontend and handling authentication.

Plugin Overview

  • Name: sorsama/deepseek-harness-relay
  • Owner: sorsama
  • Category: admin-security
  • License: MIT

This plugin provides authenticated remote access for the DSH Web profile. It sits outside Harness, allowing access to Harness over TLS connections and handling device pairing, password login, and device revocation, without modifying Harness core configuration or opening raw ports.

Core Features

  • TLS termination: Terminates TLS before forwarding traffic to the Harness frontend.
  • Device pairing: Supports QR code and password pairing methods, generating revocable Bearer Tokens.
  • Password login: Uses scrypt hashing and per-address lockout mechanisms for password login.
  • Device management: Provides a device list, supports per-device revocation and a “sign out all devices” feature.
  • Network discovery: Broadcasts discovery via _dsh._tcp mDNS advertisements so clients can easily discover the Relay service.
  • Transparent proxy: Transparently proxies the Web UI without modifying Harness frontend code.

Installation and Enablement

  1. Check the existing configuration: If Harness is currently already bound to 0.0.0.0 (for example, through the DSH Mobile LAN patch), first edit ~/.dsh/profiles/web/cordis.patch.yml and remove that line. The Relay plugin refuses to start when Harness is already bound to 0.0.0.0.
  2. Install the plugin:
    dsh plugin --profile web add dsh-relay
  1. Start Harness:
    dsh web
  1. Set the password: On the machine running Harness, open https://127.0.0.1:3443/relay/password and set the password. This page is accessible only via loopback until the password is set.

Typical Usage

Device Pairing

  1. On the Harness machine, open https://127.0.0.1:3443/relay/pair.
  2. Scan the QR code with your phone, or open the same URL on your phone and enter the displayed code.
  3. After naming the device, it will appear in the /relay/devices list.

Using DSH Mobile

DSH Mobile 0.8.0 implements the full client integration protocol. In the DSH Mobile interface, select Relay → Pair a relay to complete pairing.

Notes

  • Unofficial project: This plugin is built on DeepSeek Harness and is not an official DeepSeek project.
  • Startup restriction: If the Harness server is already bound to 0.0.0.0, the Relay plugin refuses to start.
  • Local access: Requests from the loopback address of the Harness machine are treated as operator requests and do not require login.
  • Token mechanism: Bearer Tokens are single-use and have a short validity period.
  • Authentication mechanism: Source-address validation is not a true authentication method and is primarily used for legacy client compatibility.
  • Client version: DSH Mobile versions earlier than 0.8.0 cannot directly access self-signed listeners and cannot attach credentials to requests.

Summary

deepseek-harness-relay adds a layer of TLS and authentication middleware outside Harness, addressing the need to access the Harness Web UI remotely from mobile devices or over the network while preserving Harness’s security policy (refusing 0.0.0.0). It follows conventions in the DSH plugin ecosystem and provides intuitive device management and revocation mechanisms.