In the plug-in architecture of DeepSeek Harness, SSH connections are the foundation of remote collaboration. The native ssh provider often fails on macOS because the ControlPath is too long, and it lacks security boundaries for file operations. dsh-secure-remote is a standalone plug-in that replaces the built-in provider through a bundle patch. It does not require modifying upstream source code, nor does it require migrating existing ssh_workspace v1 data. This plug-in is maintained by startGalway and is licensed under the MIT License.

Core Features

  • Connection Stability Fixes

    • macOS / Linux: Uses a short-path private directory to run OpenSSH ControlMaster, resolving PTY startup failures on macOS caused by ControlPath too long.
    • Windows: The local side uses the system ssh.exe and explicitly disables ControlMaster, but status probing and application-layer reconnection are still available.
  • Authentication and Credential Management

    • Key Mode: Automatically discovers SSH Config hosts and default keys, and supports selecting a single key file or a key folder.
    • Password Mode: Only Host / Port / User / Password are displayed; the password is stored through the DSH credentials service and does not enter SSH parameters, logs, or status interfaces.
  • Workspace Status and Security

    • Status Display: The Workspace row displays connected, connecting, degraded, and disconnected states, along with latency and redacted reasons.
    • Security Boundary: Remote file tools are strictly limited to the Workspace root directory, rejecting .., prefix collisions, and symbolic link escapes.
    • Strict Validation: Keeps StrictHostKeyChecking=yes by default and does not automatically downgrade.
    • Remote Restrictions: The remote target must be a POSIX system; returning REMOTE_OS_UNSUPPORTED when a non-POSIX target such as Windows is detected.
  • Compatibility

    • Retains the official openRawChannel raw SSH channel for compatibility with Remote Agent installation and long-lived connections.
    • Maintains compatibility with SshProfile, RemoteWorkspaceView, Workspace RPC, Session, Bash, and Terminal.

Installation and Enablement

Installing this plug-in requires a DeepSeek Harness Web profile environment and ensures that the Node.js version is 22 or higher.

Install a specified version:

dsh plugin --profile web add github:startGalway/dsh-secure-remote#v1.1.2

Install for local development:

dsh plugin --profile web add file:/absolute/path/to/dsh-secure-remote

Restart the Web profile after installation. Uninstalling the plug-in will not migrate or delete existing remote Workspaces.

Configuration Options

The plug-in uses the following default configuration:

workspaceBoundary: deny
connectionReuse: true
controlPersistMs: 300000
serverAliveIntervalSec: 15
serverAliveCountMax: 3
statusProbeIntervalMs: 30000
maxTransferBytes: 8388608

Known Limitations

  • Bash Behavior: Bash is not subject to Workspace file boundary restrictions and has the full permissions of the remote SSH account itself.
  • Remote Windows: Connections to Windows remote targets are not currently supported.
  • Feature Scope: The current version does not include bidirectional directory mirroring, atomic file transfer, background tasks, or remote Git workflows.
  • Runtime: On Unix, a short-path compatibility launcher with 0700 permissions is retained; on Windows, the system ssh.exe is called directly.

Applicable Scenarios

This plug-in is suitable for development scenarios that require stable SSH connections, secure credential storage, and strict file boundary control. Because the plug-in runs with DSH process privileges, it is recommended to review the source code and license before installation.