In the plug-in architecture of DeepSeek Harness, SSH connections are the foundation of remote collaboration. The native ssh provider often fails on macOS because the ControlPath is too long, and it lacks security boundaries for file operations. dsh-secure-remote is a standalone plug-in that replaces the built-in provider through a bundle patch. It does not require modifying upstream source code, nor does it require migrating existing ssh_workspace v1 data. This plug-in is maintained by startGalway and is licensed under the MIT License.
Core Features¶
-
Connection Stability Fixes
- macOS / Linux: Uses a short-path private directory to run OpenSSH
ControlMaster, resolving PTY startup failures on macOS caused byControlPath too long. - Windows: The local side uses the system
ssh.exeand explicitly disablesControlMaster, but status probing and application-layer reconnection are still available.
- macOS / Linux: Uses a short-path private directory to run OpenSSH
-
Authentication and Credential Management
- Key Mode: Automatically discovers SSH Config hosts and default keys, and supports selecting a single key file or a key folder.
- Password Mode: Only Host / Port / User / Password are displayed; the password is stored through the DSH credentials service and does not enter SSH parameters, logs, or status interfaces.
-
Workspace Status and Security
- Status Display: The Workspace row displays
connected,connecting,degraded, anddisconnectedstates, along with latency and redacted reasons. - Security Boundary: Remote file tools are strictly limited to the Workspace root directory, rejecting
.., prefix collisions, and symbolic link escapes. - Strict Validation: Keeps
StrictHostKeyChecking=yesby default and does not automatically downgrade. - Remote Restrictions: The remote target must be a POSIX system; returning
REMOTE_OS_UNSUPPORTEDwhen a non-POSIX target such as Windows is detected.
- Status Display: The Workspace row displays
-
Compatibility
- Retains the official
openRawChannelraw SSH channel for compatibility with Remote Agent installation and long-lived connections. - Maintains compatibility with
SshProfile,RemoteWorkspaceView, Workspace RPC, Session, Bash, and Terminal.
- Retains the official
Installation and Enablement¶
Installing this plug-in requires a DeepSeek Harness Web profile environment and ensures that the Node.js version is 22 or higher.
Install a specified version:
dsh plugin --profile web add github:startGalway/dsh-secure-remote#v1.1.2
Install for local development:
dsh plugin --profile web add file:/absolute/path/to/dsh-secure-remote
Restart the Web profile after installation. Uninstalling the plug-in will not migrate or delete existing remote Workspaces.
Configuration Options¶
The plug-in uses the following default configuration:
workspaceBoundary: deny
connectionReuse: true
controlPersistMs: 300000
serverAliveIntervalSec: 15
serverAliveCountMax: 3
statusProbeIntervalMs: 30000
maxTransferBytes: 8388608
Known Limitations¶
- Bash Behavior: Bash is not subject to Workspace file boundary restrictions and has the full permissions of the remote SSH account itself.
- Remote Windows: Connections to Windows remote targets are not currently supported.
- Feature Scope: The current version does not include bidirectional directory mirroring, atomic file transfer, background tasks, or remote Git workflows.
- Runtime: On Unix, a short-path compatibility launcher with
0700permissions is retained; on Windows, the systemssh.exeis called directly.
Applicable Scenarios¶
This plug-in is suitable for development scenarios that require stable SSH connections, secure credential storage, and strict file boundary control. Because the plug-in runs with DSH process privileges, it is recommended to review the source code and license before installation.