Introduction

The plugin ecosystem of DeepSeek Harness (DSH) allows developers to package and extend functionality. When running the DSH Web interface locally, the default listening address is only 127.0.0.1:3080, so it cannot be accessed directly from the external network. The dsh-cftunnel plugin runs a Cloudflare Tunnel to expose the local Web GUI to the public internet, and automatically handles downloading and managing cloudflared, eliminating the need for manual local network penetration configuration.

Plugin Scope

dsh-cftunnel is a DeepSeek Harness bundle plugin maintained by user weicy98. It primarily solves the problem of the local DSH interface not being accessible from the public internet by leveraging Cloudflare’s tunnel technology for local network tunneling.

Core Features

The plugin provides the following core capabilities:
* Runs a Cloudflare Tunnel
* Automatically downloads and manages cloudflared
* Supports Quick tunnel / Tunnel token / API token modes
* Exposes the local GUI through a Loopback reverse proxy
* Provides token verification and Cloudflare Access email OTP access control

Installation and Activation

To install the plugin, use the installation command provided by the official source:

dsh plugin --profile web add git+https://github.com/weicy98/dsh-cftunnel

After installation, restart dsh web and open Settings -> Cloudflare Tunnel in the interface.

Typical Usage

  1. In Settings, choose a mode (Quick tunnel / Tunnel token / API token).
  2. Enter the corresponding Cloudflare information (such as an API Token or Tunnel Token).
  3. Click the Connect button.
  4. The plugin automatically downloads and runs cloudflared. After the connection succeeds, copy the generated access URL to share it with others.

Modes and Security

The plugin provides three modes to fit different scenarios:

  • Quick tunnel: No account information is required; a random public URL is generated directly.
  • Tunnel token: Uses an existing Cloudflare Zero Trust tunnel.
  • API token: Uses the API to create the tunnel and DNS, with optional email OTP verification configured.

All traffic is forwarded through a Loopback reverse proxy (127.0.0.1:<proxyPort>), and access control is enforced on the frontend. Token verification is enabled by default (proxyAuth: 'token'), and Cloudflare Access email OTP verification can be enabled optionally.

Notes

  • First connection: On the first Connect, the plugin downloads the cloudflared binary file of about 40MB. On slow networks, it may take a few minutes.
  • Source updates: After editing the source code, use the remove + add (or version upgrade) command to refresh the plugin. pnpm treats the source code as immutable.
  • Access control: Setting proxyAuth: 'none' disables the token verification gate and relies only on Cloudflare Access email OTP or places no restrictions.
  • Required permissions: API token mode requires specific API permissions to create tunnels and DNS.

Summary

dsh-cftunnel provides a simple path to expose locally running DSH Harness to the public internet. With integrated Cloudflare Tunnel and automated configuration, developers can quickly obtain a secure access endpoint.

  • Directory: https://www.skillhub.cn/plugins/weicy98/dsh-cftunnel
  • Source code: https://github.com/weicy98/dsh-cftunnel