Introduction

The architecture of DeepSeek Harness (DSH) is browser-based; the local machine serves only as a display layer. When a DSH instance needs to run on a remote server, the dsh-plugin-ssh plugin enables this — the local machine acts as a “thin client” and connects to the remote DSH instance through an SSH tunnel, consistent with the Codex Remote model.

Plugin Overview

This plugin is maintained by ArcherLyu under the MIT license. It allows you to manage remote DeepSeek Harness instances over SSH, while the local machine is only responsible for opening a browser to display the remote Web GUI. The plugin consists of two parts: a standalone dsh-ssh command-line tool and a profile bundle integrated into the dsh web profile, which adds an SSH Remotes panel to the settings.

Core Features

  • Remote Management: Manage remote DeepSeek Harness instances over SSH.
  • Thin Client Mode: The local machine serves only as a display layer and does not run heavy logic.
  • Standalone CLI: Provides the dsh-ssh command-line tool with a set of operational commands.
  • Web Panel Integration: Adds the SSH Remotes panel to the local Web GUI settings through a dsh profile bundle.
  • Core Commands: Supports configuration management (add, rm, list), connection control (connect, disconnect, open), and remote operations (setup, start, stop, logs).

Installation and Activation

Before use, ensure the local environment meets the following prerequisites:
* dsh version >= 0.1.0-rc.6 (web profile)
* the ssh command is available in PATH
* pnpm is installed

Install the plugin into the local web profile; it takes effect the next time dsh web starts:

dsh plugin --profile web add /path/to/dsh-plugin-ssh

Usage Examples

  1. Add a remote instance configuration: Specify the host, user, and workspace path.
    dsh-ssh add prod --host my-server --user deploy --workspace /srv/app
  1. Configure the remote environment: The plugin installs the required dependencies on the remote server, creates the workspace, and optionally copies local configuration files.
    dsh-ssh setup prod --copy-settings
  1. Connect and open: Establish an SSH tunnel and open the remote DSH Web interface in the browser.
    dsh-ssh connect prod
  1. View status and logs: Check the tunnel status, remote process status, and harness logs.
    dsh-ssh status prod
    dsh-ssh logs prod

In the Settings → SSH Remotes panel of the local Web GUI, you can also see all configured remote instances and directly perform Connect, Open, Disconnect, Start, Stop, or Logs operations by clicking the buttons.

How It Works

The plugin operates mainly as two parts:
1. CLI tool (dsh-ssh): Runs locally and is responsible for generating SSH tunnel commands and managing local configuration files.
2. Profile Bundle: Installed in the local web profile, providing the /ssh-remotes HTTP route and GUI panel.

The local dsh-ssh connect command executes ssh -N -L to open a tunnel, mapping the remote 127.0.0.1:<remote-port> to a local port. The remote DSH harness binds only to 127.0.0.1 and is not directly exposed to the network; all traffic must pass through the SSH tunnel established locally.

Cautions

  • Authentication mode: BatchMode=yes is enabled when the SSH tunnel runs, so interactive password entry is not supported. Key authentication or an SSH agent must be configured.
  • Port binding: The remote harness binds to 127.0.0.1 by default and can be accessed only through the SSH tunnel.
  • Security restrictions: The local /ssh-remotes route rejects non-loopback Origin headers to prevent cross-origin access.
  • LLM credentials: The remote harness reads $DSH_HOME/settings.yaml and the .env files in the working directory. If you use --copy-settings, ensure the credentials on the remote server are configured correctly.