DSH (DeepSeek Harness) adopts a plugin-based architecture, allowing developers to extend functionality as needed. Deploying a Harness environment on a remote server (such as a cloud instance) usually involves cumbersome manual steps, such as configuring Node.js, extracting files, and handling credentials, and makes it difficult to guarantee environment consistency and security.
The DSH Remote Runtime plugin is designed to solve this problem. It manages an isolated, official-build Harness runtime on a remote Linux host over OpenSSH and provides a native Web control interface. All SSH connections, file operations, process execution, and key credentials remain on the plugin host; the browser only retrieves summarized information through a restricted JSON interface.
Core Features¶
This plugin primarily adds the following capabilities to the DSH Web UI:
- Remote configuration management: Add remote host configurations and manage remote workspaces.
- Runtime validation: Automatically install and validate the remote runtime environment, including Node 22.19 and official DSH rc.8. Downloads and all extracted files are verified with SHA-256.
- Security isolation: Credentials are written with
0600permissions and stored only on the host; they are never returned to browser state, logs, snapshots, or process arguments. - Access control: SSH is the sole access-control boundary.
- Traffic restrictions: Authenticated Client-Proxy outbound traffic is only allowed to access public HTTP(S); other addresses (private, local, IPv6, etc.) are denied.
- Tunneling and UI: Exposes the remote Harness UI through a local loopback tunnel without directly exposing the remote server’s Web API.
Installation and Enabling¶
Installing this plugin requires the current local DSH version to be 0.1.0-rc.8 and running the Web profile.
- Run the following command to install the plugin:
npx.cmd --yes @deepseek-ai/dsh@0.1.0-rc.8 plugin --profile web add @artificialnotimbecile/dsh-remote-runtime@latest
- After installation, restart the running Web profile.
Typical Usage¶
After installation, configure it in the DSH Web UI:
- Open Settings -> Remote runtime.
- Add an OpenSSH host and optionally specify a remote workspace path.
- Select the outbound mode:
- Remote-direct: Remote direct mode.
- Client-proxy: Client proxy mode (authentication required).
- Run the read-only Doctor check; after confirming the environment meets the requirements, explicitly install the validated runtime.
- Import the DeepSeek API key through the “write-only” form.
- Start the runtime; the system automatically opens the local loopback tunnel URL.
- Browse workspaces, view session history, send or cancel prompts in the browser.
Disconnecting does not terminate the remote Harness runtime; stopping is a separate operation. Removing the local configuration does not delete the remote runtime or session data.
Use Cases and Notes¶
- Environment requirements:
- Local client: Windows, macOS, or Linux; Node.js version must be
^22.19.0or>=24;sshmust be installed. - Remote host: Linux x64, glibc 2.28+, Bash, tar, gzip, sha256sum installed, and a writable home directory.
- Local client: Windows, macOS, or Linux; Node.js version must be
- Software status: DeepSeek Harness is pre-release software. Subsequent DSH versions will not be supported until certain features (such as Typert generation and CI for assembly configuration files) are fully aligned.
- Permissions and security: The plugin host runs with DSH process permissions. When sharing a remote host account, it is recommended to use a dedicated remote OS user for stricter process isolation.
This plugin is maintained by the community, uses the MIT license, and has no official affiliation or endorsement from DeepSeek.