Preface¶
DeepSeek Harness (DSH) is bound to the local loopback address by default, which limits the ability to access it from a local area network (LAN) or remote services. The DSH Network plugin sits in front of DSH and provides an authentication gateway, supporting connections via LAN, Tailnet, or custom HTTPS endpoints. This plugin allows pairing once and binding multiple routes.
Installation and Activation¶
Use the official commands to install and start the DSH Web service:
dsh plugin --profile web add dsh-network@latest
dsh web
Core Capabilities¶
This plugin provides the following capabilities:
* Multi-route support: Supports LAN, Tailnet, and custom HTTPS connections.
* Connection management: Pair once and bind multiple routes.
* Authentication gateway: Provides an authentication gateway with short-lived pairing tickets, rotated device credentials, and persistent host IDs.
* UI component: Optional iOS app download card.
Configuration and Usage¶
After installation, you can view the host status or create a pairing QR code in the Network panel on the settings page. You can also use the setup assistant in the terminal:
dsh plugin --profile web exec dsh-network setup
Configuration Parameters¶
The default gateway listening port is 3081. The underlying DSH Web server remains bound to the loopback address. Key configuration items include:
gatewayPort: Authentication gateway port (default3081).bindHost: Gateway listening address (default0.0.0.0; use127.0.0.1to restrict to loopback only).hostName: Host display name.statePath: Path for storing pairing and device state.iosAppDownloadURL: HTTPS URL displayed on the iOS app download card.
Route Setup¶
Choose a connection method based on your needs:
- LAN Setup: Ensure network connectivity between devices, then run:
dsh plugin --profile web exec dsh-network setup lan
- Tailnet Setup: The host must have Tailscale installed and signed in, then run:
dsh plugin --profile web exec dsh-network setup tailscale
- Custom HTTPS: A reverse proxy must already be configured, then run:
dsh plugin --profile web exec dsh-network setup custom --url https://dsh.example.com
Notes¶
- Runtime behavior: DSH remains on loopback, while the plugin provides an authentication gateway in front of it.
- Network dependencies:
- LAN HTTP depends on a trusted local network.
- Custom public routes must already provide trusted HTTPS and HTTP/WebSocket forwarding; this plugin does not configure DNS, certificates, firewalls, or reverse proxies.
- Pairing security: Pairing tickets are one-time and expire after 5 minutes. The host stores credential hashes, not raw credentials.
- Panel functionality: The current settings panel only displays host status, paired device count, and pairing actions. A complete device list and revocation controls are future work.
This plugin extends DSH’s network reachability. See the catalog and source code for more details.