Introduction¶
The Web interface of DeepSeek Harness (DSH) usually runs locally, and direct mobile access is often limited by network conditions or domain resolution. The dsh-mobile-access plugin establishes an SSH reverse tunnel to map the Web interface to a user’s own domain, enabling a phone to securely access the local Agent over HTTPS.
What is dsh-mobile-access¶
This is a DSH plugin package designed to solve the issue of accessing a local Web interface from mobile devices. It delivers the DeepSeek Harness Web GUI to a phone through a custom domain, a local token gateway, and a supervised SSH reverse tunnel.
- Maintainer: kk99668
- Category: Client
- License: MIT
Core Features¶
The plugin provides the following capabilities:
- Custom domain access: Access the Web interface on a phone through a user-specified domain.
- Local token gateway: Implements request authentication in front of the Web server as the sole security boundary.
- Supervised SSH reverse tunnel: Supports automatic reconnection and an exponential backoff strategy to maintain connection stability.
- Weak network optimization: Supports message compression and includes a connection controller to handle signal fluctuations.
- Mobile context integration: Injects the
DSH_WEB_PUBLIC_URLenvironment variable insurfaceContextmode. - Terminal QR code: Generates a QR code after the tunnel is established for convenient phone scanning and configuration.
Installation and Enabling¶
The plugin is an optional component and must be enabled on an installed web profile.
dsh plugin --profile web add github:kk99668/dsh-mobile-access
Configuration and Deployment¶
After enabling it, configure environment variables in the environment where DSH starts, or override the default configuration.
Environment Variable Configuration¶
The plugin reads environment variables for initialization. The following variables are required:
DSH_MOBILE_PUBLIC_HOST: Public access address (e.g.,dsh.example.com).DSH_MOBILE_RELAY_HOST: Relay server address.DSH_MOBILE_RELAY_USER: SSH login user on the relay server.DSH_MOBILE_TOKEN: Token gateway secret (at least 8 characters).
Configuration Override¶
If you need to modify parameters such as default ports or SSH keys, you can override the configuration in cordis.patch.yml:
- id: mobile-access
config:
publicHost: dsh.example.com
relayHost: vps.example.com
relayUser: dsh-relay
token: a-long-random-secret
remoteBindPort: 8443
identityFile: C:\Users\you\.ssh\id_ed25519
Server-Side Deployment¶
Run the script once on the Relay Server to install Caddy and configure the reverse proxy:
sudo ./scripts/setup-server.sh dsh.example.com 3080 ~/dsh-relay.pub
This script configures Caddy to handle HTTPS, creates a dedicated SSH user, and sets firewall rules.
Notes¶
During deployment and use, pay attention to the following facts:
- SSH client dependency: An
sshclient program must be present on the machine running DSH. - Device login: Each device requires a separate browser login; there is no persistent device registry.
- Windows auto-start: Auto-start on Windows is handled by the user; the plugin process is not automatically added to startup items.
- Security boundary: The token gateway is the sole security boundary. Anyone who knows the token can control this Agent, so treat it as a credential and store it securely.
- Cookie mechanism: The login Cookie does not include
Max-Age, which means each browser profile must log in again. - Port binding: The SSH tunnel binds only to
127.0.0.1on the Relay Server. A phone cannot connect directly to this port and must go through Caddy.
Conclusion¶
dsh-mobile-access provides a reliable bridge solution from a local environment to mobile devices. By combining an SSH tunnel with a token gateway, it enables secure remote access to the Web interface without changing the core DSH architecture. It is suitable for developers who need to use DSH stably over mobile networks.