Introduction

The Web interface of DeepSeek Harness (DSH) usually runs locally, and direct mobile access is often limited by network conditions or domain resolution. The dsh-mobile-access plugin establishes an SSH reverse tunnel to map the Web interface to a user’s own domain, enabling a phone to securely access the local Agent over HTTPS.

What is dsh-mobile-access

This is a DSH plugin package designed to solve the issue of accessing a local Web interface from mobile devices. It delivers the DeepSeek Harness Web GUI to a phone through a custom domain, a local token gateway, and a supervised SSH reverse tunnel.

  • Maintainer: kk99668
  • Category: Client
  • License: MIT

Core Features

The plugin provides the following capabilities:

  1. Custom domain access: Access the Web interface on a phone through a user-specified domain.
  2. Local token gateway: Implements request authentication in front of the Web server as the sole security boundary.
  3. Supervised SSH reverse tunnel: Supports automatic reconnection and an exponential backoff strategy to maintain connection stability.
  4. Weak network optimization: Supports message compression and includes a connection controller to handle signal fluctuations.
  5. Mobile context integration: Injects the DSH_WEB_PUBLIC_URL environment variable in surfaceContext mode.
  6. Terminal QR code: Generates a QR code after the tunnel is established for convenient phone scanning and configuration.

Installation and Enabling

The plugin is an optional component and must be enabled on an installed web profile.

dsh plugin --profile web add github:kk99668/dsh-mobile-access

Configuration and Deployment

After enabling it, configure environment variables in the environment where DSH starts, or override the default configuration.

Environment Variable Configuration

The plugin reads environment variables for initialization. The following variables are required:

  • DSH_MOBILE_PUBLIC_HOST: Public access address (e.g., dsh.example.com).
  • DSH_MOBILE_RELAY_HOST: Relay server address.
  • DSH_MOBILE_RELAY_USER: SSH login user on the relay server.
  • DSH_MOBILE_TOKEN: Token gateway secret (at least 8 characters).

Configuration Override

If you need to modify parameters such as default ports or SSH keys, you can override the configuration in cordis.patch.yml:

- id: mobile-access
  config:
    publicHost: dsh.example.com
    relayHost: vps.example.com
    relayUser: dsh-relay
    token: a-long-random-secret
    remoteBindPort: 8443
    identityFile: C:\Users\you\.ssh\id_ed25519

Server-Side Deployment

Run the script once on the Relay Server to install Caddy and configure the reverse proxy:

sudo ./scripts/setup-server.sh dsh.example.com 3080 ~/dsh-relay.pub

This script configures Caddy to handle HTTPS, creates a dedicated SSH user, and sets firewall rules.

Notes

During deployment and use, pay attention to the following facts:

  1. SSH client dependency: An ssh client program must be present on the machine running DSH.
  2. Device login: Each device requires a separate browser login; there is no persistent device registry.
  3. Windows auto-start: Auto-start on Windows is handled by the user; the plugin process is not automatically added to startup items.
  4. Security boundary: The token gateway is the sole security boundary. Anyone who knows the token can control this Agent, so treat it as a credential and store it securely.
  5. Cookie mechanism: The login Cookie does not include Max-Age, which means each browser profile must log in again.
  6. Port binding: The SSH tunnel binds only to 127.0.0.1 on the Relay Server. A phone cannot connect directly to this port and must go through Caddy.

Conclusion

dsh-mobile-access provides a reliable bridge solution from a local environment to mobile devices. By combining an SSH tunnel with a token gateway, it enables secure remote access to the Web interface without changing the core DSH architecture. It is suitable for developers who need to use DSH stably over mobile networks.