DeepSeek Harness (DSH) uses a plugin-based architecture. When maintaining a DSH instance, manually updating the core CLI or dependencies can easily cause service interruptions due to version mismatches or file locking issues. The dsh-autoupdate plugin solves this problem through a protected update pipeline, ensuring that the update process is safe and controllable.
Plugin Positioning¶
dsh-autoupdate is a built-in auto-update plugin for DeepSeek Harness. It was developed by maintainer lc23313 and is released under the MIT license. The plugin provides a manual check entry on the settings page and implements a complete update transaction protection mechanism, including health checks, automatic rollback, and a circuit-breaker-based degradation strategy.
Core Features¶
- Settings Page UI: Adds an “Check for Updates” button on the DSH settings page, with a confirmation dialog to trigger the update process.
- Protected Update Pipeline: Uses an “apply on exit” mechanism. The daemon performs installation after the DSH process exits, avoiding file locking issues in Windows environments.
- Precise Version and Validation: Locks the exact version during installation and confirms successful updates through dual validation (manifest version + binary execution validation).
- Automatic Rollback: If any failure occurs during the update process, the system automatically rolls back to the previous version.
- Circuit Breaker and Degradation: Includes a built-in circuit breaker that automatically degrades the mode from
auto -> notify -> offbased on consecutive failures. - Arbitrary Dist-Tag Support: Supports tracking any npm dist-tag (such as
latest,rc, etc.).
Installation and Enablement¶
Install through the official plugin channel:
dsh plugin --profile web add dsh-autoupdate
After installation, restart the DSH process to activate the plugin. You can verify whether the plugin has been registered using the following command:
dsh --dump-config --profile web
Typical Usage¶
After installation, the plugin initializes automatically. Status and log files are located at:
$DSH_HOME/plugins-data/dsh-autoupdate/
Common commands to view the current status and logs:
cat $DSH_HOME/plugins-data/dsh-autoupdate/state.json
cat $DSH_HOME/plugins-data/dsh-autoupdate/autoupdate.log
Security and Trust¶
The plugin is designed with security as a priority:
* Minimal Privileges: Only generates npm commands (version queries and global installation) and optional dsh plugin commands.
* Isolated Writes: Never writes to DSH-owned files (such as settings.yaml or configuration files).
* Audit Logging: All decision processes are recorded in autoupdate.log for easy auditing.
* Version Locking: The installation process always locks the exact version resolved at check time.
Dependency Requirements¶
Using this plugin requires the following environment conditions:
* Node.js >= 18
* @deepseek-ai/cordis >= 4.0.0
* @deepseek-ai/schemastery >= 1.0.0