Introduction

The Web interface of DeepSeek Harness (DSH) is bound to the local loopback address by default. In self-hosted or Homelab scenarios, developers typically need to access the service from other devices on the Local Area Network. However, the official CLI does not support directly specifying --host 0.0.0.0, which means that exposing the service on non-loopback addresses carries security risks. dsh-lan-gate uses plugin-level configuration to allow listening on all interfaces and enforces password protection and CIDR whitelisting, addressing this pain point.

Plugin Overview

dsh-lan-gate is a DeepSeek Harness (DSH) plugin categorized as admin-security. It is maintained by the user maxesisnclaw. Its core feature is to provide password protection for the DSH Web interface and /api endpoints, combined with a CIDR whitelist mechanism to ensure that only specific internal network segments can access the service.

Core Features

  1. Listening on all interfaces: Through a bundle patch, the webserver.host configuration value is set to 0.0.0.0, so the service listens on all network interfaces.
  2. Password protection: No password is set by default; a password must first be set via the loopback address. Only after successful verification are the UI and API visible to non-loopback clients.
  3. CIDR whitelist: By default, the following private IPv4 network ranges are allowed: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. Requests outside this range are denied.
  4. Proxy header rejection: The plugin intercepts and denies requests containing X-Forwarded-*, Forwarded, or Via headers.
  5. Loopback bypass: To facilitate debugging and recovery, access from the local loopback address is allowed without a password.
  6. Secure storage: Passwords are stored using scrypt verifiers, session tokens are random 32-byte values, and only SHA-256 hashes are retained in memory.
  7. Configuration file: The policy file is located at $DSH_HOME/lan-gate.json, with file permissions set to 0600 by default.

Installation and Enablement

Install from the official DSH plugin source:

dsh plugin --profile web add dsh-lan-gate

After installation, the plugin automatically applies the configuration patch and starts.

Configuration and Usage

  1. Initialize the password: First, access the local initialization page to set the password. The address is http://127.0.0.1:3080/dsh-lan-full/login. This step can only be completed via the loopback address.
  2. LAN access: After configuration, clients on the LAN attempting to access the DSH Web interface are automatically redirected to the login page.
  3. Policy management: In the DSH settings interface, go to the LAN Access option to edit the CIDR whitelist, the proxy header rejection policy, and to change the password.

Notes and Applicable Scenarios

This plugin runs with the permissions of the current DSH process. Before installation, it is recommended to review the source code and license (MIT).

  • Non-TLS Terminator: The plugin does not provide TLS encryption; under plain HTTP, observers on the LAN may still sniff passwords and cookies. Do not deploy it on the public Internet.
  • Reverse Proxy Limitation: Do not place this plugin behind a reverse proxy that adds forwarding headers (Forwarding Headers); by design, the plugin rejects such requests.

Summary

dsh-lan-gate provides the basic capability to securely expose the DSH Web service in Homelab environments. For more details, refer to the GitHub repository or the DSH community directory.