DeepSeek Harness’s official dsh web listens only on localhost 127.0.0.1 by default and cannot be directly exposed to the public internet. If you have already deployed Harness on a cloud server, you need a reverse proxy and a login layer to access it from the external network. dsh-cloud-gateway is specifically designed for this scenario.

What This Is

This is a login wall and public gateway plugin for cloud deployments of DeepSeek Harness. It listens on port 8080 by default and uses /dsh as the access path, avoiding conflict with the official Web port 3080. The release package does not contain real accounts, passwords, or public IPs; credentials are stored locally only.

Core Features

  • Login Wall and Reverse Proxy: Provides a login wall with account and password; after login, it reverse-proxies to the local DeepSeek Harness.
  • Port and Path: Listens on port 8080 by default, with the access path /dsh.
  • File References: Supports saving non-image files (PDF, Markdown) and generating @filename references.
  • Configuration Flexibility: Supports configuring accounts, passwords, ports, and whether to trust the reverse proxy in settings.
  • Ecosystem Compatibility: Can work with the community plugin dsh-web-mobile.

Installation and Enablement

Before installing, make sure DeepSeek Harness is installed.

dsh plugin --profile web add github:MrLukezy/dsh-cloud-gateway

The startup command must include the --trusted-host parameter; otherwise, the APIs after login will be blocked by the official guardrails.

dsh web --trusted-host YOUR_PUBLIC_IP --trusted-host your.example.com

Typical Usage

After installation and startup, visit the following URL in your browser:

http://YOUR_PUBLIC_IP:8080/dsh

Configure Account and Trust Reverse Proxy:
1. Before the first login, check the dsh web logs for temporary credentials in generated login.
2. After logging in, go to Settings → Gateway, click Gateway Settings, and modify the account and password.
3. If there is a reverse proxy such as Nginx in front, enable “Trust Reverse Proxy” in the gateway settings and reverse-proxy paths such as /dsh, /assets/, /plugins/, /api, /dsh-image-gen, and /query-balance.

Applicable Scenarios and Notes

Applicable Scenarios: Harness is already deployed on a cloud server, and you need to access the workbench from the external network through a browser.

Notes:
* Mobile Experience: This plugin does not change the official desktop layout; the portrait experience on mobile is poor. It is recommended to use it with the dsh-web-mobile plugin.
* Startup Parameter: The startup command must include --trusted-host.
* Credential Security: The release package does not contain real account passwords; credentials are stored locally.
* License: MIT License.

Summary

dsh-cloud-gateway provides a lightweight public access solution for cloud deployments of DeepSeek Harness. Through its login wall and reverse proxy features, it solves the pain point that local listening cannot be accessed from the external network.

GitHub | SkillHub Directory