Introduction¶
The default Web runtime of DeepSeek Harness (DSH) is typically bound to the local loopback address, limiting the ability of other devices on the LAN to access the Web GUI. Meanwhile, during development or operations, handling official DeepSeek interfaces directly from the command line or scripts (such as querying balance) requires exposing the API Key, posing security risks. dsh-lan, as a bundle plugin, solves these two problems: it binds the Web GUI to a LAN address and provides a balance-query RPC interface that does not leave the local PC.
What Is This¶
dsh-lan is a DeepSeek Harness (DSH) plugin maintained by developer SparkWeiyang. It belongs to the networking tools category, with an MIT license. The core value of this plugin lies in extending Web GUI access to the LAN and providing official balance-query services using credentials already configured on the local PC, ensuring that the API Key never leaves the local environment.
Core Features¶
- Open the Web GUI to the LAN: Changes the Web server binding address to
0.0.0.0, and automatically enumerates IPv4 addresses as a trust fence whitelist, without requiring additional startup parameters or patches. - Balance Query RPC: Provides the
deepseek/balanceRPC interface, using theDEEPSEEK_API_KEYconfigured on the local PC to send requests to the official API.
Installation and Enablement¶
Run the following command to install the plugin into the web profile:
dsh plugin --profile web add dsh-lan
After installation, edit $DSH_HOME/profiles/web/package.json, ensuring dsh-lan is after @deepseek-ai/dsh-web-app, and add it to the bundles list:
{
"dsh": {
"profile": {
"bundles": [
"@deepseek-ai/dsh-base",
"@deepseek-ai/dsh-web-app",
"dsh-lan"
]
}
}
}
Typical Usage¶
After installation and configuration, start the Web service:
dsh web # 默认绑定 0.0.0.0:3080
dsh web --port 8080 # 指定端口
After startup, web-runtime outputs the LAN access address (e.g., http://192.168.x.x:3080).
Invoke balance query via RPC. The client sends a standard RPC envelope:
{
"type": "client-request",
"rpcId": "uuid",
"method": "deepseek/balance",
"payload": { "args": {} }
}
Sample successful response:
{
"is_available": true,
"balance_infos": [
{ "currency": "CNY", "total_balance": "8.27", "granted_balance": "0.00", "topped_up_balance": "8.27" }
]
}
If DEEPSEEK_API_KEY is not configured on the local PC, the RPC will return an internal error.
How It Works¶
The plugin implements its features through two files:
cordis.patch.yml: This is a bundle patch file. It overrides thewebserverconfiguration, setshostto0.0.0.0(the port is adjustable via the--portoption), and insertsdeepseek-serviceservice loading logic.lib/index.js: This implements aTypertRemoteServicesubclass. It registers thedeepseek/balanceendpoint using@Remote('balance'). When handling requests, it obtains local PC credentials throughctx.credentials.resolve('DEEPSEEK_API_KEY')and calls the official interface to query the balance.
Notes¶
- Security boundary: The DSH Web carrier does not have a built-in authentication layer. The “trust fence” here refers only to network reachability policies. Once bound to
0.0.0.0, any device on the same network segment can access the Web GUI and drive sessions to execute commands. - Credential dependency: The balance-query feature depends on the
DEEPSEEK_API_KEYalready configured on the local PC. The key logically remains on the PC, but this assumes that the PC side has credentials correctly configured. - Deployment recommendation: Expose this service only in trusted network environments, or deploy a reverse proxy in front of it with authentication enabled to prevent unauthorized access.
Conclusion¶
dsh-lan achieves DSH availability within the LAN through simple configuration and provides a secure balance-query method by using local PC credentials. It aligns with DSH’s “everything is a plugin” philosophy and is suitable for development scenarios that require collaboration over a local network or scripted automated balance queries.
- Plugin directory: https://www.skillhub.cn/plugins/SparkWeiyang/dsh-lan
- Repository: https://github.com/SparkWeiyang/dsh-lan