Introduction

DeepSeek Harness (DSH) uses a plugin-based architecture. In multi-model deployment scenarios, developers often face fragmented model routing strategies, a lack of unified quota management, the inability to recover automatically after request failures, and difficulty auditing usage. dsh-llm-governor is a plugin designed for DSH. It adds model profiling, user access control, monthly credits, multiple routing strategies, failure rerouting, and usage auditing to DSH’s existing model invocation chain.

This plugin does not proxy model requests or manage provider credentials. Instead, it acts as a decision and orchestration layer, working alongside DSH’s native components.

Core Features

dsh-llm-governor provides the following governance capabilities:

  • Multi-model governance and profiling: Supports model performance profiling for downstream decisions.
  • User access control: Uses a policy table keyed by external user_id to control model distribution.
  • Monthly credits: Manages users’ monthly quotas and supports blocking over-limit requests.
  • Routing strategies: Supports Manual, Quality First, Credit First, and Auto modes.
  • Failure rerouting: Automatically attempts to switch to another available model or provider when a model call fails.
  • Usage auditing: Records usage for every decision and invocation.

Installation and Enabling

Before installing, ensure Node.js ^22.19.0 || >=24.0.0 and pnpm are installed, and DSH version is 0.1.0-rc.8 or later (verified as of 2026-08-21).

  1. Clone the repository and build the plugin.
    git clone https://github.com/young-tim/dsh-llm-governor
    cd dsh-llm-governor
    pnpm install
    pnpm build
    pnpm pack --pack-destination <临时目录>
  1. Add the generated .tgz file to a DSH profile.
    dsh plugin --profile <profile> add <临时目录>/dsh-llm-governor-<version>.tgz
  1. Restart the DSH service to load the plugin.

Usage and Configuration

Routing Strategies and Model Selection

Model selection goes directly into the DSH Composer (Auto mode is supported), while governance settings go into DSH native Settings. Decision records are displayed in the Governor Trajectory view for the same session.

Initial Quality Configuration

Auto, Quality First, and Credit First modes rely on Quality scores for models. After the initial installation, go to the Settings → Governor → Models page. For each model, select a quick tier to initialize it:
* Lite 75: Cost-saving tier.
* Balanced 85: Flash / standard tier.
* Pro 95: High-quality tier.

These quick tiers copy the same initial score to seven task types. You can later use “Advanced tuning” to adjust specific scores for different tasks.

Architecture and Responsibility Boundaries

Invocation Chain

The position of Governor in the DSH invocation chain is as follows:

Governor (选路/额度/审计) → DSH ctx.llm → DSH Provider Adapter → DSH Credentials Service → Provider

Responsibility Boundaries

  • Does not proxy requests: Governor does not take over HTTP proxying or WebSocket traffic; it only provides decision logic.
  • Does not manage credentials: Provider credentials are managed by the DSH Credentials Service. Governor does not read, store, or require DEEPSEEK_API_KEY (only when a specific route selects deepseek-official and no stored credential is available, the DSH adapter uses the environment variable).
  • Does not provide a login system: Governor does not provide registration, login, MFA, SCIM, or IdP lifecycle management.

Identity and User Management

The Users section in Governor is not an account directory; it is a governance policy table keyed by external user_id. It stores model allow lists, monthly credits, and usage summaries.

Identity Provider

Governor supports four identity binding modes: local, header, jwt, and custom:
* local: Treats the entire instance as a fixed user; suitable for personal or single-administrator deployments.
* header / jwt: Suitable for enterprise environments and should be used with a DSH identity bridge or trusted proxy.
* custom: An extension point that allows third-party host plugins to implement custom identity verification logic.

User Policies

Maintaining user policies in Settings does not create an account that can log in to DSH. Enterprise deployments typically need to preconfigure and deactivate users through an IdP, SCIM synchronization, or an administrative plugin.

Dependencies and Compatibility

  • DSH version: Requires compatibility with DSH 0.1.0-rc.8 (as of 2026-08-21).
  • Runtime environment: TypeScript ESM, Node.js ^22.19.0 || >=24.0.0, pnpm 11.

Conclusion

dsh-llm-governor provides a complete governance loop for DeepSeek Harness, covering model routing, quota control, and auditing. It integrates as a plugin without intruding on DSH’s core request processing flow, making it suitable for deployments that require fine-grained management and multi-tenant scenarios.