Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture. In multi-model deployment scenarios, developers often face fragmented model routing strategies, a lack of unified quota management, the inability to recover automatically after request failures, and difficulty auditing usage. dsh-llm-governor is a plugin designed for DSH. It adds model profiling, user access control, monthly credits, multiple routing strategies, failure rerouting, and usage auditing to DSH’s existing model invocation chain.
This plugin does not proxy model requests or manage provider credentials. Instead, it acts as a decision and orchestration layer, working alongside DSH’s native components.
Core Features¶
dsh-llm-governor provides the following governance capabilities:
- Multi-model governance and profiling: Supports model performance profiling for downstream decisions.
- User access control: Uses a policy table keyed by external
user_idto control model distribution. - Monthly credits: Manages users’ monthly quotas and supports blocking over-limit requests.
- Routing strategies: Supports Manual, Quality First, Credit First, and Auto modes.
- Failure rerouting: Automatically attempts to switch to another available model or provider when a model call fails.
- Usage auditing: Records usage for every decision and invocation.
Installation and Enabling¶
Before installing, ensure Node.js ^22.19.0 || >=24.0.0 and pnpm are installed, and DSH version is 0.1.0-rc.8 or later (verified as of 2026-08-21).
- Clone the repository and build the plugin.
git clone https://github.com/young-tim/dsh-llm-governor
cd dsh-llm-governor
pnpm install
pnpm build
pnpm pack --pack-destination <临时目录>
- Add the generated
.tgzfile to a DSH profile.
dsh plugin --profile <profile> add <临时目录>/dsh-llm-governor-<version>.tgz
- Restart the DSH service to load the plugin.
Usage and Configuration¶
Routing Strategies and Model Selection¶
Model selection goes directly into the DSH Composer (Auto mode is supported), while governance settings go into DSH native Settings. Decision records are displayed in the Governor Trajectory view for the same session.
Initial Quality Configuration¶
Auto, Quality First, and Credit First modes rely on Quality scores for models. After the initial installation, go to the Settings → Governor → Models page. For each model, select a quick tier to initialize it:
* Lite 75: Cost-saving tier.
* Balanced 85: Flash / standard tier.
* Pro 95: High-quality tier.
These quick tiers copy the same initial score to seven task types. You can later use “Advanced tuning” to adjust specific scores for different tasks.
Architecture and Responsibility Boundaries¶
Invocation Chain¶
The position of Governor in the DSH invocation chain is as follows:
Governor (选路/额度/审计) → DSH ctx.llm → DSH Provider Adapter → DSH Credentials Service → Provider
Responsibility Boundaries¶
- Does not proxy requests: Governor does not take over HTTP proxying or WebSocket traffic; it only provides decision logic.
- Does not manage credentials: Provider credentials are managed by the DSH Credentials Service. Governor does not read, store, or require
DEEPSEEK_API_KEY(only when a specific route selectsdeepseek-officialand no stored credential is available, the DSH adapter uses the environment variable). - Does not provide a login system: Governor does not provide registration, login, MFA, SCIM, or IdP lifecycle management.
Identity and User Management¶
The Users section in Governor is not an account directory; it is a governance policy table keyed by external user_id. It stores model allow lists, monthly credits, and usage summaries.
Identity Provider¶
Governor supports four identity binding modes: local, header, jwt, and custom:
* local: Treats the entire instance as a fixed user; suitable for personal or single-administrator deployments.
* header / jwt: Suitable for enterprise environments and should be used with a DSH identity bridge or trusted proxy.
* custom: An extension point that allows third-party host plugins to implement custom identity verification logic.
User Policies¶
Maintaining user policies in Settings does not create an account that can log in to DSH. Enterprise deployments typically need to preconfigure and deactivate users through an IdP, SCIM synchronization, or an administrative plugin.
Dependencies and Compatibility¶
- DSH version: Requires compatibility with DSH 0.1.0-rc.8 (as of 2026-08-21).
- Runtime environment: TypeScript ESM, Node.js
^22.19.0 || >=24.0.0, pnpm 11.
Conclusion¶
dsh-llm-governor provides a complete governance loop for DeepSeek Harness, covering model routing, quota control, and auditing. It integrates as a plugin without intruding on DSH’s core request processing flow, making it suitable for deployments that require fine-grained management and multi-tenant scenarios.