Introduction

When running the DeepSeek Harness (DSH) locally, developers often need to access the console through a LAN or the public internet. Exposing ports directly is relatively risky. The dsh-remote-access plugin uses Caddy as a reverse proxy and API Gateway to provide secure LAN access to local DSH, a private Tailscale entry point, and an optional Cloudflare Tunnel public entry point.

Core Features

This plugin mainly addresses remote access to local DSH. Its core capabilities include:

  • Multi-mode entry points: Provides three access modes: LAN, Tailscale Serve/Funnel, and Cloudflare Tunnel.
  • API policy control: Configures independent API allowlists for different entry points (lan/serve/funnel/cloudflare), with high-risk interfaces restricted by default.
  • Unified gateway: Uses Caddy as the reverse proxy and API Gateway to uniformly handle Host, Origin, WebSocket, and TLS.
  • Authentication and security: Supports Basic Auth credential management, provides a QR code login entry point (one-time tickets), and includes edge diagnostic tools.
  • TLS automation: In LAN mode, supports lanTlsMode: auto, automatically detecting OpenSSL or falling back to the Caddy internal CA.

Installation and Enablement

  1. Install using a command:
    dsh plugin --profile web add @greenonion/dsh-remote-access
  1. Manual installation:
    git clone <repo-url> dsh-remote-access
    cd dsh-remote-access
    node install.js
  1. After installation, restart DSH and manage Caddy, LAN policy, and API policy in Settings → Remote Access.

Typical Usage

  • Configure LAN TLS:
    By default, lanTlsMode is auto. If OpenSSL is not found, it automatically falls back to Caddy internal. You can explicitly set it to caddy-internal in cordis.patch.yml to avoid relying on the system OpenSSL.
  • Configure Cloudflare Tunnel:
    Enable Cloudflare on the settings page and configure externalOrigins (e.g., https://dsh.example.com). The plugin only controls the loopback adapter and does not manage the cloudflared process.
  • Run diagnostics:
    Use the included diagnostic script to check network status.
    node scripts/edge-diagnostics.mjs --tailscale --json

Use Cases and Notes

  • Use cases: Local DSH needs to be accessed by other devices on the LAN or via the public internet.
  • Notes:
    • In newer DSH versions, client-connection authenticates browser pages; older versions may fall back.
    • Tunnel-only mode does not provide user authentication and only exposes basic APIs.
    • The API method allowlist is not a sandbox; an entity that gains session.prompt still has full control.
    • LAN access can be restricted by source network ranges using lanAllowedCidrs.
    • Disabling a port removes it from the Caddyfile, and Caddy --watch hot-applies the change.

Conclusion

This plugin solves the remote access issue for local DSH runtime through a unified gateway and policy control. For full documentation or to report issues, visit the GitHub repository.