Introduction¶
When running the DeepSeek Harness (DSH) locally, developers often need to access the console through a LAN or the public internet. Exposing ports directly is relatively risky. The dsh-remote-access plugin uses Caddy as a reverse proxy and API Gateway to provide secure LAN access to local DSH, a private Tailscale entry point, and an optional Cloudflare Tunnel public entry point.
Core Features¶
This plugin mainly addresses remote access to local DSH. Its core capabilities include:
- Multi-mode entry points: Provides three access modes: LAN, Tailscale Serve/Funnel, and Cloudflare Tunnel.
- API policy control: Configures independent API allowlists for different entry points (lan/serve/funnel/cloudflare), with high-risk interfaces restricted by default.
- Unified gateway: Uses Caddy as the reverse proxy and API Gateway to uniformly handle Host, Origin, WebSocket, and TLS.
- Authentication and security: Supports Basic Auth credential management, provides a QR code login entry point (one-time tickets), and includes edge diagnostic tools.
- TLS automation: In LAN mode, supports
lanTlsMode: auto, automatically detecting OpenSSL or falling back to the Caddy internal CA.
Installation and Enablement¶
- Install using a command:
dsh plugin --profile web add @greenonion/dsh-remote-access
- Manual installation:
git clone <repo-url> dsh-remote-access
cd dsh-remote-access
node install.js
- After installation, restart DSH and manage Caddy, LAN policy, and API policy in Settings → Remote Access.
Typical Usage¶
- Configure LAN TLS:
By default,lanTlsModeisauto. If OpenSSL is not found, it automatically falls back to Caddy internal. You can explicitly set it tocaddy-internalincordis.patch.ymlto avoid relying on the system OpenSSL. - Configure Cloudflare Tunnel:
Enable Cloudflare on the settings page and configureexternalOrigins(e.g., https://dsh.example.com). The plugin only controls the loopback adapter and does not manage the cloudflared process. - Run diagnostics:
Use the included diagnostic script to check network status.
node scripts/edge-diagnostics.mjs --tailscale --json
Use Cases and Notes¶
- Use cases: Local DSH needs to be accessed by other devices on the LAN or via the public internet.
- Notes:
- In newer DSH versions,
client-connectionauthenticates browser pages; older versions may fall back. - Tunnel-only mode does not provide user authentication and only exposes basic APIs.
- The API method allowlist is not a sandbox; an entity that gains
session.promptstill has full control. - LAN access can be restricted by source network ranges using
lanAllowedCidrs. - Disabling a port removes it from the Caddyfile, and Caddy
--watchhot-applies the change.
- In newer DSH versions,
Conclusion¶
This plugin solves the remote access issue for local DSH runtime through a unified gateway and policy control. For full documentation or to report issues, visit the GitHub repository.