Introduction¶
DeepSeek Harness (DSH) listens only on the local loopback address (127.0.0.1) by default, so phones, tablets, or other devices cannot access the Web console from external locations. dsh-remote-mobile enables secure access over Tailscale virtual private networks and local area networks without modifying DSH’s underlying code, using access-control middleware and request isolation.
What Is This¶
dsh-remote-mobile is a secure gateway plugin for remote and mobile access, developed by IceApriler. It provides DSH with LAN and Tailscale connectivity, QR-code pairing, RSA transport-layer encryption, and brute-force protection, and includes style adaptations for mobile interfaces.
Core Capabilities¶
- Network Access: Supports access via Tailscale virtual private networks and local area networks (LAN / Wi-Fi).
- Pairing and Authentication: Supports quick pairing with a QR code, RSA transport-layer encryption, and scrypt slow-hash password storage.
- Security Protection: Includes brute-force protection with rate limiting and an intelligent mechanism for passing through static resources.
- Mobile Adaptation: Includes built-in mobile style adaptations and supports real-time status updates via SSE.
- Plugin Coexistence: Provides a general-purpose coexistence protection mechanism for plugins.
Installation and Enablement¶
- Install the Plugin
Run the official plugin installation command:
dsh plugin --profile web add dsh-remote-mobile
-
Configure External Listening
DSH listens only on127.0.0.1by default. You must modify the configuration file to allow access from the LAN/Tailscale.
The configuration file path is~/.dsh/profiles/web/cordis.patch.yml(on Windows:%USERPROFILE%\.dsh\profiles\web).Add the following content to the configuration file:
- id: webserver
name: '@deepseek-ai/dsh-host-webserver'
inject: [webStartup]
config:
host: '0.0.0.0'
port: 3080
- Start the Service
Start the DSH Web service:
dsh web --no-open
- Pair with a QR Code
Open the DSH Web console in a browser, go to the Settings page, and scan the QR code to complete pairing.
Notes¶
- Configuration Notes: You do not need to manually register
id: remote-mobileincordis.patch.yml. The DSH Bundle system handles it automatically. - Ecosystem Plugin Conflicts: It is not recommended to install the
@linxin666/dsh-web-allbundle. Install individual plugins as needed to avoid duplicate mobile floating entry points and gesture interaction conflicts. - Runtime Permissions: The plugin runs with the permissions of the current DSH process. It is recommended to review the source code and license before installation.
Summary¶
dsh-remote-mobile addresses DSH’s default network restrictions by providing a secure external access channel through middleware and encryption mechanisms, and it includes mobile-oriented adaptations. For more details, see the Directory Page or the GitHub Repository.