DeepSeek Harness (DSH) spills content to external storage instead of directly stuffing it into the model context when handling ultra-long tool outputs. The default dsh-spill-local can only write to local disk. dsh-spill-s3 is a plugin that implements the ctx.spillStore interface and writes spilled data to S3-compatible object storage (such as AWS S3, MinIO, and Cloudflare R2), replacing local disk storage.
Plugin Positioning¶
- Name:
dsh-spill-s3 - Maintainer:
tancheng33 - Category: Networking tool
- Core Value: Moves spilled tool outputs from local disk to object storage, solving data persistence issues in containerized deployments or distributed environments.
Core Features¶
- Implements an S3-compatible spill backend.
- Spills oversized tool outputs to object storage.
- Supports AWS S3, MinIO, Cloudflare R2, or any S3-compatible server.
- Implements the
ctx.spillStoreinterface. - Automatically disables
spill-localon installation. - Does not depend on the AWS SDK and uses
node:cryptofor signing.
Installation and Enablement¶
Installing this plugin requires using DSH’s plugin management command. The installation package includes the cordis.patch.yml configuration file, which automatically disables the default spill-local backend because ctx.spillStore accepts only one implementation per context.
dsh plugin --profile <name> add dsh-spill-s3
Typical Usage¶
After installation, you need to specify the bucket and endpoint in the configuration file. Note that the bucket field is empty in the configuration and must be filled in manually, because the plugin does not create the bucket automatically.
Add the following configuration to cordis.patch.yml:
- id: spill-s3
config:
endpoint: https://s3.us-east-1.amazonaws.com
region: us-east-1
bucket: my-agent-spill
prefix: dsh-spill
forcePathStyle: false # AWS virtual-hosted style
accessKeyIdRef: AWS_ACCESS_KEY_ID
secretAccessKeyRef: AWS_SECRET_ACCESS_KEY
sessionTokenRef: AWS_SESSION_TOKEN
serverSideEncryption: AES256
retrieval: cli
presignExpiresSeconds: 3600
timeoutMs: 30000
MinIO / R2 / Self-Hosted Example¶
If using MinIO or a self-hosted service, you usually need to set forcePathStyle: true.
- id: spill-s3
config:
endpoint: http://127.0.0.1:9000
region: us-east-1 # arbitrary value, used only for the signing scope
bucket: agent-spill
forcePathStyle: true # required
serverSideEncryption: '' # some servers reject this header
# ... rest of config
Use Cases and Notes¶
- Use Cases: Suitable for headless/containerized runtime environments, long-term retention of spilled data, or scenarios where team members need to share spill results.
- Prerequisite: The bucket must already exist; the plugin does not create it.
- Credential Mechanism: Fields such as
accessKeyIdRefare reference names, not plaintext values. The values are resolved throughctx.credentialson each upload. It is recommended to use this together with a credential center or secret manager. - Retrieval Modes: Supports three modes:
cli(default): The model executesaws s3 cp.presigned: The model obtains a presigned URL with an expiration (note that this is a credential with a lifecycle).locator-only: Only provides the location, and the user reads it manually.
- Security and Performance: Uses
node:cryptofor signing and has no AWS SDK dependency. The Session ID is hashed to protect privacy.
Summary¶
This plugin replaces the storage backend to adapt DSH’s spill mechanism to cloud and containerized environments without changing the spill strategy.
- GitHub: https://github.com/tancheng33/dsh-spill-s3
- Directory: https://www.skillhub.cn/plugins/tancheng33/dsh-spill-s3