DeepSeek Harness (DSH) uses a plugin-based architecture. When handling workspace environment configuration, developers often want to reuse locally configured .envrc files. DSH’s native environment management, however, differs from the behavior of direnv, and parsing .envrc directly within the DSH process introduces complexity in state management. The dsh-workspace-envrc plugin is designed to solve this problem. It delegates the discovery, evaluation, and authorization validation of .envrc entirely to the direnv executable installed on the host, thereby providing native direnv environment behavior within DSH.
This is an out-of-tree DSH bundle maintained by TTTPOB. Its core purpose is to apply the host’s native direnv environment to Bash executions that are explicitly attributed to an Agent or workspace, as well as local stdio workspace MCP lines. The plugin does not parse or source .envrc directly, nor does it maintain its own authorization database; instead, it invokes the host’s direnv to perform all environment changes.
Core Features¶
- Bash Environment Integration: The integration plugin reversibly decorates
ctx.shell.resolve. When the call has a current initiator Agent and that Agent maps to a canonical workspace, the plugin replacesrequest.commandwith a command launched throughdirenv exec, ensuring that environment variables are managed bydirenv. - MCP Environment Integration: The integration plugin reversibly decorates
ctx.workspaceMcp.activate. Only local stdio MCP lines mapped to a canonical workspace are wrapped so that thedirenvenvironment is applied during execution. - Full Delegation: The plugin delegates
.envrcdiscovery, evaluation, authorization hash, allow/deny logic, and stdlib handling entirely to the installeddirenvexecutable. It does not itself hold environment snapshots or authorization data.
Installation and Enablement¶
Before installing, ensure that direnv is installed on the host and that the required dsh-workspace-overlay dependency is installed. Follow these steps:
- Install the overlay bundle first:
dsh plugin --profile web add https://github.com/TTTPOB/dsh-workspace-overlay/releases/download/v0.1.1/dsh-workspace-overlay-0.1.1.tgz
- Then install the envrc bundle:
dsh plugin --profile web add https://github.com/TTTPOB/dsh-workspace-envrc/releases/download/v0.1.1/dsh-workspace-envrc-0.1.1.tgz
- Export the configuration to verify the installation:
dsh --profile web --dump-config
After installation, verify module resolution and the final composition. Ensure that in dsh.profile.bundles the overlay is placed before envrc, and restart the Host.
Configuration and Usage¶
The plugin configuration is defined by the WorkspaceEnvrcConfig interface, with the following defaults:
executable: direnv
shimShell: /bin/bash
enableBash: true
enableWorkspaceMcp: true
versionCheckTimeoutMs: 5000
Activation and Preflight:
During activation preflight, the plugin runs direnv version and a restricted shim probe to verify that direnv is available. However, it does not read the workspace’s .envrc at this stage.
Authorization Management:
The authorization process is handled entirely by the host’s direnv. Users must run direnv allow <exact .envrc> outside DSH. The plugin does not expose allow/deny tools to the model and does not invoke direnv allow/permit/grant/edit.
How It Works:
For Bash, the plugin starts a new process via exec direnv exec <canonical-workspace> <managed-env-shim> <original-command>, preserving the caller-resolved cwd for the original program. For MCP, the plugin only rewrites command/args, without changing cwd or explicit env.
Applicable Scenarios and Notes¶
Unsupported Features:
This bundle does not support persistent shells or terminal creation. DSH mounts terminals in a preset private isolated realm, and this plugin, as a Host profile layer, relies on an internal mounting API that is not yet stable to implement that capability. For this reason, it is currently restricted.
Security and Boundaries:
1. Stateless: The plugin does not modify the Harness process.env. Executions in different workspaces are resolved by Agent scope and do not share mutable workspace state.
2. Privacy Protection: The plugin does not read, log, or print full environment snapshots, .envrc contents, stdout/stderr, or secrets.
3. Sandbox Limitations: The current overlay MCP stdio transport lacks a sandbox/confine seam. Therefore, MCP child processes and .envrc evaluation use the transport’s host process permissions and are not claimed to be equivalent to the Bash sandbox.
Summary¶
dsh-workspace-envrc provides a non-invasive way for DSH to leverage the host’s native direnv capabilities to manage workspace environments. By using a delegation mechanism, it avoids maintaining environment state inside DSH. It is suitable for development scenarios that require seamless use of local .envrc configurations within DSH.