Foreword

The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In scenarios that require managing cloud resources, calling Azure CLI directly often suffers from unstructured output and complicated command parameters. The wode25500/dsh-az plugin aims to address this pain point. It wraps Azure CLI to provide native tools, allowing the model to directly read structured data and perform queries, display, and deployment of Azure resources.

What It Is

dsh-az is an independent community project maintained by WODE25500. It is not an official Azure tool, but a DSH plugin built on the open-source Azure/azure-cli (MIT License). The plugin continues Microsoft ecosystem themes and provides DSH agents with a standardized toolchain for managing Azure resources.

Core Features

The plugin provides 7 native tools, covering the core scenarios of resource management:

  1. az_status: Query the current status.
  2. az_subscriptions: Manage subscription information.
  3. az_resource_query: Query resources.
  4. az_show: Display details of a specific resource.
  5. az_activity_log: Diagnose Azure activity logs.
  6. az_group_create: Create resource groups.
  7. az_deploy: Deploy Bicep and ARM JSON templates.

In addition, the plugin has the following features:
* Structured data output: All query tools enforce the use of --output json, so the model can directly parse the returned JSON structure without writing regular expressions or parsing logic.
* Safety confirmation mechanism: For write operations (such as group create and deploy), the plugin explicitly requests confirmation to prevent accidental operations.
* Template support: Natively supports deployment of Bicep and ARM JSON templates.

Installation and Enablement

During installation, a tool with the ID az must be inserted into the DSH configuration. This tool points to the plugin’s entry file and requires configuration of the Azure CLI path and subscription ID.

- insert:
    - id: az
      name: './src/index.js'
      config:
        azPath: az
        subscription: <your-sub-id>

Notes:
* azPath: Specifies the path to the local az command.
* subscription: Specifies the default subscription ID for operations.

Typical Usage

Based on the installation above, the agent can perform the following steps:

  1. Query and Display: Use az_status to view the global status, or use az_resource_query and az_show to obtain structured data for specific resources.
  2. Subscription Management: Call az_subscriptions to view the list of available subscriptions.
  3. Resource Group Creation: Use az_group_create to create a new resource group (confirmation required).
  4. Template Deployment: Use az_deploy to upload and execute Bicep or ARM JSON templates (confirmation required).
  5. Log Diagnostics: Use az_activity_log to inspect Azure activity logs.

Applicable Scenarios and Considerations

  • Applicable scenarios: Suitable for developers who need to automate Azure resource management in the DeepSeek Harness environment, especially in scenarios that frequently require template deployment or resource auditing.
  • Considerations:
    • This is an independent community project, not an official product. It is recommended to review the source code and license before use.
    • Because the plugin runs with the permissions of the current DSH process, ensure the environment is secure.
    • When performing write operations, pay close attention to the explicit confirmation prompts to avoid accidentally modifying production environments.

Conclusion

By wrapping Azure CLI as DSH-native tools, dsh-az lowers the barrier for agents to operate cloud platforms. It focuses on providing structured data and a secure deployment process, making it a practical tool for Azure users to manage resources in the DSH ecosystem. For more details and source code, visit the project homepage.