Introduction

The Web GUI of DeepSeek Harness (DSH) is bound to the local address by default. To access it from an external network or LAN, you typically need to configure an SSH tunnel or a complex reverse proxy. dsh-remote-access is a DSH plugin that acts as a TLS edge entry point for the DSH Web service. It provides independent port listening, self-signed certificates, login authentication, session protection, and transparent HTTP/WebSocket reverse proxying. It supports exposing the service to remote networks through FRP, Cloudflare tunnels, or similar mechanisms.

Core Features

  • TLS and Authentication: Listens on a dedicated port (default 3081) and automatically generates self-signed certificates. Supports username and password login. After login, it issues session Cookies with HttpOnly/SameSite/Lax/Secure attributes.
  • Transparent Proxy: Transparently forwards HTTP and WebSocket requests to the local DSH Web service (127.0.0.1:3080).
  • Hot Configuration: Modify TLS, port, listen address, username, and password immediately via the GUI settings panel. Supports start and stop actions.
  • Remote Access: Supports LAN access, FRP tunnels, and Cloudflare tunnels for remote access.

Installation

This plugin is a DSH Web Profile plugin and requires a running DSH Web deployment first.

Use the official command dsh plugin to install (works on Linux, macOS, and Windows):

dsh plugin --profile web add github:zergtant/dsh-remote-access

After installation, DSH must be restarted for the plugin to take effect. The plugin defaults to enabled: false and does not automatically listen on any port. During installation, pnpm may report missing peer dependency warnings; this is expected and does not affect actual operation.

Usage

  1. After restarting DSH, open the GUI: Settings → Remote Access.
  2. Set the username (default admin) and password.
  3. Click the Start button at the top of the page (takes effect immediately).
  4. Access:
    • Local machine: https://127.0.0.1:3081
    • LAN: https://<host-IP>:3081
    • Public network: point an frp tunnel to 127.0.0.1:3081

Configuration

Field Default Description
Start/Stop — Actions at the top of the page: click “Start” to start immediately, click “Stop” to stop immediately. Neither requires saving. The current status is displayed in real time next to the buttons.
TLS (HTTPS) On Self-signed HTTPS. Off = plain HTTP (for intranet/debugging only). Takes effect after saving.
Port 3081 1–65535. The listening address migrates immediately after saving.
Listen Address 0.0.0.0 0.0.0.0 (external) / 127.0.0.1 (local only, for example for frp only).
Username admin Login username.
Password — Stored in the DSH credential store (~/.dsh/.credentials.yaml). If left blank, the existing value remains unchanged.

Notes

  • Self-Signed Certificate: On first browser access, the certificate will be marked as untrusted. You need to click “Advanced → Proceed to site”.
  • Session State: Sessions are stored in memory. You must log in again after DSH restarts.
  • Single-Instance Limit: A single process has one edge. One DSH instance corresponds to one 3081 port. Multiple instances require different ports.
  • pnpm Notices: Peer dependency warnings during installation are expected. The plugin still runs normally.

Conclusion

dsh-remote-access adds a layer of TLS and authentication gateway, solving the problem that the locally listening DSH Web service is difficult to access remotely. It is suitable for scenarios where DSH needs to be accessed through tunnels in intranet or public network environments.