在 DeepSeek Harness(DSH)环境中,跨机器同步配置通常意味着复制整个配置目录,这会引入敏感信息和本地化设置。dsh-sync 旨在解决这些问题,提供一种更安全、更可控的 Git 同步工作流。

dsh-sync 是一个用于同步 DeepSeek Harness 设置和配置文件的插件。它由 ZhenHuangLab 维护。核心价值在于让用户明确选择要同步的内容,同时将敏感数据和本地设置保留在本地,并在应用变更前进行审核。

Core Features

  • Selective configuration sync: Sync only selected namespaces and configuration files.
  • Sensitive-settings awareness: Strip known keys and local paths from configurations before storage to ensure sensitive data does not enter Git.
  • Line-by-line review: Review changes before applying them, and enable or disable individual lines.
  • Executable change confirmation: Explicit confirmation is required when changes involve code or plugin execution.
  • Conflict handling: Supports cherry-picking a single line or choosing Keep/Take for the entire file.
  • Safe recovery: Back up before applying, and restore on interruption or validation failure.

Install and Enable

Using a Web configuration file as an example, the install command is as follows:

dsh plugin --profile web add dsh-sync

After installation, restart dsh web, then open Settings → Git Sync in the Web UI.

Usage

Web Interface Flow

  1. In Settings → Git Sync, enter the Git remote URL and branch.
  2. Select the settings namespaces, configuration files, patches, and presets to sync.
  3. Add machine-specific settings paths to Keep local-only paths, ensuring these paths are not synced.
  4. Save the configuration and choose Compare.
  5. Check the incoming and outgoing changes, and apply the settings after confirming they are correct.

Command-Line Operations

The following /sync commands can be used in a session:

/sync status
/sync check
/sync diff
/sync pull
/sync push
/sync doctor
/sync recover

The command can also be run directly in the terminal:

dsh-sync status
dsh-sync check
dsh-sync doctor
dsh-sync recover

Local Path Configuration

If certain settings (such as baseURL) need to remain unchanged on a specific machine, add these paths to Keep local-only paths.

Notes

  • Credential handling: dsh-sync does not store Git credentials in the configuration; instead, it uses the existing Git environment. It rejects HTTPS remote URLs that contain embedded credentials.
  • Scan reports: Sensitive scan reports show affected paths but do not reveal specific key values.
  • Content that is not synced: The following content is never synced: credentials, sessions, storage, node_modules, generated configuration files (such as .dsh-sync, .env*), system presets, symbolic links, or gitlinks.
  • Executable changes: Changes involving code or plugin execution are never applied automatically; they must be confirmed by the user.

Summary

dsh-sync provides DSH with a secure Sidecar Git workflow. Through selective configuration synchronization, sensitive data filtering, and strict change confirmation mechanisms, it addresses the pain points of cross-machine configuration management.