Introduction

By default, for security reasons, the DeepSeek Harness (DSH) WebUI does not allow listening on 0.0.0.0. When you need to access the WebUI from the public internet, directly exposing the port is risky. DSH uses a plugin-based architecture. The community maintains the dsh-remote-access plugin to provide secure access over the public internet.

Plugin Overview

dsh-remote-access is a client plugin maintained by RedreamR. It addresses the issue that the DSH WebUI itself cannot listen on a public address, enabling secure remote access through port forwarding and password verification.

Core Features

  • Public Internet Access: Provides secure access to the DeepSeek Harness WebUI over the public internet.
  • Access Control: Supports configuring the forwarded port and password to prevent unauthorized access.
  • Security Policies: Supports configuring CAPTCHA, the maximum number of attempts per day, and the maximum number of attempts per 5 hours.
  • Configuration Methods: Supports configuration through the DSH settings UI or the profile overlay (cordis.patch.yml).

Installation and Uninstallation

The plugin is installed using DSH’s plugin commands. Due to pnpm restrictions on GitHub packages, you need to add the --dangerously-allow-all-builds argument when installing.

Installation command:

dsh plugin --profile web add github:RedreamR/dsh-remote-access --dangerously-allow-all-builds

Uninstallation command:

dsh plugin --profile web remove dsh-remote-access

Configuration Example

The plugin configuration supports two methods: using the “Remote” page in the DSH settings UI, or overriding values in the profile’s cordis.patch.yml.

Basic configuration YAML example:

- id: dsh-remote-access
  config:
    enabled: true
    remoteHost: '0.0.0.0'
    remotePort: 3081
    password: 'your-strong-password'
    enableCaptcha: false
    maxAttemptsPerDay: 20
    maxAttemptsPer5h: 10

Notes:
* When the password is saved through the settings UI, it is written in encrypted form to $DSH_HOME/settings.yaml.
* Because the DSH WebUI itself does not allow listening on 0.0.0.0, this plugin provides a forwarding feature.

Use Cases and Considerations

This plugin runs with the permissions of the current DSH process. It is suitable for users who need to access the WebUI over the public internet. Before installation, review the source code and license to ensure they comply with your security policies.