Foreword¶
DeepSeek Harness (DSH) provides a Web interface for developers to debug and view sessions, but by default it usually listens only on the local loopback address. If you want to continue work from your phone, you typically need to set up an SSH tunnel or configure complex port forwarding. The moonglasskitty/dsh-tailscale-sync plugin leverages the encrypted tunnel provided by Tailscale, allowing developers to access the Harness Web service from a phone without manually configuring network ports.
What Is This¶
This is a DSH plugin (networking tool category) maintained by MoonGlassKitty. Its core function is to securely expose the Harness Web service through Tailscale to other devices in the same Tailnet, enabling zero-configuration remote access.
Core Features¶
- Port Locking: Automatically binds the Harness Web service to
127.0.0.1:3080, so it is not exposed to the normal LAN and only local access is allowed. - Automatic Trust: Automatically detects the local
*.ts.netdomain (viatailscale status) and modifies the/apitrust boundary, allowing only that domain. - Zero Configuration: Uses Tailscale’s authentication and MagicDNS capabilities, eliminating the need to manually configure routing and domains.
- Cross-Platform: Supports Windows, macOS, and Linux systems.
Installation and Enablement¶
The installation and enablement process consists of three steps.
-
Install Tailscale (one-time operation)
Install Tailscale on both your computer and phone, and log in with the same account. Make sure MagicDNS is enabled on your Tailnet (enabled by default in newer versions). -
Install the Plugin
Run the following command in your computer terminal:
dsh plugin --profile web add github:MoonGlassKitty/dsh-tailscale-sync
- Enable the HTTPS Tunnel
Run the following command on your computer to start the encrypted tunnel:
tailscale serve --bg 3080
If you see the message “Serve is not enabled on your tailnet”, follow the prompt and click the link to authorize it once.
Typical Usage¶
After completing the steps above, your phone can access Harness.
-
Get the Machine Name
Runtailscale statuson your computer and find your machine name (for example,my-macbook). -
Access from the Phone
Keep Tailscale connected on your phone, then open the following URL in your browser:
https://<你的机器名>.ts.net
- Disable the Tunnel
When you no longer need remote access, run the following command to turn off the tunnel:
tailscale serve --https=443 off
Applicable Scenarios and Notes¶
- Applicable Scenarios: Suitable for developers who need to continue DeepSeek Harness sessions from a computer on a phone, or for cases where temporary inspection of Harness status is needed.
- Permissions and Security: The plugin only modifies Web service configuration. Settings and API key management must still be handled locally at
http://127.0.0.1:3080(due to security restrictions in the Harness source code). - Network Limitation: The port listens only on the loopback address; devices on a normal LAN cannot directly access this port.
- MagicDNS Requirement: If MagicDNS is not enabled on your Tailnet, the plugin automatically falls back to local-only access. In that case, you need to manually fill in the
trustedHostsconfiguration item in thecordis.patch.ymlfile.
Conclusion¶
By integrating Tailscale, this plugin solves the inconvenience of local-only access to the DSH Web interface and provides a secure, convenient mobile access solution. For more details and source code, see the GitHub repository or the DSH ecosystem directory.