Introduction¶
DeepSeek Harness (DSH) is a plugin-based system designed to provide flexible agent control capabilities. In local development or deployment scenarios, users typically need a Web UI to manage sessions and view output. The kevin66z0/dsh-telegram plugin provides DSH with a Telegram remote control entry point, allowing users to interact directly with the Agent from a mobile device, with support for session binding, real-time viewing of streaming replies, and quick actions.
Plugin Overview¶
This plugin is maintained by Kevin66Z0 and is released under the MIT license. It uses Telegram as a unified console and manages access permissions through an allowlist mechanism to ensure session security.
Core Features¶
- Full session console: Supports binding sessions, viewing session details, sending text prompts, and displaying replies in real time by editing a single message.
- Real-time streaming replies: Assistant output is streamed into the message through live editing, including the reasoning process and tool-call steps, and finalized as HTML.
- Interactive question buttons: When the Agent invokes an interactive question, the interface generates clickable inline keyboards, allowing users to answer without typing text.
- Quick keyboard: Provides a row of quick actions, such as
/create(Create),/archive(Archive),/attach(Bind), and/stop(Stop). - Secure defaults: Uses an allowlist mechanism, so only authorized chat IDs can communicate with the bot, and all other access is denied with an access-denied message.
- Tokens never touch the disk: The bot token is referenced from an environment variable (
!!js process.env.TELEGRAM_BOT_TOKEN) and is not written directly into a configuration file. - Cold session recovery: Communicates through the Host’s apiProxy, supporting cold session recovery and queued message semantics.
Installation and Enablement¶
Environment Requirements¶
- Node.js >= 22.19
- An installed DeepSeek Harness source directory (recommended) or a running DSH deployment
- A Bot Token obtained from @BotFather
- Outbound access to api.telegram.org
Installation Steps¶
- Clone or download the plugin code.
- Run the Installation script to mount the plugin into the DSH directory:
./install.sh /path/to/deepseek-harness
Configuration Steps¶
- Set the environment variable: Inject the token into
DSH_HOME/.envand set 600 permissions:
echo 'TELEGRAM_BOT_TOKEN=<token-from-@BotFather>' >> "$DSH_HOME/.env"
chmod 600 "$DSH_HOME/.env"
- Configure the allowlist: Configure the chat IDs that are allowed to access in
$DSH_HOME/settings.yaml:
telegram:
allowChatIds: [123456789]
- Restart the service: Restart the DSH service to make the configuration take effect.
Typical Usage¶
The plugin is operated through Telegram bot commands. The following is a list of the main commands:
/attach [scope|n|id|none|arc]: Bind the current chat to the specified session./create: Open the creation submenu./operate: Open the operations submenu./new [path|n|none]: Create a new session./fork [n|id]: Fork a session from the last completed turn./archive [n|id]: Archive the specified session./status [n|id]: View session details./model [name]: Set the global default model./rename [title]: Rename the currently bound session./preset [name|n]: Select a preset Agent configuration.
Security and Caveats¶
- Allowlist restriction: The plugin denies all access by default, and
allowChatIdsmust be specified in the configuration. - No inbound listening: The plugin does not listen on any inbound port and communicates only through outbound long polling to Telegram, making it suitable for use behind NAT.
- Token management: The token is stored in an environment variable. If leaked, it can be quickly revoked and regenerated through @BotFather.
- Dependency requirement: Node.js >= 22.19 is required.
Summary¶
dsh-telegram provides DeepSeek Harness with a secure, lightweight mobile control solution. Through Telegram, developers can manage Agent sessions on any device without relying on a Web UI. All sensitive operations, such as token storage and session binding, follow security best practices.