Introduction¶
The Web GUI of DeepSeek Harness (DSH) does not support access from the public internet by default. The dsh-https-fix plugin solves external access and security configuration issues by using a built-in HTTPS reverse proxy and runtime hot patching.
Plugin Overview¶
dsh-https-fix is a network tool plugin maintained by MingYU-kalo and licensed under the MIT License. Its core purpose is to make the DSH Web GUI accessible over HTTPS from external networks, while also providing certificate management, domain registration, and access control features.
Core Features¶
The plugin mainly provides the following capabilities:
- HTTPS reverse proxy: The plugin listens for TLS on its own and forwards traffic to the local HTTP port.
- Trusted domain registration: Register domains or IPs into the trusted list at runtime without modifying DSH startup parameters.
- Client hot patch: Modify
@deepseek-ai/dsh-client-connection/lib/client.jsto allow access to the settings page via domain/IP. - TLS certificate management: Supports automatic self-signed certificates, custom certificates (including IP certificates), and scenarios where no domain is available and an IP is used.
- Web username/password login: Provides separate Web authentication (default admin/admin), with a 7-day session.
- Access and security: External HTTP access can be disabled; ports and automatic Token mode can be configured.
- Diagnostic tools: Provides an “Validate HTTPS Availability” function with 12 checks.
Installation and Activation¶
Before installation, make sure the plugin version exactly matches the DSH version. The installation command is as follows:
dsh plugin --profile web add github:MingYU-kalo/dsh-https-fix#dsh-<版本>
If installing from a local path, the file: prefix is required:
dsh plugin --profile web add file:/path/to/dsh-https-fix
After installation, restart the DSH Web service. Open https://<domain or IP>:<port> in a browser and log in with the default admin / admin.
Typical Usage¶
- After logging in, navigate to Settings → Plugin Configuration → Https Fix.
- On the configuration page, enter the domain or IP and select the certificate type:
- Leave both paths empty: use an automatic self-signed certificate.
- Fill in paths: use your own certificate. - Click “Apply Hot Patch in One Click”.
- Click “Validate HTTPS Availability” and ensure all 12 checks are displayed in green.
Notes¶
High-risk plugin: This plugin modifies the DSH source code file @deepseek-ai/dsh-client-connection/lib/client.js via runtime hot patching, and has the following risks:
- Strict version binding: The plugin version must exactly match the DSH version. Installing the wrong version will cause DSH to fail to start.
- Upgrade conflicts: After upgrading DSH, the old plugin may overwrite the hot patch and prevent DSH from starting. Before upgrading DSH, you must first uninstall or disable the plugin.
- Security risk: The plugin exposes DSH to the public internet, with default credentials
admin/admin. Be sure to change the password on the login page and configure a firewall whitelist. - Local installation restriction: Local path installation must use the
file:prefix; otherwise, it will be treated as a linked dependency and cause startup failure.
Summary¶
dsh-https-fix uses hot patching to enable external HTTPS access to DSH, making it suitable for scenarios where the DSH Web interface needs to be accessed over the public internet. However, because it directly modifies core source code, it has high requirements for version compatibility and upgrade processes, so use it with extreme caution.
- Plugin directory page: dsh-https-fix
- Source code address: github.com/MingYU-kalo/dsh-https-fix