DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture and supports feature extension through plugins. For developers who need to use the dsh Web UI in remote environments (such as intranets or cloud servers), configuring a public IP or port mapping is usually required. dshost-plugin is an official remote cloud relay plugin maintained by NoelJudeNoel. It uses a secure WebSocket tunnel, allowing you to access a local dsh instance from anywhere without exposing local ports.

Plugin Introduction

This plugin is part of the DSH ecosystem and aims to solve network traversal issues in remote-access scenarios. It is a tool open-sourced under the MIT license, which runs a local Agent that actively connects to a DSHost relay server to implement a reverse proxy.

Core Features

  • Zero Public IP: The Agent actively makes outbound connections to the relay server (wss://dshost.me/agent), so no inbound ports need to be opened locally.
  • Non-Destructive Multi-Version Compatibility: Supports multiple DSH version ranges, including versions from 0.0.1-rc.* through 0.1.5-*.
  • Security Mechanisms: The relay layer rewrites Host/Origin to comply with DSH’s trust boundary; sensitive keys in settings.describe are masked before delivery; production environments enforce encrypted transmission over wss.
  • Starts with dsh: Loaded as a cordis plugin with the dsh web command, supporting automatic reconnection and a low-bandwidth idle state.

Installation and Activation

Before installing, ensure your environment meets the dependency requirement: Node.js >= 22.5.0.

1. Request a Token

Visit dshost.me, register or log in, and create an instance to obtain an access Token that starts with dsh_.

Use the official installation script, which automatically installs pnpm and adds the plugin to the current profile.

# macOS / Linux
curl -fsSL https://dshost.me/install.sh | RELAY_HOST=dshost.me bash

3. Manual Installation

dsh plugin add dshost-plugin

4. Configure the Plugin

Declare the plugin in the cordis.patch.yml file of the current profile. New configuration lines must be placed inside the - insert: block:

- insert:
    - id: dshost-agent
      name: 'dshost-plugin'
      config:
        token: dsh_your_token_here
        relayUrl: wss://dshost.me/agent
        autoConnect: true

5. Restart dsh

After applying the configuration, restart the DSH service.

sudo systemctl restart dsh

Configuration Options

Field Required Description
token ✔ Relay access Token, requested on dshost.me
relayUrl ✔ Relay WebSocket address; must be wss:// in production
autoConnect ✕ Defaults to true, connecting on startup
dshHost / dshPort ✕ Local dsh web address, defaulting to 127.0.0.1:3080

Notes

  • Node.js Version: The plugin requires a Node.js >= 22.5.0 runtime.
  • Dependencies: The core dependency is the ws library.
  • License: Licensed under the MIT license; please review the source code yourself.
  • Permissions: The plugin runs with the permissions of the current dsh process. Ensure the configured dshHost and dshPort are accessible by that process.
  • Syntax Requirement: When declaring the plugin in cordis.patch.yml, new content must be placed inside a - insert: list item.

Summary

dshost-plugin provides DSH users with a solution to securely access the Web UI without a public IP. Its active outbound Agent architecture reduces operational complexity, while security rewriting and enforced encryption ensure the reliability of data transmission.