Introduction¶
In DeepSeek Harness (DSH), proxy configuration typically requires modifying configuration files and restarting the process. The dsh-proxy plugin solves this problem by taking over global fetch calls, allowing hot reloading of HTTP(S)/SOCKS5 routing via Web settings or configuration files without restarting DSH.
Plugin Introduction¶
tr1v3r/dsh-proxy is a DSH plugin for routing all in-process outbound requests (LLM providers, web_search, streamable-http MCP).
- Maintainer: tr1v3r
- Category: Network tools
- License: MIT
Core Features¶
- Global routing: Intercepts all in-process outbound requests and forwards them through HTTP(S) CONNECT or SOCKS5 proxies.
- Runtime switching: Switch between direct, follow-system, and manual proxy modes without restarting.
- Protocol support: Supports HTTP(S) and SOCKS5.
- Bypass rules: Supports noProxy rules (undici-style matchers).
- Subprocess environment variables: Supports exporting proxy environment variables to subprocesses (
exportEnv: true). - System proxy detection: Supports detecting proxy settings from macOS System Settings (system mode).
- Loopback bypass: Local loopback addresses are skipped by default.
Installation and Activation¶
The plugin is installed via npm. Run the following command in the target configuration profile directory:
dsh plugin --profile <name> install --no-frozen-lockfile
Configuration and Usage¶
Via Web Settings¶
- Open the DSH Web interface.
- Go to Settings → General → Network proxy.
- Select a mode from the dropdown: Direct, Follow system, or Manual.
- In Manual mode, enter the proxy address and bypass list. Text fields save on blur.
Via Configuration File¶
Edit ~/.config/dsh/profiles/<name>/cordis.patch.yml.
- id: dsh-proxy
config:
mode: manual # direct | system | manual
proxy: socks5://127.0.0.1:1080 # http://…, https://…, socks5://…
noProxy: # optional bypass list
- localhost
- .internal.example
- registry.corp:443
bypassLoopback: true # true: loopback stays direct
exportEnv: true # set HTTP(S)_PROXY for children
Runtime Switching¶
- Web settings: Use the icon button at the bottom of the sidebar (above Settings) to switch modes.
- Hot reload: After modifying
cordis.patch.yml, the configuration takes effect automatically without restarting.
Notes¶
- Credential security: Proxy URLs with embedded usernames/passwords are stored in plaintext on disk and are only protected by file permissions. It is recommended to use unauthenticated proxies locally.
- Environment variable propagation: Credentials are propagated to the DSH process as
HTTP(S)_PROXYenvironment variables. Child processes (such as stdio MCP servers) can read these variables. - Request interruption: If a request has been running for approximately 30 seconds after a proxy switch, it will be interrupted.
- System mode limitations: System mode currently supports macOS only; Windows Registry, Linux desktop, and PAC are not supported.
- URL validity: Invalid URLs are not saved.
Summary¶
dsh-proxy provides proxy control for DSH’s global outbound traffic, with hot reload and multiple modes. It is suitable for scenarios that require dynamically switching network environments during development or runtime.