Introduction

In DeepSeek Harness (DSH), proxy configuration typically requires modifying configuration files and restarting the process. The dsh-proxy plugin solves this problem by taking over global fetch calls, allowing hot reloading of HTTP(S)/SOCKS5 routing via Web settings or configuration files without restarting DSH.

Plugin Introduction

tr1v3r/dsh-proxy is a DSH plugin for routing all in-process outbound requests (LLM providers, web_search, streamable-http MCP).
- Maintainer: tr1v3r
- Category: Network tools
- License: MIT

Core Features

  • Global routing: Intercepts all in-process outbound requests and forwards them through HTTP(S) CONNECT or SOCKS5 proxies.
  • Runtime switching: Switch between direct, follow-system, and manual proxy modes without restarting.
  • Protocol support: Supports HTTP(S) and SOCKS5.
  • Bypass rules: Supports noProxy rules (undici-style matchers).
  • Subprocess environment variables: Supports exporting proxy environment variables to subprocesses (exportEnv: true).
  • System proxy detection: Supports detecting proxy settings from macOS System Settings (system mode).
  • Loopback bypass: Local loopback addresses are skipped by default.

Installation and Activation

The plugin is installed via npm. Run the following command in the target configuration profile directory:

dsh plugin --profile <name> install --no-frozen-lockfile

Configuration and Usage

Via Web Settings

  1. Open the DSH Web interface.
  2. Go to Settings → General → Network proxy.
  3. Select a mode from the dropdown: Direct, Follow system, or Manual.
  4. In Manual mode, enter the proxy address and bypass list. Text fields save on blur.

Via Configuration File

Edit ~/.config/dsh/profiles/<name>/cordis.patch.yml.

- id: dsh-proxy
  config:
    mode: manual                       # direct | system | manual
    proxy: socks5://127.0.0.1:1080     # http://…, https://…, socks5://…
    noProxy:                           # optional bypass list
      - localhost
      - .internal.example
      - registry.corp:443
    bypassLoopback: true               # true: loopback stays direct
    exportEnv: true                    # set HTTP(S)_PROXY for children

Runtime Switching

  • Web settings: Use the icon button at the bottom of the sidebar (above Settings) to switch modes.
  • Hot reload: After modifying cordis.patch.yml, the configuration takes effect automatically without restarting.

Notes

  • Credential security: Proxy URLs with embedded usernames/passwords are stored in plaintext on disk and are only protected by file permissions. It is recommended to use unauthenticated proxies locally.
  • Environment variable propagation: Credentials are propagated to the DSH process as HTTP(S)_PROXY environment variables. Child processes (such as stdio MCP servers) can read these variables.
  • Request interruption: If a request has been running for approximately 30 seconds after a proxy switch, it will be interrupted.
  • System mode limitations: System mode currently supports macOS only; Windows Registry, Linux desktop, and PAC are not supported.
  • URL validity: Invalid URLs are not saved.

Summary

dsh-proxy provides proxy control for DSH’s global outbound traffic, with hot reload and multiple modes. It is suitable for scenarios that require dynamically switching network environments during development or runtime.