Introduction

DeepSeek Harness (DSH) uses a plugin-based architecture. MCP Servers developed locally typically run on a developer’s machine, making them inaccessible to remote Agents (such as those running in the cloud or other network environments). Exposing local ports directly creates security risks and is cumbersome to configure.

The dsh-mcp-tunnel plugin establishes an outbound tunnel for a local MCP Server by building a Docker Compose stack (including mcp-proxy and cloudflared). It maps the local service to a publicly accessible HTTPS URL and outputs a configuration snippet to dsh-mcp-client, enabling remote Agents to invoke local tools seamlessly.

Plugin Overview

  • Name: dsh-mcp-tunnel
  • Type: DSH plugin(networking tool)
  • Maintainer: 988hj7tczd-oss
  • License: MIT

Core Features

The plugin mainly provides the following capabilities:
1. Stack generation: Automatically generates a Docker Compose stack that includes mcp-proxy (authentication and forwarding) and cloudflared (outbound tunnel).
2. Secure tunnel: Establishes outbound connections only; no inbound ports are exposed to the public internet. The host binds only the 127.0.0.1 loopback port.
3. Certificate management: Automatically generates and manages self-signed CA and server certificates.
4. CLI tool: Provides create, status, and stop commands to manage the tunnel lifecycle.
5. Configuration assistance: Generates a pending mcp-client configuration snippet and does not automatically modify the host Profile.

Installation

Install it as a Bundle into your DSH Profile:

cd <你的 DSH profile>
pnpm add ./dsh-mcp-tunnel

Usage

Start the tunnel using the CLI tool mcp_tunnel_create.

mcp_tunnel_create name=<name> serverDir=<dir> provider=cloudflare-quick

Parameters:
* name: Tunnel name. It is also used as the Compose project name and the serverName for mcp-client.
* serverDir: MCP Server directory. The url field in .mcp.json is prioritized as the upstream.
* provider: Tunnel provider. Defaults to cloudflare-quick (no account required). Production environments require a self-managed authentication layer.
* token: Access token. By default, it is automatically generated and written to .env (permissions 0600).
* deployDir: Deployment directory. Defaults to ~/.dsh/mcp-tunnels/<name>.

After running, it automatically:
1. Checks the Docker environment.
2. Starts the container stack.
3. Obtains and outputs the public URL.
4. Generates the configuration snippet file.

mcp-client Configuration

The plugin does not automatically modify your Profile configuration. It generates an mcp-client.pending.yml file in the deployment directory. You need to manually add its contents to cordis.patch.yml.

Configuration snippet example:

- insert:
    - id: mcp-<serverName>
      name: '@deepseek-ai/dsh-mcp-client'
      config:
        serverName: <name>
        transport: streamable-http
        url: <https://xxx.trycloudflare.com>
        headers:
          Authorization: 'Bearer <token>'
        toolCallTimeoutMs: 60000
        failOnStartupError: false

Notes

  1. Prerequisites: In development mode, the project depends on an adjacent dsh-src directory (referenced via link:). You must check it out and run pnpm install && pnpm run build.
  2. Stdio limitation: The plugin does not include a built-in bridge to convert command-based stdio MCP Servers to HTTP. If the server is stdio-based, you must first convert it to an HTTP endpoint.
  3. Security model:
    • The default Cloudflare Quick Tunnel is suitable for testing only. Production traffic must add your own authentication layer (for example, a Bearer Token).
    • All sensitive information (such as tokens) is stored in the .env file in the deployment directory (permissions 0600) and is not placed in the Docker Compose file.
  4. Container dependencies: Inter-container health checks rely on the service_started event rather than probes included in the image.

Conclusion

dsh-mcp-tunnel provides a low-risk solution for exposing local services and isolates complex network configuration through a Docker stack. Together with dsh-mcp-client, developers can conveniently expose local tool capabilities to remote agents.