When handling deployment rollbacks in a DeepSeek Harness (DSH) environment, developers often need to verify that all targets have actually stopped serving the failed version and have returned to the previous known-good state. This typically involves inspecting live infrastructure or performing rollback actions. To avoid the uncertainty of relying on live observation or the side effects of executing actual rollbacks, you can use the dsh-deployment-rollback-proof plugin.
What It Is¶
The plugin is maintained by dongsheng123132 and is designed to generate offline, deterministic evidence. It does not perform rollbacks or observe live infrastructure; instead, it verifies an explicit, hash-only manifest to prove that each declared deployment target stops serving a failed artifact and converges to the same final known-good digest within the RTO (recovery time objective).
Core Features¶
The plugin focuses on manifest validation. Its main capabilities include:
- Validating explicit, hash-only manifests.
- Checking exact target coverage and consecutive observation sequences.
- Checking minimum distinct observers.
- Checking environment binding and the final known-good digest across all targets.
- Verifying zero active failed artifact replicas and exact known-good replica convergence.
- Checking event/schedule binding, temporal ordering, RTO, and evidence freshness.
- Rejecting reports that contain sensitive keys.
- Generating a machine-readable settlement verdict.
Installation and Enablement¶
DSH installs the package from cordis.patch.yml. Before use, ensure the environment meets the following requirements:
- Node.js 22 or later.
- DSH version 0.1.2-alpha.4 or later.
Typical Usage¶
The plugin provides a command-line tool and DSH integration interfaces.
Command-line usage examples:
# 使用 inspect 进行检查
node bin/dsh-deployment-rollback-proof.mjs inspect examples/rolled-back.
# 使用 verify 进行验证
node bin/dsh-deployment-rollback-proof.mjs verify examples/rolled-back.
DSH integration:
The plugin exposes the dsh_deployment_rollback_inspect and dsh_deployment_rollback_verify interfaces.
MCP server mode:
The plugin also provides a standalone stdio MCP server that exposes the deployment_rollback_inspect and deployment_rollback_verify interfaces.
Applicability and Cautions¶
- Offline operation: The plugin works offline only. It does not perform rollbacks, authenticate receipts, grant authorizations, observe live infrastructure, or prove application correctness.
- Manifest validation only: It validates explicit, hash-only manifests only.
- Security: Rejects path traversal and symbolic links, creates content-addressed reports, and rejects reports containing sensitive keys (such as keys named
secret,authorization,raw,body,content,log,prompt, orchat). - License: MIT license.