dshbase

插件目录 / Developer / dsh-docker

dsh-docker

已验证 · 实测可装 devLythen

✓ 持续维护 基于 1 个官方 DSH 包

查看 GitHub ↗ ← 返回插件目录

3Stars
0Forks
0未关闭 issue
JavaScript语言
2026-08-14最近推送
跨平台平台

功能简介

DeepSeek Harness的Docker镜像,支持自托管部署

✅
我们的评价
可用 — 实测通过,早期项目

DeepSeek Harness的Docker镜像,支持自托管部署 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

dsh-docker

Docker template for running the DeepSeek Harness Web UI. 简体中文

Quickstart

cp .env.example .env
docker compose up -d

Configure the provider URL, credentials, and model through the Web UI. Public deployments require the Nginx session login (24-hour expiry by default) before this configuration is available.

Open http://localhost:3080.

Stop the service with:

docker compose down

Local data and live configuration

  • config/ is mounted at /dsh-home and stores Harness state and user configuration.
  • workspace/ is mounted at /home/node (the Web UI's default workspace location); set DSH_WORKSPACE in .env to mount a custom host directory instead.
  • dsh plugin manages profile plugins through pnpm (bundled in the image), e.g. docker compose exec dsh dsh plugin --profile web add <package>.

Configure provider settings after startup through the Web UI. Public deployments require the Nginx session login first. DSH watches user configuration and credential files under config/; changes apply to subsequent requests without restarting the container. .env contains Compose-only settings such as the host port and Nginx trusted host.

Ports

Only two host ports are ever published, both defined once in .env:

DSH_PORT=3080   # DSH Web UI, published on host 127.0.0.1
AUTH_PORT=8081  # login/session service, published on host 127.0.0.1
  • The Compose publish mapping and DSH's trust fence (--trusted-host) both read DSH_PORT automatically; no other file needs editing.
  • Container-internal ports are private constants that are never published and can be ignored when changing ports: socat 3080 → dsh web 3081 inside the DSH container, 8081 inside the auth container.
  • Nginx is the only host-side file to sync. Its port literals are centralized in the constants block at the top of nginx/dsh.conf.example (two set lines mirroring .env); or let .env stay the single source of truth by rendering:
./scripts/render-nginx-conf.sh | sudo tee /etc/nginx/sites-available/dsh.conf

Port-change procedure: edit .env → docker compose up -d → re-render (or sync the constants block) → sudo nginx -t && sudo systemctl reload nginx.

Public deployment

Public deployment requires a DNS record, a TLS certificate, Nginx, and an authenticated reverse proxy. Do not expose the Docker port directly to the Internet.

Public authentication uses a login service plus session cookies: Nginx validates every request's session cookie with an internal auth_request subrequest and redirects invalid or expired sessions to the /login/ page. Sessions expire after 24 hours by default; restarting the auth service invalidates every session immediately.

Set the public authority and the login password in .env:

DSH_PORT=3080
DSH_TRUSTED_HOST=dsh.example.com
AUTH_PASSWORD=<strong random password>
# AUTH_TTL_HOURS=24

Generate a password:

openssl rand -base64 24 | tr '+/' '-_' | tr -d '='

Start DSH and the login service, and keep the host ports bound to localhost:

docker compose up -d --build

Use nginx/dsh.conf.example as the reverse-proxy starting point (ports — see “Ports” above), then set its server_name, TLS certificate paths, and HTTPS listener, and reload Nginx:

sudo nginx -t
sudo systemctl reload nginx

Authentication behavior

  • The first request to any page redirects to /login/; enter AUTH_PASSWORD from .env.
  • A successful login sets a dsh_session cookie (HttpOnly + SameSite=Lax, plus Secure over HTTPS) that expires after AUTH_TTL_HOURS (default 24); afterwards the user is sent back to the login page.
  • Sessions live in the auth container's memory: docker compose restart auth (or rebooting the host) logs everyone out immediately.
  • 5 consecutive wrong passwords lock that source IP for 15 minutes.

The public URL is then https://dsh.example.com.

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-docker」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:devLythen/dsh-docker

Headless(CLI)profile:

dsh plugin --profile headless add github:devLythen/dsh-docker

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。

适合谁

想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。

二次开发建议

工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7797 个插件 →