插件目录 / Knowledge / dsh-multi-tenant
dsh-multi-tenant
已验证 · 实测可装 GuoMonth
功能简介
DSH 多租户 SaaS 扩展:租户身份、会话隔离、授权、审计
可用 — 实测通过,早期项目
DSH 多租户 SaaS 扩展:租户身份、会话隔离、授权、审计 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-multi-tenant
OIDC, membership authorization and native DSH access, with a Kubernetes AgentEnvironment for each user. The current tested runtime implements that workspace as a Cell from dsh-isolated-runtime.
Cell MVP alpha. Two-user and real-model regression passed. 0.9.0-alpha.1 uses npm latest, a default installation channel, not a stability promise. Breaking changes are allowed; historical compatibility, upgrades and seamless recovery are not promised.
Fixed release boundary
DSH is exactly 0.1.5-rc.2, source fb2c4b9e698e30edb738bca4cf0618587db7d203. Each release locks the publicly pullable Cell and Operator images by @sha256 digest, with matching runtime source and DSH identity in cell-release.json (platform) / release.json (runtime). Pin the deployed platform image by digest too. npm latest selects a package at installation; it does not authorize moving image tags or a DSH version range at runtime.
Breaking updates are allowed: publish a new explicit combination, update configuration/state expectations as needed and validate the affected flow. No compatibility shim, historical upgrade or migration promise is required. Published artifact identities stay immutable. The public runtime pair is locked to v0.3.0-alpha.1, Linux/amd64. Exact digests are in the release manifest. Null digests block publication.
Start
An administrator first configures Kubernetes, the platform-mode Cell Operator, OIDC, DNS/TLS, storage and permissions. The platform needs direct Kubernetes API and Cell Pod-IP connectivity; run it in the cluster. Running npx on an ordinary host does not provide cluster networking.
Runtime setup: npx [email protected] manifests prints the pinned Operator/CRD/RBAC YAML for administrator review and deployment. Its release command prints the fixed Cell image and DSH version. This replaces the old standalone launcher; the runtime npm package does not run a second user-facing server.
# Node.js 24+
npx dsh-multi-tenant@latest start --config /private/config.json
The command runs in the foreground. SIGINT/SIGTERM stop the platform and retain Cells/data; SIGHUP reloads membership. Record the resolved exact npm version and image digests for deployment; do not resolve latest on every restart. This release does not create kind clusters.
See the alpha startup guide for existing-cluster deployment, configuration and administrative commands.
Unpublished cell-mvp-v1 source candidate
This branch targets [email protected]; it is not published. Published 0.9.0-alpha.1 and npm @latest retain the calibrated-profile configuration above and do not accept the candidate schema. The Connector is bound to runtime source ed914317e98a93752e8af4f7831c384fc1e92f13; Cell and Operator image digests remain null because these local candidate images are not a public release. See the candidate setup guide. DSH remains pinned to 0.1.5-rc.2.
The local candidate passed MVP internal acceptance on 2026-09-22, including native Bash subprocesses and deployment without calibration; this does not publish the candidate.
Ownership
The current request path is Envoy TLS/routing → platform openid-client OIDC and admission → Node Connector → Go launcher → DSH. Envoy does not perform platform login or tenant authorization.
| Component | Owns | Does not own |
|---|---|---|
dsh-multi-tenant |
OIDC, trusted membership, user protocols, parent/child sessions, durable allocation intent, authorized proxy | Pod/PVC controllers or runtime image builds |
dsh-isolated-runtime |
Current Cell Operator/images, resource identity/lifecycle, restricted Connector | User login, membership or platform sessions |
| DSH | Native Web, application sessions, tools and model calls | Platform tenant authorization |
AgentEnvironment direction
Kubernetes is the runtime direction; Process and Docker runtime backends are not planned as supported alternatives. AgentEnvironment is the product concept. The local integration trial selected upstream agent-sandbox core: W1 will map the product directly to Sandbox, without a second CRD or controller. The existing Cell implementation and legacy provider source have not yet been removed; that cleanup is planned for W1. This design is not implemented by the current candidate. See AgentEnvironment design and Issue #104.
One AgentEnvironment is the user's persistent DSH environment and is intended to contain multiple DSH conversations sharing that workspace. The currently tested Cell preserves its workspace data and native DSH state across Pod replacement. This demonstrates Cell-level persistence; it does not establish session-level isolation for home files or OAuth/CLI credentials.
The current release remains limited to one cluster, one platform replica and a fixed version combination; it does not add HA or a recovery system.
Real alpha test
Captured from the 2026-09-20 OIDC → Cell → native DSH session. deepseek-flash wrote/read a file and read an uploaded attachment. This is DSH's native UI; model credentials are not supplied by this project.


The regression report distinguishes cluster, local socket and fixture evidence. The release record and startup guide describe the published package and its limits.
Historical Process/Docker SDK and workbench material is outside the current Cell installation path and remains only as historical source/evidence. MIT; bundled dependencies retain their licenses in THIRD_PARTY_NOTICES.
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-multi-tenant」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:GuoMonth/dsh-multi-tenant Headless(CLI)profile:
dsh plugin --profile headless add github:GuoMonth/dsh-multi-tenant 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
给 agent 一套记忆、知识库或检索层,让它不再跨会话丢上下文。
适合谁
跑长项目、想让 agent 记住决策、文档和偏好而不用每次重讲的人。
二次开发建议
记忆/检索后端是缝——插新存储、调蒸馏策略,或加引用与审计轨迹。