插件目录 / Network / dsh-remote-acces
dsh-remote-acces
已验证 · 实测可装 wuwuzhige-sudo
功能简介
一键设置密码保护的远程访问
可用 — 实测通过,早期项目
一键设置密码保护的远程访问 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-remote-access
One-command setup for password-protected remote access to the DeepSeek Harness (dsh) web UI — the same production setup used by the author on their own tailnet.
dsh web binds to 127.0.0.1 only, and a hardcoded set of privileged methods (settings.*, credentials.*, agentPreset.*, llm.discoverModels, …) is loopback-only by design ("until a real authentication layer exists"). This project makes remote full-featured access practical today:
browser → TLS (Tailscale Serve / reverse proxy) → Caddy (password auth) → dsh (loopback)
What the script does
- Patches the dsh privileged-methods fence (one line) so trusted hosts are allowed instead of loopback-only. Idempotent, keeps a
.bakbackup. - Installs the official Caddy (apt or direct binary download;
GH_PROXYmirror variable supported for CN networks) and writes a Caddyfile with bcrypt basic auth that reverse-proxies to the loopback dsh server. - Installs a systemd user service for the auth proxy (auto-start, crash-restart, journald logs).
- Prints the Tailscale Serve command and access URL.
Quickstart
git clone https://github.com/wuwuzhige-sudo/dsh-remote-access
cd dsh-remote-access
./scripts/setup-remote-access.sh \
--password 'choose-a-strong-password' \
--user dsh \
--trusted-host myhost.tailXXXX.ts.net # your Tailscale DNS name
# then:
sudo tailscale serve --bg 3081
systemctl --user restart dsh-web
Open https://<machine-name>.<tailnet>.ts.net — a password prompt appears, and the full dsh UI (settings, agent presets, credentials, model discovery included) works remotely.
If
dsh webruns through a reverse proxy / Tailscale Serve, the browser origin is a real hostname, so the dsh server must be started withdsh web --trusted-host <hostname>(and the same value passed to the script via--trusted-host).
Options
| Flag | Default | Meaning |
|---|---|---|
--password <pw> |
— | password for the auth layer (required) |
--user <name> |
dsh |
auth username |
--dsh-port <port> |
3080 |
dsh web listen port |
--caddy-port <port> |
3081 |
auth proxy listen port |
--trusted-host <h> |
— | repeatable; hostnames allowed to drive dsh |
--dry-run |
off | print actions without changing anything |
--skip-patch |
off | do not touch the dsh core patch |
--skip-caddy |
off | assume caddy is already installed |
GH_PROXY (env) |
— | mirror prefix for the caddy download, e.g. https://ghfast.top/ |
Why not a plugin?
Two of the three moving parts cannot live inside the dsh plugin system:
- Caddy is a separate process (a reverse proxy) — dsh plugins only run inside the dsh process.
- The privileged-methods fence is hardcoded in
dsh-client-connection(a module-private closure); a plugin cannot bypass it from the outside, and the webserver route registry does not allow intercepting/apiahead of the built-in route.
The --trusted-host flag itself is official dsh functionality. This script simply assembles the pieces.
Security
⚠️ The dsh web UI can execute arbitrary commands on the host. Anyone with the password can drive it.
- The dsh server must stay bound to loopback — the Caddy proxy is the only public entry.
- The password is stored as a bcrypt hash only (in
~/.local/share/dsh-remote-access/Caddyfile). - Use a strong, unique password. Over Tailscale the traffic is encrypted end-to-end and constrained to your tailnet.
- This is a stopgap: the dsh project plans a real authentication layer. When it ships, drop the patch + proxy and use the official auth.
Uninstall
systemctl --user disable --now dsh-caddy
sudo tailscale serve --https 443 off
rm -f ~/.config/systemd/user/dsh-caddy.service ~/.local/share/dsh-remote-access/Caddyfile
# restore the dsh patch (see the .bak path printed during setup)
mv <dsh-client-connection>/lib/index.js.bak <dsh-client-connection>/lib/index.js
License
MIT
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-remote-acces」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:wuwuzhige-sudo/dsh-remote-acces Headless(CLI)profile:
dsh plugin --profile headless add github:wuwuzhige-sudo/dsh-remote-acces 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
给 agent 网络能力——请求、API、代理或协议——让它能触达外部系统。
适合谁
任务涉及网络的人——调 API、抓资源或与远端服务通信。
二次开发建议
适配器和请求整形是缝——加协议、鉴权处理器、重试和端点抽象。