dshbase

插件目录 / Developer / dsh-ssh-remote

dsh-ssh-remote

已验证 · 实测可装 CrazyShout

✓ 持续维护 基于 8 个官方 DSH 包 纯 TypeScript

查看 GitHub ↗ ← 返回插件目录

2Stars
0Forks
0未关闭 issue
TypeScript语言
2026-08-14最近推送
跨平台平台

功能简介

DeepSeek Harness的SSH远程工作区:浏览/读写远程文件

✅
我们的评价
可用 — 实测通过,早期项目

DeepSeek Harness的SSH远程工作区:浏览/读写远程文件 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

dsh-ssh-remote

English | 中文

SSH remote workspaces for DeepSeek Harness: let the agent connect to remote
hosts over SSH, browse/read/write remote files, run remote commands, open
remote terminals, and show connection status with colored dots in the
sidebar — in the spirit of Codex Remote.

Status: the Web UI, SSH directory picker, persisted remote workspaces,
transparent SFTP filesystem routing, and OpenSSH command/terminal routing
are implemented end to end.

Features

  • SSH connection management: ssh2 connection pool (one per host),
    keepalive, exponential-backoff auto-reconnect, connection state machine.
  • Remote file operations: SFTP implementation of the FileSystem twelve
    primitives (read/write/edit/list/stat) with DSH FS_* error-code alignment.
  • Remote commands: ssh_remote exec runs a shell command on the host.
  • Codex-style SSH discovery: concrete Host aliases are collected from
    ~/.ssh/config (including Include files), then effective HostName/User/
    Port/IdentityFile/ProxyJump/ProxyCommand values are resolved with ssh -G.
  • OpenSSH-owned configuration: the Web panel is read-only and never
    duplicates SSH credentials into DSH settings. Edit ~/.ssh/config, then
    press Refresh.
  • Native Add Workspace flow: choose an SSH alias, browse its directories,
    and open one as a normal Harness workspace.
  • Transparent workspace routing: read/write/edit and other filesystem
    calls use SFTP; bash and terminal processes use the system OpenSSH client.
    Local workspaces keep using the original local providers.
  • Connection status dots: green = connected, amber = connecting/
    reconnecting, red = disconnected/error.
  • Multiple hosts: workspace records persist to
    $DSH_HOME/ssh-remote-workspaces.json.

Install

Requires Node 22+, pnpm, DSH 0.1.0-rc.x.

# Option A: npm (once published)
dsh plugin --profile web add dsh-ssh-remote

# Option B: GitHub (no publish needed)
dsh plugin --profile web add 'github:CrazyShout/dsh-ssh-remote'

Restart dsh web afterwards.

Usage

In the Web UI:

  1. Click Add Workspace.
  2. Choose an SSH alias discovered from ~/.ssh/config.
  3. Browse to a remote directory and click Open this folder.
  4. Start a session in the resulting workspace. Use Full access so the
    local OpenSSH process can reach the remote host.

Harness still stores a local workspace path. The plugin creates a small local
anchor under $DSH_HOME/ssh-workspace-anchors/ and persists its exact mapping
in $DSH_HOME/ssh-workspace-anchors.json. Only that anchor and its descendants
are routed to the corresponding ssh://alias/path; unrelated local paths are
never intercepted.

The lower-level ssh_remote tool remains available for explicit operations:

The agent drives remote hosts through the ssh_remote tool:

ssh_remote { action: "add",    uri: "ssh://user@gpu-server:22/home/user/exp" }
ssh_remote { action: "connect", id: "<id>" }
ssh_remote { action: "exec",    id: "<id>", command: "nvidia-smi" }
ssh_remote { action: "read",    id: "<id>", path: "train.py" }
ssh_remote { action: "write",   id: "<id>", path: "notes.txt", content: "..." }
ssh_remote { action: "list" }

path accepts a remote absolute path (/home/user/exp/a.py) or a
workspace-relative path (a.py).

Authentication

  • Prefers the local ssh-agent (SSH_AUTH_SOCK).
  • Tries effective IdentityFile entries returned by OpenSSH in order.
  • ProxyJump (including multiple hops) and ProxyCommand streams are opened
    by the system OpenSSH client, keeping its Include/wildcard/Match semantics.
  • The remote must enable the sftp subsystem
    (Subsystem sftp internal-sftp).

SSH configuration

Add a concrete alias to ~/.ssh/config, verify ssh devbox, then refresh the
SSH Remote plugin panel:

Host devbox
  HostName devbox.example.com
  User you
  IdentityFile ~/.ssh/id_ed25519
  ProxyJump bastion

Register a workspace with the alias, not duplicated connection fields:

ssh_remote { action: "add", uri: "ssh://devbox/home/you/project" }

Older ssh-remote.hosts entries remain a read-only compatibility fallback,
but new configuration should live only in OpenSSH config.

Routing and security boundary

  • File traffic is handled by SFTP; commands and terminals are launched through
    the system ssh executable, so SSH aliases, Include, Match,
    ProxyJump, agent forwarding, and host-key policy stay owned by OpenSSH.
  • Routing is exact and boundary-aware: an anchor /a/project matches itself
    and /a/project/..., but never /a/project-copy.
  • Creating a workspace does not copy or mount the remote tree locally. The
    local anchor contains no remote source files.

Roadmap

  • DSH Credentials integration and configurable remote-path read policies.

Development

pnpm install
pnpm run build   # tsc for host + client
pnpm test

lib/ is committed to git so a git install never ships without built code.

License

MIT

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-ssh-remote」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:CrazyShout/dsh-ssh-remote

Headless(CLI)profile:

dsh plugin --profile headless add github:CrazyShout/dsh-ssh-remote

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。

适合谁

想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。

二次开发建议

工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7797 个插件 →