DeepSeek Harness Plugin

Harzva/dsh-control-plane

Category Development & Runtime Added 2026-09-05

Local-first control plane for managing multiple DSH runtimes, profiles, presets, sessions, plans, and knowledge references.

Install

# from a prebuilt release tarball

dsh plugin --profile web add "https://github.com/Harzva/dsh-control-plane/releases/latest/download/dsh-control-plane-0.1.0.tgz"

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:Harzva/dsh-control-plane

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

Local-first developer control plane for composing, inspecting, and managing multiple DeepSeek Harness runtimes, profiles, presets, sessions, plans, and knowledge references.

Status

The repository has completed Stage 7 and published the first public release: Harzva/dsh-control-plane, v0.1.0. The public release contains the contracts, allowlisted Runtime Manager MVP, installable DSH Bundle, reference-only Plan/Artifact/Knowledge bridge, and replaceable Scenario Adapters. Submission to awesome-dsh-plugin is the next stage and is not claimed as merged or accepted.

The Web panels are read-only projections. Runtime start/stop and health behavior remains in the source Runtime Manager API. The Stage 4 bridge resolves only bounded metadata and opaque references; it does not read or upload document content.

Why this exists

Developers often use more than one DSH environment: an official runtime, a team-customized runtime, a development fork, and different Agent Presets for different workflows. dsh-control-plane provides a stable local control plane so those environments can be discovered, composed, inspected, and recovered without mixing their private files or session data.

The project does not replace DSH. It provides a control-plane core and a versioned DSH Bundle that can present the control plane inside DSH.

Planned capabilities

  • Register official, customized, development, and custom DSH runtimes.
  • Inspect Profile and Preset references without copying private configuration.
  • Start, stop, and health-check runtimes through allowlisted adapters.
  • Connect Sessions to plans, artifacts, and knowledge references.
  • Provide an additive DSH Host/Client integration panel.
  • Show bounded Runtime Catalog, Session Board, Plan Panel, Artifact Board, and Knowledge Reference projections in DSH Web.
  • Use and extend replaceable scenario adapters, including an interview-learning example.
  • Validate releases in an isolated DSH Profile before public publication.

Public safe-core

This repository contains public schemas, adapters, examples, tests, and documentation. It does not contain credentials, raw chats, real sessions, private knowledge, private machine paths, or production DSH configuration.

Machine-local values belong in the ignored agentworkos.local.toml. Public examples use placeholders and synthetic identifiers.

Architecture and roadmap

DSH integration direction

The current target is DSH 0.1.0-rc.8. The root package provides a dsh.bundle patch layer, a strict ./typert Host manifest, and one checked-in ./client bundle. Internal source modules are composed into this one installable package so a tarball does not depend on sibling file: packages. The Web contribution uses additive Settings Slots and local failure boundaries.

Development status

The Stage 1 contracts, Stage 2 Runtime Manager, Stage 4 reference bridge, and Stage 5 scenario adapters remain usable as source modules. Stage 3–5 are included in the public Bundle. Stage 6 security and review work and the Stage 7 public release gates are complete. Build and inspect the candidate with:

pnpm install --frozen-lockfile
pnpm run build:dsh
pnpm run check
pnpm run pack:dsh
pnpm run verify:release-candidate

Use an isolated DSH Profile for runtime checks. Do not install this directory or a locally configured Profile into a production workspace.

License

MIT. See LICENSE.

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.