Local-first control plane for managing multiple DSH runtimes, profiles, presets, sessions, plans, and knowledge references.
Install
# from a prebuilt release tarball
dsh plugin --profile web add "https://github.com/Harzva/dsh-control-plane/releases/latest/download/dsh-control-plane-0.1.0.tgz"
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:Harzva/dsh-control-plane
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Local-first developer control plane for composing, inspecting, and managing multiple DeepSeek Harness runtimes, profiles, presets, sessions, plans, and knowledge references.
Status
The repository has completed Stage 7 and published the first public release:
Harzva/dsh-control-plane,
v0.1.0.
The public release contains the contracts, allowlisted Runtime Manager MVP,
installable DSH Bundle, reference-only Plan/Artifact/Knowledge bridge, and
replaceable Scenario Adapters. Submission to awesome-dsh-plugin is the next
stage and is not claimed as merged or accepted.
The Web panels are read-only projections. Runtime start/stop and health behavior remains in the source Runtime Manager API. The Stage 4 bridge resolves only bounded metadata and opaque references; it does not read or upload document content.
Why this exists
Developers often use more than one DSH environment: an official runtime, a
team-customized runtime, a development fork, and different Agent Presets for
different workflows. dsh-control-plane provides a stable local control plane
so those environments can be discovered, composed, inspected, and recovered
without mixing their private files or session data.
The project does not replace DSH. It provides a control-plane core and a versioned DSH Bundle that can present the control plane inside DSH.
Planned capabilities
- Register official, customized, development, and custom DSH runtimes.
- Inspect Profile and Preset references without copying private configuration.
- Start, stop, and health-check runtimes through allowlisted adapters.
- Connect Sessions to plans, artifacts, and knowledge references.
- Provide an additive DSH Host/Client integration panel.
- Show bounded Runtime Catalog, Session Board, Plan Panel, Artifact Board, and Knowledge Reference projections in DSH Web.
- Use and extend replaceable scenario adapters, including an interview-learning example.
- Validate releases in an isolated DSH Profile before public publication.
Public safe-core
This repository contains public schemas, adapters, examples, tests, and documentation. It does not contain credentials, raw chats, real sessions, private knowledge, private machine paths, or production DSH configuration.
Machine-local values belong in the ignored agentworkos.local.toml. Public
examples use placeholders and synthetic identifiers.
Architecture and roadmap
- Vision
- Architecture
- Security policy
- Contribution guide
- Review protocol
- Stage 1 foundation contract
- Stage 2 Runtime Manager
- Stage 3 DSH Bundle and Client panels
- Stage 4 Plan / Knowledge Bridge
- Stage 5 Scenario Adapters
- Stage 6 Security and DeepSeek Pro Review
- Stage 7 Release Candidate
- Stage 8 awesome-dsh-plugin Submission
- Stage 9 Harzva Plugin Registry
- Long-term roadmap
DSH integration direction
The current target is DSH 0.1.0-rc.8. The root package provides a
dsh.bundle patch layer, a strict ./typert Host manifest, and one checked-in
./client bundle. Internal source modules are composed into this one
installable package so a tarball does not depend on sibling file: packages.
The Web contribution uses additive Settings Slots and local failure boundaries.
Development status
The Stage 1 contracts, Stage 2 Runtime Manager, Stage 4 reference bridge, and Stage 5 scenario adapters remain usable as source modules. Stage 3–5 are included in the public Bundle. Stage 6 security and review work and the Stage 7 public release gates are complete. Build and inspect the candidate with:
pnpm install --frozen-lockfile
pnpm run build:dsh
pnpm run check
pnpm run pack:dsh
pnpm run verify:release-candidate
Use an isolated DSH Profile for runtime checks. Do not install this directory or a locally configured Profile into a production workspace.
License
MIT. See LICENSE.
Links
More in this category
strukto-ai/mirage#dsh★ 3606
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 303
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
lire1131/dsh-undo-savepoint★ 144
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 115
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
kanneiren/dsh-network-settings★ 108
Visualize the DSH process network path on Windows or WSL with layered DNS/TCP/TLS/HTTP probes, detect stale proxy configuration, and apply snapshot-guarded repairs.
Jayden-X-L/forkprobe★ 71
Compare multiple skills on the same task and pick the winner.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.