Authenticated LAN, Tailnet, and public HTTPS access for a DSH Host, with persistent host identity, pairing, and QR setup.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-network
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:baixianger/dsh-network
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
DSH Network
Reach your DeepSeek Harness host from your LAN, Tailnet, or an existing HTTPS endpoint. Pair a client once and keep multiple routes attached to the same host identity.
One host, several ways to connect
| Route | Address | Setup |
|---|---|---|
| LAN | A reachable local gateway address | Choose LAN and scan the pairing QR. |
| Tailnet | A Tailscale Serve MagicDNS HTTPS URL | Choose Tailscale on an already signed-in host. |
| Custom HTTPS | Your working reverse-proxy URL | Supply the address when creating the QR. |
DSH stays on loopback. The plugin puts an authenticated gateway in front of it, with short-lived pairing tickets, rotating device credentials, and a persistent host ID.
Quick start
dsh plugin --profile web add dsh-network@latest
dsh web
Open Settings → Network to see the host and create a pairing QR, or use the setup assistant in another terminal:
dsh plugin --profile web exec dsh-network setup
Choose LAN, Tailscale, or Custom address. The assistant asks when no mode is supplied. Scan the result with a compatible client.
The default gateway listens on port 3081. DSH's underlying Web server remains bound to loopback at its configured port.
Choose your route
# LAN: both devices must be able to reach each other
dsh plugin --profile web exec dsh-network setup lan
# Tailnet: requires Tailscale already installed and signed in
dsh plugin --profile web exec dsh-network setup tailscale
# A working HTTPS gateway you already operate
dsh plugin --profile web exec dsh-network setup custom --url https://dsh.example.com
Use --url http://HOST:3081 if LAN detection selects the wrong interface. Tailscale setup configures Serve to forward to the authenticated gateway. A custom public route must already provide trusted HTTPS and HTTP/WebSocket forwarding; this plugin does not configure DNS, certificates, firewalls, or a reverse proxy.
Settings that explain the current state
The Network page groups host identity and device pairing separately, with labelled inputs, pending states, and inline errors. It follows DSH's English/Chinese locale and light/dark theme. Pending settings requests stop when the panel unmounts.
An optional iosAppDownloadURL displays a dismissible app-download card when configured with a valid HTTPS URL. Without one, the card stays hidden.
Configuration
| Field | Default | Purpose |
|---|---|---|
gatewayPort |
3081 |
Authenticated gateway port. |
bindHost |
0.0.0.0 |
Gateway interfaces; 127.0.0.1 limits it to loopback. |
hostName |
System hostname | Host display name. |
statePath |
$DSH_HOME/network/state.json |
Pairing and device state. |
historyChunkTrim |
true |
Remove redundant settled streaming chunks from history responses. |
historyTrustedHosts |
[] |
Additional allowed direct-Web Host values for history routes. |
iosAppDownloadURL |
Unset | App Store or TestFlight HTTPS URL for the optional card. |
DSH_HOME defaults to ~/.dsh. History trimming preserves rendered messages, first-token timing, and current partial output while reducing redundant deltas; savings depend on the session. Its routes retain the host's origin and cross-site checks.
Pairing & credentials
Pairing tickets are single-use and expire after five minutes. A paired client receives a refresh credential and a one-hour access token; refresh rotates both. The host stores hashes, not the original credentials. Pairing links are generated on demand rather than broadcast.
LAN HTTP relies on a trusted local network. For a public route, expose the authenticated gateway through HTTPS, not the underlying DSH Web port. See public deployment boundaries.
Troubleshooting
| Symptom | Check |
|---|---|
| LAN address does not open | Device reachability, private-interface firewall rules, and the selected IP. |
| Tailscale setup fails | tailscale status and the host's existing sign-in. |
| Public route fails | Trusted TLS and both HTTP/WebSocket reverse-proxy forwarding. |
| Pairing QR expired | Generate a new single-use ticket. |
Full device listing and revocation controls in settings remain future work; the current panel exposes host status, paired-device count, and pairing.
Development & feedback
npm ci
npm run check
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 8598
Remote control of a dsh web workspace from phone or PC: QR-code pairing through a token-gated channel, SSE real-time sync, and separate mobile and full desktop GUI modes.
zhu1090093659/dsh-web#packages/dsh-ssh★ 8598
SSH ops panel for DSH: web terminal, SFTP transfer with progress, local port forwarding, and one-command cluster execution across hosts; agents share the same host config.
saya-ch/dsh-mobile★ 421
Access DeepSeek Harness from the Android app or a mobile browser with secure LAN and remote connections, persistent device pairing, and a customizable mobile interface.
ZSeven-W/dsh-ios★ 317
A live iOS Simulator or USB-connected iPhone inside the conversation: 22 agent tools for booting, building, driving the UI by accessibility identity or OCR text, list-row actions and SwiftUI preview hot reload, plus a streaming sidebar panel you can tap and drag on.
liguobao/ds-harness-remote★ 307
Multi-device remote access for DeepSeek Harness: continue an active session from your phone, tablet, browser, or another computer over an end-to-end encrypted channel (Noise IK + adaptive relay/WebRTC transport), with device authorization, ApiProxy-only remote capabilities, and read-only file preview via dsh-file-viewer — no shell, remote desktop, or write access.
wenbin-wb/dsh-bridge★ 191
Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.