Trusted Iroh mesh networking for DSH hosts, with encrypted peer discovery, remote session delivery, and reachability status.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-weave
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:baixianger/dsh-weave
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
DSH Weave
Connect explicitly trusted DeepSeek Harness hosts through Iroh. Keep pairing, peer identity, reachability, and the remote session directory in one transport layer.
What you get
| Capability | Behavior |
|---|---|
| Persistent identity | The same host identity survives restarts. |
| Explicit pairing | Exchange endpoint tickets and trust each peer locally. |
| Encrypted transport | Iroh provides QUIC connections, direct paths, and relay fallback. |
| Remote directory | Discover workspaces and sessions on paired hosts. |
| Visible state | Host reachability is separate from agent idle/running/offline state. |
| Native settings | Grouped identity and pairing controls, copy feedback, and removal confirmation. |
Quick start
On each host:
dsh plugin --profile web add dsh-weave@latest
dsh web
- Open Settings → Weave on both hosts.
- Exchange their tickets through a channel you trust.
- Add and explicitly trust the other host's ticket on each side.
- Use a higher-level plugin such as DSH Chat to select remote sessions.
Add DSH Bridge when messages should reach local agents on a receiving host. Bridge is optional for transport startup.
One transport, separate responsibilities
flowchart LR
A[Host A · Bridge] --> WA[Weave]
WA <-->|Iroh · QUIC| WB[Weave]
WB --> B[Host B · Bridge]
Iroh owns encrypted connectivity. Weave owns host trust, endpoint refresh, reachability, and authenticated requests. Chat owns rooms, membership, and room capabilities. Knowing a ticket alone does not grant trust or agent access.
Configuration
| Field | Default | Purpose |
|---|---|---|
hostName |
System hostname | Display label for the host. |
relayMode |
default |
Iroh default relay selection, or disabled. |
persistIdentity / persistPeers |
true |
Keep identity and trusted peers across restarts. |
acknowledgementTimeoutMs |
10000 |
Default acknowledgement deadline. |
maxConcurrentInbound |
64 |
Bound concurrent incoming requests. |
shutdownTimeoutMs |
1000 |
Bound transport shutdown. |
Identity and trusted peers are stored under $DSH_HOME/dsh-weave (~/.dsh by default), with owner-only permissions. identityPath and peersPath can override their locations.
Cancellation & delivery
Outbound requests accept a cancellation signal. Cancellation closes their connection; the receiving listener is also notified when the peer disconnects. Cancelling a request does not mark an otherwise reachable host offline. Chat's longer polling requests use matching acknowledgement deadlines.
The current release is a transport MVP. It provides pairing, directory access, and authenticated request delivery. A general remote task approval workflow and durable transport outbox/reconnect replay are not implemented. Application-level persistence belongs to the consuming plugin.
Protocol & architecture
Architecture · Protocol · Security · Room authority
The design documents include planned capabilities; use this README and the release notes for current behavior.
Development & feedback
npm ci
npm run check
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 8296
Remote control of a dsh web workspace from phone or PC: QR-code pairing through a token-gated channel, SSE real-time sync, and separate mobile and full desktop GUI modes.
zhu1090093659/dsh-web#packages/dsh-ssh★ 8296
SSH ops panel for DSH: web terminal, SFTP transfer with progress, local port forwarding, and one-command cluster execution across hosts; agents share the same host config.
saya-ch/dsh-mobile★ 356
Access DeepSeek Harness from the Android app or a mobile browser with secure LAN and remote connections, persistent device pairing, and a customizable mobile interface.
ZSeven-W/dsh-ios★ 309
A live iOS Simulator or USB-connected iPhone inside the conversation: 22 agent tools for booting, building, driving the UI by accessibility identity or OCR text, list-row actions and SwiftUI preview hot reload, plus a streaming sidebar panel you can tap and drag on.
liguobao/ds-harness-remote★ 254
Multi-device remote access for DeepSeek Harness: continue an active session from your phone, tablet, browser, or another computer over an end-to-end encrypted channel (Noise IK + adaptive relay/WebRTC transport), with device authorization, ApiProxy-only remote capabilities, and read-only file preview via dsh-file-viewer — no shell, remote desktop, or write access.
wenbin-wb/dsh-bridge★ 181
Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.