AgentsDanceAI/deepseek-harness-cloud
Accounts, credits and cloud agent workspaces for DeepSeek Harness — run it as a hosted product, or self-host in 5 minutes.
项目介绍Project Overview
DSH Cloud 是围绕 DeepSeek Harness 的云端代理与可自托管平台,提供账户、服务端模型网关、20 个模型、计费、团队协作与可选浏览器工作区。使用时可直接选用托管版,或通过 npx @agentsdanceai/dsh-cloud start 启动社区版并配置 UPSTREAM_API_KEY 后在 http://localhost:8787 访问。注意:工作区默认关闭,开启前须按安全文档审查镜像、网络、权限与隔离配置。
DSH Cloud is a managed and self-hostable platform wrapping DeepSeek Harness, offering accounts, a server-side model gateway serving 20 models, a web console, teams, usage billing, and an optional browser workspace. Use the hosted subscription or run the Community Edition locally via npx @agentsdanceai/dsh-cloud start, then set UPSTREAM_API_KEY in ./dsh-cloud/.env and open http://localhost:8787. Caveat: the workspace executes user code, is off by default, and operators must review the security checklist before enabling it.
请帮我了解并安装插件:【deepseek-harness-cloud】【https://github.com/AgentsDanceAI/deepseek-harness-cloud】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile web add github:AgentsDanceAI/deepseek-harness-cloud
把 AgentsDanceAI/deepseek-harness-cloud 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DSH Cloud
Managed cloud agents and a self-hostable platform around DeepSeek Harness.
Accounts, a server-side model gateway, usage policy, teams, and an optional browser workspace—without distributing an upstream model key to every client.
Release: 0.2.0
中文 · Architecture · Self-host · Editions · Security · Support
Boot the whole Community Edition locally with one command (Docker required):
npx --yes @agentsdanceai/dsh-cloud start
Put your model upstream key into ./dsh-cloud/.env (UPSTREAM_API_KEY=), run
the same command again, and open http://localhost:8787. No Node? uvx dsh-cloud start does the same from PyPI. Details: Quick start.
Choose your path
Use DSH Cloud Hosted
DSH Cloud Hosted is the managed subscription service: no server installation, with model access, workspace capacity, upgrades, monitoring, backups, and account support. Current plans are paid once for the selected monthly or annual term and do not renew automatically.
New accounts start with 500 free credits, and the hosted gateway serves 20 models with no upstream key of your own.
Start on DSH Cloud Hosted · Individual plans · Team plans
Self-host Community Edition
Run the source-available Community Edition with your own domain, database, identity providers, model upstream, storage, and operational controls. Docker Compose is the canonical persistent path; Docker, npm/npx, and uv/uvx use the same versioned stack contract.
Self-hosting guide · Configuration template · Security checklist
Develop and contribute
The public repository includes the FastAPI service, web console, gateway, deployment definitions, desktop overlay, mobile shells, tests, and release contracts.
Development setup · Contributing · Architecture · Changelog
What is included
| Capability | Community behavior |
|---|---|
| Account access | Email/password and email-code paths, optional Google/GitHub OAuth, revocable browser/device/API credentials |
| Model gateway | OpenAI-compatible chat/models and an Anthropic-compatible messages surface; operator upstream key remains server-side |
| Usage and plans | Model catalog, server-side pricing, credit ledger, rate/concurrency gates, usage records, and optional entitlements |
| Teams | Membership, roles, seats, pooled allowances, and per-member attribution |
| Payments | Optional provider adapters with server-authoritative products and authenticated, idempotent webhook handling |
| Web console | Account, plan, order, team, administration, legal, and download surfaces |
| Desktop and mobile | Device authorization plus desktop overlay and mobile shell integration contracts |
| Workspaces | Optional browser-accessible agent runtime; disabled by default and subject to the isolation warning below |
| Operations | Docker/Compose definitions, readiness/liveness/version endpoints, persistent data, release metadata, and upgrade guidance |
Self-hosters remain responsible for infrastructure, provider agreements, model costs, TLS, identity/email delivery, payment configuration, data protection, backups, monitoring, and applicable law.
20 models, one gateway
| Provider | Models |
|---|---|
| DeepSeek | DeepSeek-V4-Flash · DeepSeek-V4-Pro |
Gemini-3.6-Flash |
|
| Xiaomi | MiMo-V2-Omni |
| MiniMax | MiniMax-M2.7 · MiniMax-M3 |
| Alibaba | Qwen3-Omni-30B-A3B · Qwen3-VL-32B · Qwen3.8-Max |
| Moonshot | Kimi-K2.7-Code · Kimi-K3 |
| Zhipu | GLM-5.2 |
| ByteDance | Doubao-Seed-2.0-Pro |
| OpenAI | GPT-5.6-Luna · GPT-5.6-Terra · GPT-5.6-Sol |
| xAI | Grok-4.5 |
| Anthropic | Claude-Sonnet-5 · Claude-Opus-5 · Claude-Fable-5 |
New accounts start with 500 free credits — every model above works out of the box. No card, no API keys, no per-provider signups. Try them on DSH Cloud Hosted, or pipe them into a stock DeepSeek Harness install with one command:
npx --yes dsh-plugin-cloud setup
The gateway serves the live catalog, so this table is contract-tested against
server/config/models.json.
Quick start
All commands below pin release 0.2.0; pin exact versions in automation.
One command — npm/npx
One-shot:
npx --yes @agentsdanceai/dsh-cloud@0.2.0 start --mode trial --wait
Installed:
npm install --global @agentsdanceai/dsh-cloud@0.2.0
dsh-cloud start --mode trial --wait
The stack boots with an empty upstream key. Before chatting, set
UPSTREAM_API_KEY in ./dsh-cloud/.env and run the same command again.
One command — uv/uvx
One-shot:
uvx dsh-cloud==0.2.0 start --mode trial --wait
Installed:
uv tool install dsh-cloud==0.2.0
dsh-cloud start --mode trial --wait
For explicit lifecycle control, both CLIs also provide init, doctor, and
up. Pin immutable versions in automation and review generated configuration
before starting it.
From source — Docker Compose
git clone https://github.com/AgentsDanceAI/deepseek-harness-cloud.git && cd deepseek-harness-cloud
bash scripts/quickstart.sh --domain localhost --admin-email you@example.com
The script writes deploy/selfhost/.env with a generated AUTH_SECRET, asks
for your model upstream, starts the stack, and waits for readiness — then open
http://localhost:8787. Development mode prints sign-in codes to server logs;
never use it on a public network. Manual Compose steps: docs/deploy.md.
Single container — prebuilt image
(umask 077; mkdir -p .dsh-cloud; printf 'AUTH_SECRET=%s\nDHC_DEV=1\nPUBLIC_BASE=http://127.0.0.1:8081\n' "$(openssl rand -hex 32)" > .dsh-cloud/docker.env)
docker run --rm --name dsh-cloud --env-file .dsh-cloud/docker.env --publish 127.0.0.1:8081:8100 --mount type=volume,src=dsh-cloud-data,dst=/app/data ghcr.io/agentsdanceai/dsh-cloud-server:0.2.0
Check http://127.0.0.1:8081/readyz, then add your upstream key to
.dsh-cloud/docker.env before model calls. No TLS in this mode — keep the
loopback bind. Building the image from source: docs/deploy.md.
The full deployment guide covers configuration, the versioned GHCR path, backups, upgrades, rollback, scaling, and troubleshooting: docs/deploy.md.
Architecture at a glance
browser / desktop / mobile
|
| HTTPS + session/device credential
v
TLS edge / reverse proxy
|
v
DSH Cloud FastAPI service --------> operator-selected model/search upstream
| accounts, teams, plans server-side provider credential
| model gateway and metering
| web console and payments
|
+---- SQLite or PostgreSQL
|
+---- optional workspace backend -> agent runtime container
The gateway authenticates and authorizes the caller, validates a configured model ID, replaces the client credential with the operator's upstream credential, streams the response, and records normalized usage. See the architecture document for flows and trust boundaries.
Security posture
Workspaces execute user-controlled code. They are off by default. A container and Docker socket proxy are not automatically a hostile multi-tenant security boundary; public operators must review image trust, Docker authority, networks, mounts, privileges, egress, previews, credentials, and resource isolation before enabling them. See docs/security.md.
Report vulnerabilities privately through the
GitHub security advisory form
or security@agentsdance.ai. Do not open a public vulnerability issue or include
live credentials and user data. See SECURITY.md.
Development
Python 3.11+, uv, and Node.js 22 are the tested contributor toolchain:
uv sync --project server --all-extras --locked
uv run --project server pytest server/tests -q
uv run --project server ruff check server/app server/tests server/scripts
node --test server/tests/js/*.test.mjs
Run the server locally:
DHC_DEV=1 AUTH_SECRET=local-development-secret \
uv run --project server uvicorn app.main:app --app-dir server --reload
CLI source checks, once the package directories are present in the candidate tree:
node packages/cli-npm/bin/dsh-cloud.mjs --help
node packages/cli-npm/bin/dsh-cloud.mjs start --dry-run --json
uv run --project packages/cli-python dsh-cloud --help
uv run --project packages/cli-python dsh-cloud start --dry-run --json
Read CONTRIBUTING.md for DCO sign-off, provenance disclosure, tests, security routing, and edition-boundary review.
Repository map
| Path | Purpose |
|---|---|
server/ |
FastAPI application, gateway, data layer, templates, configuration, tests |
packages/dsh-plugin-cloud/ |
Plugin that connects stock DeepSeek Harness installs to the cloud gateway |
deploy/selfhost/ |
Canonical public Compose stack, Caddy config, and environment template |
packages/ |
Version-matched npm and Python lifecycle CLIs |
release/ |
Canonical release identity and schemas |
desktop/ |
Pinned upstream desktop assembly, minimal patches, and cloud integration plugin |
mobile/, miniprogram/ |
Mobile integration shells |
docs/ |
Architecture, deployment, security, edition, compatibility, and maintainer docs |
legal/ |
Hosted legal documents and third-party/licensing records |
Versions, licensing, and marks
- Current software license: DSH Cloud Community License 1.0.
- Human-readable license guide: LICENSING.md.
- Community, Hosted, and Enterprise boundary: docs/editions.md.
- Trademark use: TRADEMARKS.md.
- Third-party notices: legal/THIRD_PARTY_NOTICES.md.
- Release changes: CHANGELOG.md.
DSH Cloud is independently developed and operated. It is not affiliated with or endorsed by DeepSeek. “DeepSeek” and related marks belong to their respective owners.
ruvnet/ruflo
amruthpillai/reactive-resume
volcengine/OpenViking
Molunerfinn/PicGo
titanwings/colleague-skill
nocobase/nocobase
Tencent/WeKnora