pointer-a/dsh-server-login
面向公网的多租户 DSH 托管平台 —— 部署到一台公网服务器后,多个用户注册并经管理员审核,各自获得一套相互隔离的 deepseek-harness(DSH)环境,随时通过域名安全访问。
Project Overview项目介绍
This repository is a cordis-distributed native plugin built exclusively for DeepSeek Harness (DSH) that enables public, multi-tenant DSH hosting. Once deployed on a public-facing server, it lets multiple users register accounts, which are approved by an admin, and each user gets a fully isolated DSH environment they can access securely via a custom domain name. It ships with two configurable deployment modes: a single-server bare-metal mode and a production-grade containerized Kubernetes mode, and its web interface is optimized for mobile browser access.
It addresses core gaps in the original single-user local DSH, which lacks built-in user authentication, multi-tenant isolation, and an authentication layer for remote web access. After a user’s registration is approved by the admin, they get their own dedicated file space and DSH process. All file operations are protected by dual path validation checks to prevent users from escaping their root directory, and each user’s API keys are encrypted and stored separately using AES-256-GCM to guarantee full credential isolation. This plugin is ideal for admins who need to set up a shared team or public-facing multi-user DSH service.
The project is released under the permissive MIT license, and the two deployment modes can be switched via a simple environment variable. For single-server mode, you need a Linux server running Node.js 22.19 or newer, plus a pre-installed global DSH CLI. For Kubernetes mode, it supports multi-node high availability, assigns each user an isolated Pod, and includes complete step-by-step deployment documentation and troubleshooting guides for both modes. Before accessing the DSH chat interface, you must configure your domain, nginx reverse proxy, and HTTPS certificates first.
dsh-server-login 是专为 DeepSeek Harness(DSH)打造的多租户公网托管服务端插件,提供带审核的用户注册登录、多租户隔离编排与网页访问入口。原生以 cordis 插件形式分发,支持单机裸机部署和 Kubernetes 容器化部署两种模式,可让多个用户各自拥有独立隔离的 DSH 环境,随时通过域名安全访问,还适配了移动端访问体验。
它填补了原生 DSH 作为单用户本地工具,缺少用户认证、多租户隔离和远程访问认证层的不足。管理员可审核注册用户,每个用户拥有独立的文件空间和 DSH 进程,路径经过双重围栏校验防止越权访问,用户 API 密钥以 AES-256-GCM 加密存储,保障完全的凭据隔离,适合需要搭建团队共享或公开多用户 DSH 服务的管理员使用。
该项目遵循 MIT 许可证,支持通过环境变量切换两种部署模式。单机模式要求 Linux 服务器、Node.js 22.19+ 或 24+,以及预先安装好 DSH CLI;K8s 模式支持多机高可用部署,每个用户分配独立 Pod,项目提供完善的部署文档和问题排查指南,部署后需要配置域名、nginx 和 HTTPS 证书才能正常访问 DSH 界面。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-server-login(pointer-a/dsh-server-login)
仓库:https://github.com/pointer-a/dsh-server-login
本站详情页:https://www.yhbd.top/plugins/pointer-a-dsh-server-login/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 28 · 最近提交 2026-08-26 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 28 stars - an early-stage project星标 28,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:pointer-a/dsh-server-login
把 pointer-a/dsh-server-login 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-server-login
面向公网的多租户 DSH 托管平台 —— 部署到一台公网服务器后,多个用户注册并经管理员审核,各自获得一套相互隔离的 DeepSeek Harness(DSH)环境,随时通过域名安全访问(已适配手机端)。
以 DSH 插件市场 的 cordis-plugin 形态分发,遵守 STANDARD.md。
它解决什么
DSH 本身是单用户本地工具:没有认证、没有多租户隔离、Web 远程访问缺认证层。dsh-server-login 在其之上补一层服务端登录 + 多租户编排:
用户浏览器
│ HTTPS
▼
nginx(TLS 终结,主域 + *.子域 通配)
▼
编排服务 dsh-server-login(Fastify,单进程)
├─ 认证 / 审核 / 管理台 / 网页桌面 / 域名 API
└─ 按 Host 或 /u/<userId>/dsh/* 路由
└─ 反向代理 → 各用户的 DSH 子进程(只绑 127.0.0.1 动态端口,不出公网)
流程:管理员审核注册用户 → 每个用户落到自己的文件桌面 → 按文件夹启动 DSH → 通过域名访问,彼此文件隔离。
核心能力
| 能力 | 说明 |
|---|---|
| 登录与审核 | bootstrap-admin 创建首个管理员;注册后需审核通过才能登录;禁用用户会同时删除其会话并停止运行中的 DSH |
| 每用户隔离 DSH | 主 DSH 常驻对外服务;崩溃时按需拉起一次守护 DSH 修复并自动重启主实例 |
| 网页桌面 | 文件浏览 / 新建 / 上传;按文件夹启动 DSH;所有路径经「词法包含 + 符号链接分量」双重围栏校验 |
| 每文件夹插件 | 自动检测该用户 profile 已安装的插件,按文件夹勾选启用,持久化并注入 cordis patch |
| 多形态访问 | 默认子路径 /u/<userId>/dsh/;每用户子域名 <用户名>.<baseDomain>(HTTP + WebSocket);自定义域名 + nginx server {} 生成接口 |
| 凭据隔离 | 每用户命名 API 密钥库,AES-256-GCM 加密落库(references-not-secrets);换 key 自动重建实例;spawn 只注入当前启用的 key |
部署形态(二选一)
同一套代码,靠 DSH_SERVER_LOGIN_DEPLOY_MODE 切换:
| 模式 A:直接部署(单服务器) | 模式 B:K8s + 容器化 | |
|---|---|---|
| 形态 | 单机裸机,child_process + setuid/iptables |
多机 ACK,每用户独立 Pod |
| 数据 | SQLite(本机文件) | PostgreSQL(CloudNativePG) |
| 隔离 | 软隔离 / OS 账号硬隔离 | Pod 网络 + SecurityContext + NetworkPolicy |
| 弹性/HA | 无(单点) | 控制面 3 副本 + leader election,DSH Pod 自动重建 |
| 交付 | git clone + 脚本 |
kubectl apply -f deploy/ |
模式 B 已完整落地(Phase 0–4):每用户 DSH Pod(dsh + tcp-bridge sidecar)+ file sidecar(8082)+ Headless Service + NetworkPolicy;控制面 3 副本 + Lease 选主 + reconcile + 崩溃接管;NAS(CNFS) 共享卷 + PSA restricted + ResourceQuota。见 K8s 部署教程 与 踩坑记录。
快速开始(模式 A)
前置:Linux 服务器、Node ^22.19 或 ≥24、已安装 DSH CLI(npm i -g @deepseek-ai/dsh)。完整的生产流程(systemd / DNS / 通配证书 / nginx)见部署教程。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
kenryu42/cc-safety-net
hyhmrright/brooks-lint
zhu1090093659/dsh-trading
lire1131/dsh-undo-savepoint
jigjoy-ai/baro
c3ll256/dsh-toy
huaweicloud/huaweicloud-devkit