Community, hardened container packaging for the official DeepSeek Harness (`@deepseek-ai/dsh`) CLI/Web UI — Docker, Compose and Helm, non-root, loopback-only, pinned to DSH `0.1.1-rc.2`.
DSH integration
Ecosystem-related
Author-claimed
Safety audit
Unaudited
Last verified
2026-09-01
License
MIT
01What can it help you accomplish?
Run the official DeepSeek Harness (`@deepseek-ai/dsh`) Web UI or headless CLI as a hardened, non-root container on Docker, Compose, or Kubernetes
A ready-to-use DSH runtime with profiles, credentials and sessions persisted to a `dsh-home` volume, published only on the loopback `127.0.0.1:3080` interface
Self-hosters and platform engineers who want to deploy DeepSeek Harness without building from source
Open an interactive desktop browser inside the DeepSeek Harness WebUI via the bundled `@runzhliu/dsh-browser-desktop` plugin
A draggable, resizable embedded Chromium desktop (noVNC on 6080) plus a `browser_open` Agent tool that opens URLs from chat
DeepSeek Harness users who need an in-app interactive browser for agent-driven web tasks
Browse and install community DeepSeek Harness plugins through an optional `dshmarket` Docker/Helm variant
A `dshmarket`-based image (`0.1.1-rc.2-r2-market.1`) that surfaces community plugins without replacing the default DSH tag or `latest`
DSH users who want a graphical plugin marketplace instead of manual `dsh plugin add`
02How to install into DeepSeek Harness
Installation steps
- 01
docker compose pull
- 02
DSH_WORKSPACE=/absolute/path/to/your/project docker compose up -d --no-build
- 03
docker compose ps
- 04
docker build -t runzhliu/deepseek-harness:0.1.1-rc.2-r2 .
- 05
helm upgrade --install deepseek-harness charts/deepseek-harness
Verify the integration
- docker run --rm --entrypoint dsh runzhliu/deepseek-harness:0.1.1-rc.2-r2 --version
- curl --fail http://127.0.0.1:3080/
- docker compose ps
- 通过标准包括:CLI 版本等于构建版本;dump 后的 `webserver.config.host` 为 `0.0.0.0`;首页返回 2xx;容器进入 healthy;日志没有配置或插件加载错误;
03DSH integration and capability boundaries
Containerized distribution of the official dsh CLI/Web UI via Docker, Compose and Helm — runs `@deepseek-ai/dsh` unmodified in a hardened, loopback-only image.
Hardened, non-root DSH runtime image
Official `@deepseek-ai/dsh` npm artifact, pinned to a fixed version→A multi-arch (`linux/amd64`, `linux/arm64`) non-root image that runs the Web UI or headless CLI, with build-time CLI version verification
UID 1000, read-only root filesystem, drop ALL capabilities, no-new-privileges, minimal mountsPersistent, separated state (`dsh-home`)
Container filesystem plus a host workspace bind mount or PVC→Persisted profiles, settings, credentials, sessions and storage under `/home/node/.dsh`, surviving container rebuilds
Loopback-only, no-ingress networking
Cordis overlay patch for the container network→Host ports published only on `127.0.0.1:3080` / `127.0.0.1:6080`; no Ingress, LoadBalancer or NodePort
Bundled `@runzhliu/dsh-browser-desktop` plugin
Harness `sidebar.footer.action` and `shell.overlay` extension points→An always-visible in-WebUI browser button, an embedded noVNC Chromium desktop, and a `browser_open` Agent tool
Launcher attaches `--no-sandbox` only to the browser process, not the whole container
04Who is it for? When not to use it?
Good for
- Self-hosters and platform engineers who want to deploy DeepSeek Harness without building from source
- DeepSeek Harness users who need an in-app interactive browser for agent-driven web tasks
- DSH users who want a graphical plugin marketplace instead of manual `dsh plugin add`
Not for
- DeepSeek Harness Web has no TLS, auth, or Origin policy and its Web API can execute code, so this is a single-user local dev environment — never expose it to a LAN or public network (no `-p 3080:3080`, NodePort, LoadBalancer, or public Ingress).
- Docker isolation is not a multi-tenant security sandbox: do not hand the instance to untrusted users, do not install unaudited plugins into the persisted config volume, and only mount the workspace the agent needs (never host root, `~/.ssh`, cloud-credential dirs, or the Docker socket).
05Compatibility, maintenance and safety notes
- DeepSeek Harness Web has no TLS, auth, or Origin policy and its Web API can execute code, so this is a single-user local dev environment — never expose it to a LAN or public network (no `-p 3080:3080`, NodePort, LoadBalancer, or public Ingress).
- Helm uses a single-replica StatefulSet; horizontal scaling is explicitly refused as a HA substitute until upstream provides auth, multi-tenant isolation, and a shared/concurrency-safe state backend.
- Docker isolation is not a multi-tenant security sandbox: do not hand the instance to untrusted users, do not install unaudited plugins into the persisted config volume, and only mount the workspace the agent needs (never host root, `~/.ssh`, cloud-credential dirs, or the Docker socket).
- The container runs as the built-in `node` user (UID/GID 1000); if the host workspace rejects writes from that UID you must adjust directory permissions or build a derived image matching your local UID — do not fall back to running as root.
Community container packaging; last pushed 2026-08-29; pinned to `@deepseek-ai/dsh@0.1.1-rc.2` (image r2); no official GitHub release yet.
06Frequently asked questions
How is this different from running `npx @deepseek-ai/dsh` directly?
The image pins the DSH version (and verifies the CLI version at build time), runs as a non-root user with a read-only root filesystem, drops all Linux capabilities, and persists profiles/credentials/sessions to a `dsh-home` volume. It also fixes the Web listen address via an official Cordis overlay so the port only publishes on `127.0.0.1`.
Does it bundle DeepSeek Harness or build it from source?
No. It packages the official npm release `@deepseek-ai/dsh` as-is (currently pinned to `0.1.1-rc.2`) and deliberately does not publish a drifting Docker `latest` tag. Upgrades follow the upstream npm release.
Can I install community plugins?
The default image, Compose and Helm chart load only the official `@deepseek-ai/dsh` artifact and ship no marketplace. For a graphical plugin browser, use the explicit `dshmarket` variant (`compose.market.yaml` / image tag `…-market.1`); you can also `dsh plugin --profile web add` the bundled `@runzhliu/dsh-browser-desktop` tgz.
How do I expose it to my browser safely?
Use loopback only — Compose publishes `127.0.0.1:3080`, and on Kubernetes use `kubectl port-forward`. Never use `-p 3080:3080`, NodePort, LoadBalancer or a public Ingress: the Web API can execute code and has no auth.
How is state persisted and upgraded?
Profiles, settings, credentials, sessions and storage live in `/home/node/.dsh` (a named volume in Compose, a PVC in Helm). The image can be rebuilt while state survives; `docker compose down` keeps volumes, only `--volumes` deletes them.
07Related DSH workflows
deepseek-reasonix
by esengine
DeepSeek-native AI coding agent for your terminal. Engineered around prefix-cache stability — leave it running.
mnemon
by mnemon-dev
LLM-supervised persistent memory for AI agents — graph-based recall, cross-session knowledge, single binary. Works with DeepSeek Harness, Claude Code, OpenClaw, and any agent runtime.
phi
by pulseaiclub
a coding agent, rpc plugin, sub-agents, hashline edits, and mcp
sivtr
by ariestar
A unified memory workspace for agents and people, making terminal output and AI session context searchable and reusable across local workspaces.
08Data and sources
这是一个可直接构建的 DeepSeek Harness 社区容器方案,默认运行官方 `@deepseek-ai/dsh` 的 Web UI。
镜像的入口等价于执行 `dsh`,因此可以用运行参数覆盖默认 Web 命令:
最终发布为 [`@deepseek-ai/dsh`](https://www.npmjs.com/package/@deepseek-ai/dsh) CLI。
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-09-01. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
