官方 DeepSeek Harness(`@deepseek-ai/dsh`)CLI/Web UI 的社群加固容器封裝——Docker、Compose 與 Helm,非 root、僅回環、固定到 DSH `0.1.1-rc.2`。
DSH 整合
生態系相關
作者聲明
安全稽核
未稽核
最後核實
2026-09-01
授權條款
MIT
01它能幫你完成什麼?
Run the official DeepSeek Harness (`@deepseek-ai/dsh`) Web UI or headless CLI as a hardened, non-root container on Docker, Compose, or Kubernetes
A ready-to-use DSH runtime with profiles, credentials and sessions persisted to a `dsh-home` volume, published only on the loopback `127.0.0.1:3080` interface
Self-hosters and platform engineers who want to deploy DeepSeek Harness without building from source
Open an interactive desktop browser inside the DeepSeek Harness WebUI via the bundled `@runzhliu/dsh-browser-desktop` plugin
A draggable, resizable embedded Chromium desktop (noVNC on 6080) plus a `browser_open` Agent tool that opens URLs from chat
DeepSeek Harness users who need an in-app interactive browser for agent-driven web tasks
Browse and install community DeepSeek Harness plugins through an optional `dshmarket` Docker/Helm variant
A `dshmarket`-based image (`0.1.1-rc.2-r2-market.1`) that surfaces community plugins without replacing the default DSH tag or `latest`
DSH users who want a graphical plugin marketplace instead of manual `dsh plugin add`
02如何將外掛接入 DeepSeek Harness?
安裝步驟
- 01
docker compose pull
- 02
DSH_WORKSPACE=/absolute/path/to/your/project docker compose up -d --no-build
- 03
docker compose ps
- 04
docker build -t runzhliu/deepseek-harness:0.1.1-rc.2-r2 .
- 05
helm upgrade --install deepseek-harness charts/deepseek-harness
驗證整合成功
- docker run --rm --entrypoint dsh runzhliu/deepseek-harness:0.1.1-rc.2-r2 --version
- curl --fail http://127.0.0.1:3080/
- docker compose ps
- 通过标准包括:CLI 版本等于构建版本;dump 后的 `webserver.config.host` 为 `0.0.0.0`;首页返回 2xx;容器进入 healthy;日志没有配置或插件加载错误;
03DSH 整合程度與能力邊界
Containerized distribution of the official dsh CLI/Web UI via Docker, Compose and Helm — runs `@deepseek-ai/dsh` unmodified in a hardened, loopback-only image.
Hardened, non-root DSH runtime image
Official `@deepseek-ai/dsh` npm artifact, pinned to a fixed version→A multi-arch (`linux/amd64`, `linux/arm64`) non-root image that runs the Web UI or headless CLI, with build-time CLI version verification
UID 1000, read-only root filesystem, drop ALL capabilities, no-new-privileges, minimal mountsPersistent, separated state (`dsh-home`)
Container filesystem plus a host workspace bind mount or PVC→Persisted profiles, settings, credentials, sessions and storage under `/home/node/.dsh`, surviving container rebuilds
Loopback-only, no-ingress networking
Cordis overlay patch for the container network→Host ports published only on `127.0.0.1:3080` / `127.0.0.1:6080`; no Ingress, LoadBalancer or NodePort
Bundled `@runzhliu/dsh-browser-desktop` plugin
Harness `sidebar.footer.action` and `shell.overlay` extension points→An always-visible in-WebUI browser button, an embedded noVNC Chromium desktop, and a `browser_open` Agent tool
Launcher attaches `--no-sandbox` only to the browser process, not the whole container
04適合誰?何時不該用?
適合
- Self-hosters and platform engineers who want to deploy DeepSeek Harness without building from source
- DeepSeek Harness users who need an in-app interactive browser for agent-driven web tasks
- DSH users who want a graphical plugin marketplace instead of manual `dsh plugin add`
不適合
- DeepSeek Harness Web has no TLS, auth, or Origin policy and its Web API can execute code, so this is a single-user local dev environment — never expose it to a LAN or public network (no `-p 3080:3080`, NodePort, LoadBalancer, or public Ingress).
- Docker isolation is not a multi-tenant security sandbox: do not hand the instance to untrusted users, do not install unaudited plugins into the persisted config volume, and only mount the workspace the agent needs (never host root, `~/.ssh`, cloud-credential dirs, or the Docker socket).
05相容性、維護與安全提醒
- DeepSeek Harness Web has no TLS, auth, or Origin policy and its Web API can execute code, so this is a single-user local dev environment — never expose it to a LAN or public network (no `-p 3080:3080`, NodePort, LoadBalancer, or public Ingress).
- Helm uses a single-replica StatefulSet; horizontal scaling is explicitly refused as a HA substitute until upstream provides auth, multi-tenant isolation, and a shared/concurrency-safe state backend.
- Docker isolation is not a multi-tenant security sandbox: do not hand the instance to untrusted users, do not install unaudited plugins into the persisted config volume, and only mount the workspace the agent needs (never host root, `~/.ssh`, cloud-credential dirs, or the Docker socket).
- The container runs as the built-in `node` user (UID/GID 1000); if the host workspace rejects writes from that UID you must adjust directory permissions or build a derived image matching your local UID — do not fall back to running as root.
Community container packaging; last pushed 2026-08-29; pinned to `@deepseek-ai/dsh@0.1.1-rc.2` (image r2); no official GitHub release yet.
06常見問題
這和直接執行 `npx @deepseek-ai/dsh` 有什麼不同?
映像固定 DSH 版本(並在建置時校驗實際 CLI 版本),以非 root 使用者執行,根檔案系統唯讀,捨棄全部 Linux capabilities,並把配置、憑證、會話持久化到 `dsh-home` 卷。它還透過官方 Cordis overlay 修正 Web 監聽位址,使埠號只發佈到 `127.0.0.1`。
它會打包或自行建置 DeepSeek Harness 嗎?
不會。它原樣封裝官方 npm 發行物 `@deepseek-ai/dsh`(目前固定 `0.1.1-rc.2`),並刻意不發佈會漂移的 Docker `latest` 標籤。升級跟隨上游 npm 發行。
我可以安裝社群套件嗎?
預設映像、Compose 與 Helm Chart 只載入官方 `@deepseek-ai/dsh` 發行物,不內建套件市集。需要圖形化套件瀏覽時,使用明確的 `dshmarket` 變體(`compose.market.yaml` / 映像標籤 `…-market.1`);也可以 `dsh plugin --profile web add` 內含的 `@runzhliu/dsh-browser-desktop` tgz。
如何安全地讓瀏覽器存取它?
只在回環位址存取——Compose 發佈 `127.0.0.1:3080`,Kubernetes 則用 `kubectl port-forward`。絕對不要用 `-p 3080:3080`、NodePort、LoadBalancer 或公開 Ingress:Web API 可執行程式碼且無認證。
狀態如何持久化與升級?
配置、憑證、會話與儲存位於 `/home/node/.dsh`(Compose 為命名卷,Helm 為 PVC)。映像可重建而狀態保留;`docker compose down` 保留卷,只有 `--volumes` 才會刪除。
07相關的 DSH 工作流程
deepseek-reasonix
作者 esengine
專為 DeepSeek 打造的終端 AI 程式設計智慧體,圍繞字首快取穩定性設計,可常駐執行。
mnemon
作者 mnemon-dev
LLM 監督的持久記憶系統,基於圖結構召回、跨會話知識共享,單個二進位制檔案,相容 DeepSeek Harness 等執行時。
phi
作者 pulseaiclub
來自 pi 的編碼智慧體,支援無限提供方、子智慧體、行內編輯與許可權門控。
sivtr
作者 ariestar
A unified agent memory workspace for human and agent | 一個統一的agent記憶工作空間
08資料與來源
这是一个可直接构建的 DeepSeek Harness 社区容器方案,默认运行官方 `@deepseek-ai/dsh` 的 Web UI。
镜像的入口等价于执行 `dsh`,因此可以用运行参数覆盖默认 Web 命令:
最终发布为 [`@deepseek-ai/dsh`](https://www.npmjs.com/package/@deepseek-ai/dsh) CLI。
此頁面根據專案公開文件、儲存庫中繼資料與 DSH Plugins 的結構化解析所產生;最後核實於 2026-09-01。發現錯誤?提交更正。
最佳 DeepSeek Harness 外掛
從全目錄挑出的 12 個值得優先安裝的外掛,涵蓋各個分類。
