返回目录

deepseek-harness-docker

维护状态: 活跃

runzhliu/deepseek-harness-docker

社区 Docker 与 Kubernetes 打包,含加固镜像、Compose、Helm、Web UI 与无头 CLI。

前往 GitHub
$ dsh plugin add deepseek-harness-docker

100

星标

10

Fork

Shell

语言

MIT

许可证

2026-08-13

创建于

2026-09-24

最近推送

官方 DeepSeek Harness(`@deepseek-ai/dsh`)CLI/Web UI 的社区加固容器打包——Docker、Compose 与 Helm,非 root、仅回环、固定到 DSH `0.1.1-rc.2`。

DSH 适配

生态相关

作者声明

安全审计

未审计

最后核验

2026-09-01

许可证

MIT

01它能帮你完成什么?

  • Run the official DeepSeek Harness (`@deepseek-ai/dsh`) Web UI or headless CLI as a hardened, non-root container on Docker, Compose, or Kubernetes

    A ready-to-use DSH runtime with profiles, credentials and sessions persisted to a `dsh-home` volume, published only on the loopback `127.0.0.1:3080` interface

    Self-hosters and platform engineers who want to deploy DeepSeek Harness without building from source

  • Open an interactive desktop browser inside the DeepSeek Harness WebUI via the bundled `@runzhliu/dsh-browser-desktop` plugin

    A draggable, resizable embedded Chromium desktop (noVNC on 6080) plus a `browser_open` Agent tool that opens URLs from chat

    DeepSeek Harness users who need an in-app interactive browser for agent-driven web tasks

  • Browse and install community DeepSeek Harness plugins through an optional `dshmarket` Docker/Helm variant

    A `dshmarket`-based image (`0.1.1-rc.2-r2-market.1`) that surfaces community plugins without replacing the default DSH tag or `latest`

    DSH users who want a graphical plugin marketplace instead of manual `dsh plugin add`

02如何接入 DeepSeek Harness?

安装步骤

  1. 01

    docker compose pull

  2. 02

    DSH_WORKSPACE=/absolute/path/to/your/project docker compose up -d --no-build

  3. 03

    docker compose ps

  4. 04

    docker build -t runzhliu/deepseek-harness:0.1.1-rc.2-r2 .

  5. 05

    helm upgrade --install deepseek-harness charts/deepseek-harness

验证接入成功

  • docker run --rm --entrypoint dsh runzhliu/deepseek-harness:0.1.1-rc.2-r2 --version
  • curl --fail http://127.0.0.1:3080/
  • docker compose ps
  • 通过标准包括:CLI 版本等于构建版本;dump 后的 `webserver.config.host` 为 `0.0.0.0`;首页返回 2xx;容器进入 healthy;日志没有配置或插件加载错误;

03DSH 适配与能力边界

DSH 适配生态相关

Containerized distribution of the official dsh CLI/Web UI via Docker, Compose and Helm — runs `@deepseek-ai/dsh` unmodified in a hardened, loopback-only image.

  • Hardened, non-root DSH runtime image

    Official `@deepseek-ai/dsh` npm artifact, pinned to a fixed version→A multi-arch (`linux/amd64`, `linux/arm64`) non-root image that runs the Web UI or headless CLI, with build-time CLI version verification

    UID 1000, read-only root filesystem, drop ALL capabilities, no-new-privileges, minimal mounts
  • Persistent, separated state (`dsh-home`)

    Container filesystem plus a host workspace bind mount or PVC→Persisted profiles, settings, credentials, sessions and storage under `/home/node/.dsh`, surviving container rebuilds

  • Loopback-only, no-ingress networking

    Cordis overlay patch for the container network→Host ports published only on `127.0.0.1:3080` / `127.0.0.1:6080`; no Ingress, LoadBalancer or NodePort

  • Bundled `@runzhliu/dsh-browser-desktop` plugin

    Harness `sidebar.footer.action` and `shell.overlay` extension points→An always-visible in-WebUI browser button, an embedded noVNC Chromium desktop, and a `browser_open` Agent tool

    Launcher attaches `--no-sandbox` only to the browser process, not the whole container

04适合谁?何时不该用?

适合

  • Self-hosters and platform engineers who want to deploy DeepSeek Harness without building from source
  • DeepSeek Harness users who need an in-app interactive browser for agent-driven web tasks
  • DSH users who want a graphical plugin marketplace instead of manual `dsh plugin add`

不适合

  • DeepSeek Harness Web has no TLS, auth, or Origin policy and its Web API can execute code, so this is a single-user local dev environment — never expose it to a LAN or public network (no `-p 3080:3080`, NodePort, LoadBalancer, or public Ingress).
  • Docker isolation is not a multi-tenant security sandbox: do not hand the instance to untrusted users, do not install unaudited plugins into the persisted config volume, and only mount the workspace the agent needs (never host root, `~/.ssh`, cloud-credential dirs, or the Docker socket).

05兼容性、维护与安全提示

  • DeepSeek Harness Web has no TLS, auth, or Origin policy and its Web API can execute code, so this is a single-user local dev environment — never expose it to a LAN or public network (no `-p 3080:3080`, NodePort, LoadBalancer, or public Ingress).
  • Helm uses a single-replica StatefulSet; horizontal scaling is explicitly refused as a HA substitute until upstream provides auth, multi-tenant isolation, and a shared/concurrency-safe state backend.
  • Docker isolation is not a multi-tenant security sandbox: do not hand the instance to untrusted users, do not install unaudited plugins into the persisted config volume, and only mount the workspace the agent needs (never host root, `~/.ssh`, cloud-credential dirs, or the Docker socket).
  • The container runs as the built-in `node` user (UID/GID 1000); if the host workspace rejects writes from that UID you must adjust directory permissions or build a derived image matching your local UID — do not fall back to running as root.
2026-08-132026-08-29作者未说明

Community container packaging; last pushed 2026-08-29; pinned to `@deepseek-ai/dsh@0.1.1-rc.2` (image r2); no official GitHub release yet.

06常见问题

这和直接运行 `npx @deepseek-ai/dsh` 有什么区别?

镜像固定 DSH 版本(并在构建时校验实际 CLI 版本),以非 root 用户运行,根文件系统只读,丢弃全部 Linux capabilities,并把配置、凭据、会话持久化到 `dsh-home` 卷。它还通过官方 Cordis overlay 修正 Web 监听地址,使端口只发布到 `127.0.0.1`。

它会打包或自行构建 DeepSeek Harness 吗?

不会。它原样封装官方 npm 发行物 `@deepseek-ai/dsh`(当前固定 `0.1.1-rc.2`),并故意不发布会漂移的 Docker `latest` 标签。升级跟随上游 npm 发行。

我可以安装社区插件吗?

默认镜像、Compose 与 Helm Chart 只加载官方 `@deepseek-ai/dsh` 发行物,不内置插件市场。需要图形化插件浏览时,使用显式的 `dshmarket` 变体(`compose.market.yaml` / 镜像标签 `…-market.1`);也可以 `dsh plugin --profile web add` 内置的 `@runzhliu/dsh-browser-desktop` tgz。

如何安全地让浏览器访问它?

只在回环地址访问——Compose 发布 `127.0.0.1:3080`,Kubernetes 则用 `kubectl port-forward`。绝不要用 `-p 3080:3080`、NodePort、LoadBalancer 或公开 Ingress:Web API 可执行代码且无认证。

状态如何持久化与升级?

配置、凭据、会话与存储位于 `/home/node/.dsh`(Compose 为命名卷,Helm 为 PVC)。镜像可重建而状态保留;`docker compose down` 保留卷,只有 `--volumes` 才会删除。

08数据与来源

  • 作者声明github.com487e5e89ebc7…

    这是一个可直接构建的 DeepSeek Harness 社区容器方案,默认运行官方 `@deepseek-ai/dsh` 的 Web UI。

  • 作者声明github.com487e5e89ebc7…

    镜像的入口等价于执行 `dsh`,因此可以用运行参数覆盖默认 Web 命令:

  • 作者声明github.com487e5e89ebc7…

    最终发布为 [`@deepseek-ai/dsh`](https://www.npmjs.com/package/@deepseek-ai/dsh) CLI。

页面基于项目公开文档、仓库元数据和 DSH Plugins 的结构化解析生成;最后核验于 2026-09-01。发现错误?提交更正。

🏆

最佳 DeepSeek Harness 插件

从全目录挑出的 12 个值得优先安装的插件,覆盖各个分类。

DSH Plugins 是独立的 DeepSeek Harness 插件市场,与 DeepSeek 官方无关,也不代表官方背书。第三方插件未经安全审计,安装前请审查源码。

每周获取最新的 DeepSeek Harness 插件,绝不滥发。