dsh-one-gateway
A DeepSeek Harness Web plugin that places a loopback-only, identity-aware private gateway in front of DSH Web.
Install
$ dsh plugin --profile web add -w /path/to/dsh-one-gatewayPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Installs as a DSH Web-profile bundle with a Cordis patch.
- Keeps the gateway and DSH upstream on loopback.
- Proxies HTTP and WebSocket requests to local DSH.
- Enforces exact allowlists for Tailscale login, Cloudflare email, or issued credential principals.
- Supports Tailscale Serve, Cloudflare Access, and Headscale TCP Serve onboarding.
- Locally validates Cloudflare Access JWT claims and JWKS-based signatures.
- Issues, lists, and revokes Headscale gateway credentials.
- Provides setup preview mode and a diagnostic doctor command.
Useful For
- Privately sharing a self-hosted DSH Web instance with explicitly allowlisted people.
- Putting Tailscale Serve in front of a loopback-only DSH Web deployment.
- Using Cloudflare Access as an identity provider while retaining local JWT validation.
- Providing Headscale TCP Serve access with operator-managed TLS and per-principal gateway credentials.
Who It Fits
- DeepSeek Harness Web operators.
- Self-hosting and homelab users.
- Teams using Tailscale Serve, Cloudflare Access, or Headscale.
Documented Limitations
- Allowlisted users retain full DSH administrator privileges; the plugin does not make DSH multi-tenant.
- Only one ingress provider can run in a gateway instance.
- Cloudflare setup does not create tunnels, DNS records, or Access applications, and cannot independently prove Access remains attached.
- Headscale TCP Serve requires an operator-supplied TLS certificate, private key, and credential store.
- Uninstall does not remove provider routes, tunnels, Access applications, or credential files.
- It does not protect against a malicious same-host administrator or processes that can access the DSH or gateway loopback ports.
- EasyTier, ZeroTier, WireGuard-only, NetBird, Twingate, Pangolin, generic reverse proxies, raw LAN, SSH tunnels, and public tunnels are not supported.
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 1 runtime, 0 development, 0 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- TiantianFlow/dsh-one-gateway
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- e62f91b · 2026-08-22
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 11GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-08-21
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
A DeepSeek Harness bridge that runs unmodified Pi ecosystem extensions as native DSH plugins.
View plugin →Connects DeepSeek Harness to Feishu/Lark through a scan-to-connect bot with streaming cards and workspace-aware agent sessions.
View plugin →DeepSeek Harness plugin that bridges a local-shell-mcp service into DSH with shell, file, browser, remote-worker, and Live Workspace tools.
View plugin →Univer-powered DeepSeek Harness plugin for creating, editing, previewing, reviewing, and exporting office content.
View plugin →