dsh-one-gateway
Private zero-trust gateway providing identity-verified loopback ingress for DeepSeek Harness Web.
Install
$ dsh plugin --profile web add github:TiantianFlow/dsh-one-gatewayPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Loopback-only reverse proxy for HTTP and WebSocket traffic into DSH Web
- Zero-trust principal allowlist verification before forwarding any request
- Tailscale Serve integration using injected identity headers
- Cloudflare Tunnel and Cloudflare Access integration with local RS256 JWT validation
- Headscale TCP Serve integration using TLS termination and high-entropy gateway credentials
- Interactive and non-interactive setup CLI with doctor diagnostics and credential management
Useful For
- Safely exposing DeepSeek Harness Web over Tailscale or Headscale to specific allowlisted teammates
- Routing remote access through Cloudflare Access with verified identity tokens without opening direct ports
- Restricting multi-device homelab access strictly to verified principals instead of generic LAN or VPN membership
Who It Fits
- Developers hosting DeepSeek Harness Web instances on personal or team homelabs
- DevOps and security engineers requiring strict zero-trust identity verification for AI agent harnesses
Documented Limitations
- Does not make DeepSeek Harness itself multi-tenant or introduce sub-administrator roles (all allowlisted users have full DSH access)
- Does not protect against malicious same-host local processes with access to loopback or system memory
- Does not support generic arbitrary reverse proxies, public anonymous tunnels, or unmanaged LAN access
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 1 runtime, 0 development, 0 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- TiantianFlow/dsh-one-gateway
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- 9b752b0 · 2026-09-27
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 13GitHub stars
- Forks
- 1
- Open issues
- 0
- Last commit
- 2026-08-26
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Compatibility bridge running unmodified Pi ecosystem extensions natively on DeepSeek Harness.
View plugin →Full office suite integration for DeepSeek Harness supporting spreadsheets, docs, slides, bases, and canvases.
View plugin →Native SQLite-backed task management and project board bundle with Web UI and Agent workflow tools for DeepSeek Harness.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed verdicts and audit logging.
View plugin →