DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dsh-one-gateway

A DeepSeek Harness Web plugin that places a loopback-only, identity-aware private gateway in front of DSH Web.

Terminal & TUIDeveloper ToolsBrowser & WebSecurity & PolicyRemote Execution
11GitHub Stars0ForksUpdated2026-08-21

Install

$ dsh plugin --profile web add -w /path/to/dsh-one-gateway

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
DSH One Gateway is an installable DSH Web-profile plugin for private ingress to DSH Web. It proxies HTTP and WebSocket traffic on loopback and supports Tailscale Serve identity headers, locally validated Cloudflare Access JWTs, and Headscale TCP Serve with issued gateway credentials.

Key Capabilities

  • Installs as a DSH Web-profile bundle with a Cordis patch.
  • Keeps the gateway and DSH upstream on loopback.
  • Proxies HTTP and WebSocket requests to local DSH.
  • Enforces exact allowlists for Tailscale login, Cloudflare email, or issued credential principals.
  • Supports Tailscale Serve, Cloudflare Access, and Headscale TCP Serve onboarding.
  • Locally validates Cloudflare Access JWT claims and JWKS-based signatures.
  • Issues, lists, and revokes Headscale gateway credentials.
  • Provides setup preview mode and a diagnostic doctor command.

Useful For

  • Privately sharing a self-hosted DSH Web instance with explicitly allowlisted people.
  • Putting Tailscale Serve in front of a loopback-only DSH Web deployment.
  • Using Cloudflare Access as an identity provider while retaining local JWT validation.
  • Providing Headscale TCP Serve access with operator-managed TLS and per-principal gateway credentials.

Who It Fits

  • DeepSeek Harness Web operators.
  • Self-hosting and homelab users.
  • Teams using Tailscale Serve, Cloudflare Access, or Headscale.

Documented Limitations

  • Allowlisted users retain full DSH administrator privileges; the plugin does not make DSH multi-tenant.
  • Only one ingress provider can run in a gateway instance.
  • Cloudflare setup does not create tunnels, DNS records, or Access applications, and cannot independently prove Access remains attached.
  • Headscale TCP Serve requires an operator-supplied TLS certificate, private key, and credential store.
  • Uninstall does not remove provider routes, tunnels, Access applications, or credential files.
  • It does not protect against a malicious same-host administrator or processes that can access the DSH or gateway loopback ports.
  • EasyTier, ZeroTier, WireGuard-only, NetBird, Twingate, Pangolin, generic reverse proxies, raw LAN, SSH tunnels, and public tunnels are not supported.

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 1 runtime, 0 development, 0 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as MIT.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
TiantianFlow/dsh-one-gateway
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin
Source checked
e62f91b · 2026-08-22

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
11GitHub stars
Forks
0
Open issues
0
Last commit
2026-08-21
Last release
No release detected
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app