evanfang0054/dsh-tailscale-console
Provide Tailscale-based secure remote access operation panel for DeepSeek Harness: one-click health check, HTTPS entry switch, macOS proxy bypass, relay server
A control panel for the DSH web GUI that operates secure remote access over Tailscale: per-device online/offline state with alerts, a one-click health check (HTTPS entry, page, /api session list, remote /api RPC over HTTPS, server direct path, proxy bypass), a Tailscale Serve HTTPS-entry status and on/off toggle with verification and retry, a macOS proxy-bypass check for *.ts.net and 100.64.0.0/10 with one-click re-apply, relay-server status with Peer Relay enable and ping verify, the exact dsh web start command, an ACL snippet generator for tailscale.com/cap/relay grants, and one-click device pairing links/QR with Add-to-Home-Screen support.
Install
dsh plugin --profile web add dsh-tailscale-consoleREADME install (npm channel: dsh plugin --profile web add dsh-tailscale-console; GitHub channel: dsh plugin --profile web add github:evanfang0054/dsh-tailscale-console; a local pnpm add "dsh-tailscale-console@file:./packages/dsh-tailscale-console" is documented for development). npm package dsh-tailscale-console 0.4.5 (registry-verified 2026-09-10; registry repository field -> github.com/evanfang0054/dsh-tailscale-console). If you previously mounted the plugin the manual way (an - insert: line in cordis.patch.yml), remove that line before switching to the dsh plugin add bundle channel — keeping both double-mounts the plugin.
Compatibility
Requires dsh >= 0.1.0-rc.6 (for --trusted-host and the webRuntime service), a dsh web profile, Node 20.x + pnpm >= 9 (pnpm-lock.yaml is v9; the default pnpm 8 under Node 24 will fail — verified with Node 20.19.2 + pnpm 10.27.0), the tailscale CLI logged in locally, and a phone with the Tailscale app for remote testing. The panel UI language is Chinese. Browsers expose crypto.randomUUID only in secure contexts, so the HTTPS entry (Tailscale Serve) is mandatory and plain http://<tailnet-ip>:3080 is debug-only.
Details
- Repo: evanfang0054/dsh-tailscale-console
- Category: Plugin Markets & Managers
- Stars: 1
- Version: npm dsh-tailscale-console 0.4.5 (registry-verified 2026-09-10)
- Last push: 2026-09-14
- First seen: 2026-08-14
Recent updates
README documents the end-to-end setup path the panel accompanies: server joins the tailnet as a Peer Relay (relay port + firewall, cloud security group must also allow inbound UDP 40000/41641), the local machine exposes HTTPS via tailscale serve --bg 3080, and DSH keeps listening on 127.0.0.1 with dsh web --trusted-host <ip>:3080 --trusted-host <host.tailnet.ts.net> plus a static trustedHosts row. Every such change requires restarting dsh web, which interrupts the running session.
FAQ
- How do I install dsh-tailscale-console?
- Run: dsh plugin --profile web add dsh-tailscale-console (or the GitHub channel dsh plugin --profile web add github:evanfang0054/dsh-tailscale-console). Remove any earlier manual - insert: line in cordis.patch.yml first so the plugin is not mounted twice.
- What are the prerequisites?
- dsh >= 0.1.0-rc.6 with a web profile, Node 20.x with pnpm >= 9 (pnpm-lock.yaml is v9 — pnpm 8 under Node 24 fails), a logged-in tailscale CLI on the local machine, and a Tailscale account with MagicDNS enabled.
- Why is plain HTTP access to the tailnet IP unusable?
- Browsers expose crypto.randomUUID only in secure contexts (HTTPS or localhost) and every DSH client RPC depends on it, so the GUI needs the Tailscale Serve HTTPS entry — http://<tailnet-ip>:3080 is for debugging only.