NIyueeE/dsh-container

Ships DeepSeek Harness as a batteries-included container: the agent, a full toolchain and a reverse proxy in one image built from the official source tags. The README documents the two Linux quick-start routes, what is inside (base image, toolchain, dsh built into /opt/deepseek-harness, Caddy exposure with optional basic auth, a supervisor that restarts dsh web on exit, OCI labels and a container HEALTHCHECK), and a single container-adapt Cordis plugin mounted via dsh --patch. That plugin is the adaptation maintenance point: it bootstraps the session cookie inside dsh so browsers never see a login token, hides the headless-hostile "Open config file" button by making settings/describe report no local document, and patches the browser-side isLoopback check so settings work through the proxy. ~/.dsh and caches live on a mounted volume, so the user layer survives image upgrades.

Other ★ 1 updated 2026-09-17 ✅ runtime-tested
View on GitHub ↗

Install

docker compose -f examples/compose.yaml up -d

README quick start, Docker Compose (Linux), quoted verbatim: docker compose -f examples/compose.yaml up -d, then docker compose logs dsh | grep 'dsh web:' and open http://127.0.0.1:3081/ (the proxy bootstraps the login). The README's recommended Linux route is Podman Quadlet: sudo mkdir -p /etc/containers/systemd, sudo cp examples/dsh.container /etc/containers/systemd/, sudo systemctl daemon-reload, sudo systemctl enable --now dsh.service. Images publish as GHCR ghcr.io/niyueee/dsh-container; restart dsh inside the container with docker exec dsh dsh-restart.

Compatibility

Linux with Docker Compose or Podman Quadlet. Base image debian:13-slim (overridable via BASE_IMAGE) with Node.js 22 LTS, pnpm, uv, Rust/cargo, git, build-essential, Caddy, podman and gh. dsh web listens on 127.0.0.1:3080 inside the container (upstream rejects --host 0.0.0.0); Caddy exposes 0.0.0.0:3081 and rewrites Host/Origin to loopback, so the proxy is the security boundary.

Details

Recent updates

The README documents the release pipeline contract rather than a changelog: the image is built from a pinned official dsh source tag with no runtime auto-update, and when upstream ships an API that makes part of the container-adapt plugin redundant, the release pipeline deletes that part and says so in the release notes (see docs/upstream-contract.md § Simplification triggers). docs/releasing.md documents the release automation (upstream tag watcher, contract check, agent repair, auto-publish).

FAQ

How do I start the dsh container?
docker compose -f examples/compose.yaml up -d, then open http://127.0.0.1:3081/. On Linux the README recommends the Podman Quadlet route (examples/dsh.container + systemctl enable --now dsh.service).
Do I need to log in?
No — the README states the proxy bootstraps the dsh session inside the container, so browsers never see the one-time login token.
Where does my data live?
On the mounted volume at /home/dsh (the user layer: ~/.dsh, caches, user-installed tools), which survives image upgrades; the system layer comes from the image.

Alternatives

deepseek-ai/deepseek-harness · awesome-dsh-plugin/awesome-dsh-plugin · yjh051108/dsh-routing-suite

More plugins in Other

Browse more in Other

Guides for Other plugins