NIyueeE/dsh-container
Ships DeepSeek Harness as a batteries-included container: the agent, a full toolchain and a reverse proxy in one image built from the official source tags. The README documents the two Linux quick-start routes, what is inside (base image, toolchain, dsh built into /opt/deepseek-harness, Caddy exposure with optional basic auth, a supervisor that restarts dsh web on exit, OCI labels and a container HEALTHCHECK), and a single container-adapt Cordis plugin mounted via dsh --patch. That plugin is the adaptation maintenance point: it bootstraps the session cookie inside dsh so browsers never see a login token, hides the headless-hostile "Open config file" button by making settings/describe report no local document, and patches the browser-side isLoopback check so settings work through the proxy. ~/.dsh and caches live on a mounted volume, so the user layer survives image upgrades.
Install
docker compose -f examples/compose.yaml up -dREADME quick start, Docker Compose (Linux), quoted verbatim: docker compose -f examples/compose.yaml up -d, then docker compose logs dsh | grep 'dsh web:' and open http://127.0.0.1:3081/ (the proxy bootstraps the login). The README's recommended Linux route is Podman Quadlet: sudo mkdir -p /etc/containers/systemd, sudo cp examples/dsh.container /etc/containers/systemd/, sudo systemctl daemon-reload, sudo systemctl enable --now dsh.service. Images publish as GHCR ghcr.io/niyueee/dsh-container; restart dsh inside the container with docker exec dsh dsh-restart.
Compatibility
Linux with Docker Compose or Podman Quadlet. Base image debian:13-slim (overridable via BASE_IMAGE) with Node.js 22 LTS, pnpm, uv, Rust/cargo, git, build-essential, Caddy, podman and gh. dsh web listens on 127.0.0.1:3080 inside the container (upstream rejects --host 0.0.0.0); Caddy exposes 0.0.0.0:3081 and rewrites Host/Origin to loopback, so the proxy is the security boundary.
Details
- Repo: NIyueeE/dsh-container
- Category: Other
- Stars: 1
- Version: Container images built from official dsh source tags (GHCR tag filter dsh-v*; DSH_TAG pinnable at build time, no runtime auto-update)
- Last push: 2026-09-17
- First seen: 2026-08-13
Recent updates
The README documents the release pipeline contract rather than a changelog: the image is built from a pinned official dsh source tag with no runtime auto-update, and when upstream ships an API that makes part of the container-adapt plugin redundant, the release pipeline deletes that part and says so in the release notes (see docs/upstream-contract.md § Simplification triggers). docs/releasing.md documents the release automation (upstream tag watcher, contract check, agent repair, auto-publish).
FAQ
- How do I start the dsh container?
- docker compose -f examples/compose.yaml up -d, then open http://127.0.0.1:3081/. On Linux the README recommends the Podman Quadlet route (examples/dsh.container + systemctl enable --now dsh.service).
- Do I need to log in?
- No — the README states the proxy bootstraps the dsh session inside the container, so browsers never see the one-time login token.
- Where does my data live?
- On the mounted volume at /home/dsh (the user layer: ~/.dsh, caches, user-installed tools), which survives image upgrades; the system layer comes from the image.
Alternatives
deepseek-ai/deepseek-harness · awesome-dsh-plugin/awesome-dsh-plugin · yjh051108/dsh-routing-suite