tensorlakeai/dsh-tensorlake-sandbox
A deepseek harness plugin for tensorlake sandbox
@tensorlakeai/dsh-sandbox moves DeepSeek Harness file, subprocess, Bash, terminal, and LSP operations into one short-lived Tensorlake microVM: sandbox-aware Bash execution delegates to the Tensorlake subprocess provider while still satisfying the permission-preset capability contract, and the model-facing working directory is the same remote Linux path. It is an installable dsh bundle and does not require changes to the Harness installation. Credentials (TENSORLAKE_API_KEY, DEEPSEEK_API_KEY, other credential-shaped env vars, DSH_* variables) are never copied into sandbox processes.
Install
npm install --global @deepseek-ai/dsh && dsh plugin --profile headless add @tensorlakeai/dsh-sandboxnpm package @tensorlakeai/dsh-sandbox 0.1.0 (registry-verified 2026-08-24). Install dsh and add the bundle to the profile you run: npm install --global @deepseek-ai/dsh, dsh plugin --profile headless add @tensorlakeai/dsh-sandbox, then TENSORLAKE_API_KEY=... DEEPSEEK_API_KEY=... dsh --profile headless "build and test this repo". Development: npm install && npm run build && dsh plugin --profile headless add . from a checkout. Verify with dsh --profile headless --dump-config: the layer disables the host subprocess and fs-sandbox providers, inserts the Tensorlake runtime/subprocess/filesystem rows, and keeps bash-sandbox mounted in danger-full-access mode. Requires a Tensorlake project with TENSORLAKE_API_KEY and DEEPSEEK_API_KEY in the host environment.
Compatibility
Node.js ^22.19.0 or >=24.0.0, @deepseek-ai/dsh 0.1.0-rc.6 or later. Moves file, subprocess, Bash, terminal, and LSP operations into one short-lived Tensorlake microVM; no changes to the Harness installation. Config fields: apiKey (TENSORLAKE_API_KEY), cwd (/home/tl-user/workspace), timeoutSecs (600), cpus, memoryMb, diskMb; DSH_TENSORLAKE_CWD overrides the shared workspace. Ephemeral sandbox starts on profile boot and terminates when dsh exits. Known limitation: tensorlake@0.5.103 pins undici@8.3.0 and nanoid@3.3.11 with high-severity advisories (npm audit) — review upstream advisories before production use.
Details
- Repo: tensorlakeai/dsh-tensorlake-sandbox
- Category: Infrastructure & Deployment
- Stars: 6
- Version: npm package @tensorlakeai/dsh-sandbox 0.1.0 (registry-verified 2026-08-24)
- Last push: 2026-08-14
- First seen: 2026-08-14
Recent updates
The current English README documents: prerequisites, install, smoke test (pwd/id/file-read expectations), configuration table, cordis.patch.yml overrides, runtime requirements (the managed Ubuntu image with bash/Node/GNU coreutils), known limitations (transitive advisory pins), development, and the three Loader entry points.
FAQ
- Does it require changes to the Harness installation?
- No — @tensorlakeai/dsh-sandbox is an installable dsh bundle; it replaces the host subprocess and fs-sandbox providers with Tensorlake-backed ones inside the profile composition.
- What runs inside the microVM?
- File, subprocess, Bash, terminal, and LSP operations run in one short-lived Tensorlake microVM with a shared Linux working directory (default /home/tl-user/workspace). The sandbox is created on profile boot and terminated when dsh exits.
- Are my API keys exposed to the sandbox?
- No — the package never copies TENSORLAKE_API_KEY, DEEPSEEK_API_KEY, other credential-shaped environment variables, or DSH_* variables into sandbox processes. Keep credentials in environment variables or a secret manager.
Alternatives
flymysql/dsh-remote · MAXeaglet/dsh-bash-terminal · AcidGr/dsh-web-lan-access