UynajGI/dsh-ssh

SSH remote-execution plugin for DeepSeek Harness: ProxyJump chain, SFTP filesystem, subprocess and PTY over ss

dsh-ssh is an SSH remote-execution plugin for DeepSeek Harness: it moves Bash, file tools, PTY terminals, and LSP onto a remote host over a single SSH connection, with multi-hop ProxyJump chains, SFTP upload/download, and full auth coverage (password, private key PEM or path, passphrase, ssh-agent, Pageant). The harness does not need to be installed remotely — dsh-ssh implements remote providers for two capability seams (ctx.subprocess and ctx.fs), so every tool built on those seams switches to the remote host with zero changes: the model thinks locally, commands run remotely, results stream back into the local model context. The Web GUI's Add-workspace flow gains a connection sidebar (VS Code Remote Explorer style) that reads ~/.ssh/config aliases, saved connections, and the local entry. Capabilities include ProxyJump chains, atomic SFTP writes, remote command execution (collect/pipe/inherit/batch stdin), interactive PTY terminals, environment isolation (scrubbed login env via env -i), per-target-key serialized fs writes, and optional strict host key verification against knownHosts fingerprints.

Agent Capabilities ★ 7 updated 2026-08-16 ⚠️ needs adapt
View on GitHub ↗

Install

npm i dsh-ssh

npm package dsh-ssh 0.3.0-pre (registry-verified 2026-08-24; README badge shows the published dist-tag). Install: npm i dsh-ssh. Then mount it in the profile's cordis.yml — one row mounts everything (connection owner + both remote providers): - id: ssh-remote / name: dsh-ssh / config: { host, port, username, privateKey, cwd, optional jump chain }. The harness does not need to be installed remotely: dsh-ssh implements remote providers for ctx.subprocess (remote processes) and ctx.fs (remote files), so every tool built on those seams (bash, file tools, terminals, LSP, subagent processes) switches to the remote host with zero changes. Built on ssh2. First (and as of 2026-08, only) SSH remote-development plugin in the dsh-plugin ecosystem; verified end-to-end against a real two-hop jump environment with key auth.

Compatibility

DeepSeek Harness web profile, Node.js ≥ 22. Remote providers for ctx.subprocess and ctx.fs seams — bash, file tools, PTY terminals, LSP, and subagent processes run on the remote host while the model thinks locally. Multi-hop ProxyJump chains (per-hop auth), password / private key / passphrase / ssh-agent / Pageant auth, SFTP upload (atomic same-dir temp + rename) and download (full fs provider). ~/.ssh/config aliases readable in the Web GUI sidebar. Connection reuse across all three providers; remote login env scrubbed (DSH_* and credential-shaped names removed) via env -i. Known limits: remote pid invisible (always -1), termination is not tree-scoped, no reconnection (dropped connection requires plugin restart), text-only streamText.

Details

Recent updates

The current English README documents: architecture (local brain, remote hands), quick start (npm i + one cordis.yml row), the three subpath rows (ssh connection owner, subprocess provider, fs provider), the Web GUI Add-workspace takeover with ~/.ssh/config sidebar, full configuration reference (host, port, username, password, privateKey, passphrase, agent, jump, cwd, readyTimeout, keepalive, strictHostKeyChecking, knownHosts), OpenSSH ~/.ssh/config mapping table, capabilities, performance (connection reuse, env cache, local spill, no polling), reliability (exit facts authoritative, UTF-8 safe, fail loud), troubleshooting, known limitations, and development/release workflow.

FAQ

Does the remote host need DeepSeek Harness installed?
No — dsh-ssh implements remote providers for the ctx.subprocess and ctx.fs seams. Every tool built on those seams (bash, file tools, terminals, LSP, subagent processes) runs on the remote host with zero changes; only an SSH server is required remotely.
Can I go through a bastion host?
Yes — the jump array builds a multi-hop ProxyJump chain (equivalent to OpenSSH ProxyJump) with independent auth per hop: dsh plugin --profile web add ssh with config.jump listing each hop's host, port, username, and privateKey.
What happens when the SSH connection drops?
Connection failures surface with readable messages and teardown cleans up active processes, terminals, staging dirs, and spill files. There is no automatic reconnection — a dropped connection requires a plugin restart.

Alternatives

juanwang-buaa/dsh-full-remote · flymysql/dsh-remote · AcidGr/dsh-web-lan-access

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins