TiantianFlow/dsh-tailscale-gateway

TiantianFlow★ 11JavaScriptLast synced: 2026-08-20

Open on GitHub

Private Tailscale access for DeepSeek Harness Web: exact user allowlists, loopback-only gateway, and guarded Serve setup

README excerpt

dsh-tailscale-gateway English · 简体中文 Private DSH Web access for the people you choose—not your whole network. Give selected Tailnet users private browser access to a local DeepSeek Harness (DSH) Web UI—without exposing DSH on your LAN or the public Internet. This small, dependency-free DSH Web-profile bundle keeps DSH and the gateway on loopback, then uses Tailscale Serve as the only remote ingress. What it gives you: an exact Tailscale-login allowlist in front of DSH, a loopback-only gateway, and conflict-safe private Serve setup. Installing alone does nothing. Guided setup writes an enabled profile entry only after your confirmation; the next DSH Web start activates it. It never opens a LAN listener or configures Funnel. Why this gateway? Tailscale delivers an authenticated connection. This bundle turns that connection into a deliberately narrow, DSH-aware access boundary: What you need What this bundle does Share DSH with only specific people Allows exact Tailscale-User-Login identities, not every Tailnet member who can reach the node. Keep DSH local Pins both DSH and the gateway to 127.0.0.1 ; there is no LAN listener or public Funnel mode. Use the normal DSH web app remotely G…

View full README on GitHub →
Tools / Devdeepseek-harnessdshdsh-pluginremote-accesssecuritytailscaletailscale-servewebsocket

Category