TiantianFlow/dsh-one-gateway

TiantianFlow★ 12JavaScript最后同步: 2026-08-21

在 GitHub 打开

Private DSH One Gateway — loopback, identity-first ingress for DeepSeek Harness

README 摘要

DSH One Gateway English · 简体中文 Share DSH Web with the people you choose — not your whole network. A DeepSeek Harness (DSH) plugin that puts a private, zero-trust gateway in front of DSH Web. Callers authenticate through Tailscale Serve, Cloudflare Access, or — on Headscale — a generated gateway credential in front of private TCP Serve. One private allowlist decides who gets in. There is no user-chosen password to manage. The gateway and DSH stay on loopback. Tailscale Serve, Cloudflare Tunnel with Cloudflare Access, or Headscale via Tailscale TCP Serve is only the private ingress. Joining that private network is never an authorization decision. Every request must resolve one unambiguous, allowlisted principal before anything is forwarded to DSH. That is self-hosted access control for a zero trust homelab: reachability is not permission. What you get: an exact principal allowlist in front of DSH, a loopback-only HTTP/WebSocket proxy, and a single onboarding command that previews a plan and refuses public or anonymous defaults. Installing the plugin does nothing until you run setup. The full command is dsh-one-gateway ; a shorter dsh-gateway alias is installed too, for typing conveni…

在 GitHub 查看完整 README →
工具/开发deepseek-harnessdshdsh-pluginremote-accesssecuritytailscaletailscale-servewebsocket

分类