App proxy

Run DeepSeek Harness Behind Clash Verge: Proxy the Tool Egress, Not Just the Browser

You already know what DeepSeek Harness is: an Agent runtime, not another chat tab. On restricted networks, failures split into model API versus tool egress. The first often still reaches DeepSeek; the second (npm, GitHub, overseas docs) dies while the browser looks healthy. This page wires Clash Verge Rev for that second path.

Overview: Tun & AI. Siblings: Claude Code, Codex CLI. Builds: download center.

Which failure are you seeing?

SymptomLayerFix direction
Key/auth errors onlyModel APICheck key/permissions first, not the proxy
Web UI up, tools can’t reach GitHub/npmTool egressTun or HTTPS_PROXY for the shell
No Clash connections row at allShell ignoring proxyNew terminal after Tun; set env vars
Rows present but still failingNode or keySwap node / verify key

Three traffic lanes

Traffic Usual path How to verify in Clash
DeepSeek API Often direct Treat key errors as API first
Harness Web UI Local browser UI up ≠ tools egressing
Shell / npx / tools Often ignore system proxy Tun or HTTPS_PROXY; watch connections

Pass condition: trigger one must-outbound mini action inside Harness and see a matching Clash connections row. No row means still direct or never sent.

Order of operations: Tun first, vars second

Tun: best for daily agents. Windows: Service Mode then Tun; failures: Tun start failed. After Tun is up, open a new terminal before npx @deepseek-ai/dsh web—old shells keep empty proxy env.

Env vars: when Tun is blocked, in the same session set HTTP_PROXY and HTTPS_PROXY to http://127.0.0.1:mixed-port. Port conflicts: 7890/7897. System-proxy LEDs do not save ignoring CLIs—see system proxy and terminal proxy.

Ten-minute minimal repro

  1. Clash Verge running, Rule mode, stable node.
  2. Tun only, or vars only—not both “for safety.”
  3. New terminal; start Harness per upstream.
  4. Set a working API key; run a read-only mini task.
  5. Check connections immediately: rows + success = network OK; no rows = still direct; rows + fail = node or key/permissions.

Node quality: latency tests, choosing a provider.

DIRECT and Fake-IP foot-guns

Domestic DIRECT is fine until it swallows github.com or npm. Rerun the outbound mini-task after rule edits. Fake-IP oddities: Fake-IP, DNS, bypass rules. Modes: Rule / Global / Direct—do not “learn” Harness on permanent Global.

Sharing Clash with Claude / Codex

One Clash install can serve Harness, Claude Code, and Codex. Ports shared; acceptance lists are not. Debug Harness alone so the connections page stays attributable. Concepts: what Harness is. Shared Web / team hosts: team usage.

Acceptance and stop-loss

Pass: mini outbound success, connections logged, domestic sites still DIRECT under Rule. Fail: change one layer. Three nodes of pure link timeouts → time/source; clear auth errors → stop at the key. Keep the client current; Tun primer: Tun mode.

Install a client that can prove Tun

Harness shells often ignore system proxy. Get Clash Verge Rev from the download center and run the acceptance steps below.