App proxy

DeepSeek Harness for Teams: Share the Web UI Safely, Keep Keys on the Host, Proxy the Egress

For teams, DeepSeek Harness blockers are rarely “what is it?” They are: how to share the Web UI, whether one instance is safe, how to split keys and workspaces, and where the proxy belongs. Install/concepts live elsewhere: what it is, npx one-command, source install, Clash proxy. This page is team operations only.

Who this page is for

Read this when more than one person needs the Web UI or the agent’s tools. If you are the only user on your laptop, the single-user guides above are enough—you do not need the SSH-tunnel, key-segregation, and shared-workspace decisions below.

Decide first: one host, or one install each

Mode Fits Real cost
Each laptop runs dsh Sensitive repos, separate edits Everyone needs Node/egress; configs drift
One host + SSH tunnel to UI Shared eval box, one plugin tree You share that OS user’s shell and chosen workspace
Expose 3080 on LAN/public Almost never Preview Web has no solid login wall—open file/command surface

“Share one instance” means share one process and host-user privilege, not SaaS multi-tenancy. Do not expect per-user isolation from the preview.

Web deploy for a team: preferred path

On the host, start with npx @deepseek-ai/dsh web (or pnpm dsh web from a checkout). Default listen is http://127.0.0.1:3080—loopback only. Safe team pattern:

  1. Run dsh on a fixed eval machine or VPS; keep loopback bind.
  2. Teammates use SSH local forwarding (remote 3080 → local 3080) and open the local URL.
  3. Use --no-open when supported so SSH sessions do not try to launch a remote browser; trust the printed URL.
  4. If the port is taken, use the supported --port flag and update the tunnel map.

Docs mention dsh web --host 0.0.0.0 for LAN; some preview CLIs refuse it. Even when allowed, put authenticating reverse proxy or a private overlay in front—a naked reverse proxy is not auth. Flags follow the current upstream repo.

Keys, env, sessions: what you may share

  • API key: Host usually reads process env → managed credentials → workspace .env → ~/.dsh/.env. Keep an org key only on the host with tight perms; never commit or paste into chat. One key = one billing/leak face.
  • Workspace: The UI-selected directory is the agent’s read/write/exec boundary. Shared folders need a clear “who may write” rule; prefer per-person clones + PRs.
  • Sessions: Logs often under host ~/.dsh/sessions/. A shared instance shares session footprints—check confidentiality before co-hosting.
  • Plugins / profile: Web profile under ~/.dsh/profiles/web/. One host is easier to reproduce than five drifted installs; backup profiles before preview upgrades.

Bottom line: sharing a host key/instance can be OK; sharing an unbounded workspace plus an unauthenticated entry is not.

Where Clash Verge actually sits

Path Who generates it Where Clash belongs
Open Web UI Browser ↔ host:3080 (often local via SSH) Usually no laptop proxy needed just to view UI
Model API Harness on the host DeepSeek API often direct; fix host egress if not
Tools / npm / git / overseas docs Host shell and children On the dsh host: Tun or HTTP(S)_PROXY on the start shell

Laptop Clash + bare host yields “UI fine, tools dead.” Host Clash verified means tunnel viewers need not re-proxy for tool egress. Steps: Harness + Clash Verge; overview Tun & AI; builds download center. Clash “Allow LAN” shares the proxy port—not the Harness control plane (Allow LAN).

Team habits that reduce pain

  • One layer per day: first prove the tunnel opens UI; then run a host egress smoke. Do not change key, node, and --host together.
  • Tight permissions: start with read-only tasks; confirm the workspace is not production data before write/exec.
  • Pin the preview: record npm package version or git commit on a shared host so surprise npx upgrades do not look like “it broke overnight.”
  • Attribute failures: UI down → tunnel/port/process; auth errors → key; tool timeouts with empty connections → host proxy; hits but still fail → node or target.
  • Alongside Claude/Codex: one Clash install can serve all; accept each product separately.

Also: FAQ, guide.

Acceptance and stop rules

Pass: agreed path opens UI; keys stay on the host; read-only smoke works; overseas tools leave host Clash connection records. Stop: do not publish unauthenticated 3080; do not disable corporate EDR for convenience; change only tunnel, key, or proxy per attempt. Backup ~/.dsh/ and the workspace before preview jumps—do not reinstall Clash as superstition.

The host that runs the agent needs egress

Harness shells and tools use the host network. Install Clash Verge Rev on that machine and run the proxy acceptance checklist.