For teams, DeepSeek Harness blockers are rarely “what is it?” They are: how to share the Web UI, whether one instance is safe, how to split keys and workspaces, and where the proxy belongs. Install/concepts live elsewhere: what it is, npx one-command, source install, Clash proxy. This page is team operations only.
Who this page is for
Read this when more than one person needs the Web UI or the agent’s tools. If you are the only user on your laptop, the single-user guides above are enough—you do not need the SSH-tunnel, key-segregation, and shared-workspace decisions below.
Decide first: one host, or one install each
| Mode | Fits | Real cost |
|---|---|---|
| Each laptop runs dsh | Sensitive repos, separate edits | Everyone needs Node/egress; configs drift |
| One host + SSH tunnel to UI | Shared eval box, one plugin tree | You share that OS user’s shell and chosen workspace |
| Expose 3080 on LAN/public | Almost never | Preview Web has no solid login wall—open file/command surface |
“Share one instance” means share one process and host-user privilege, not SaaS multi-tenancy. Do not expect per-user isolation from the preview.
Web deploy for a team: preferred path
On the host, start with npx @deepseek-ai/dsh web (or pnpm dsh web from a checkout). Default listen is http://127.0.0.1:3080—loopback only. Safe team pattern:
- Run dsh on a fixed eval machine or VPS; keep loopback bind.
- Teammates use SSH local forwarding (remote 3080 → local 3080) and open the local URL.
- Use
--no-openwhen supported so SSH sessions do not try to launch a remote browser; trust the printed URL. - If the port is taken, use the supported
--portflag and update the tunnel map.
Docs mention dsh web --host 0.0.0.0 for LAN; some preview CLIs refuse it. Even when allowed, put authenticating reverse proxy or a private overlay in front—a naked reverse proxy is not auth. Flags follow the current upstream repo.
Keys, env, sessions: what you may share
-
API key: Host usually reads process env → managed credentials → workspace
.env→~/.dsh/.env. Keep an org key only on the host with tight perms; never commit or paste into chat. One key = one billing/leak face. - Workspace: The UI-selected directory is the agent’s read/write/exec boundary. Shared folders need a clear “who may write” rule; prefer per-person clones + PRs.
-
Sessions: Logs often under host
~/.dsh/sessions/. A shared instance shares session footprints—check confidentiality before co-hosting. -
Plugins / profile: Web profile under
~/.dsh/profiles/web/. One host is easier to reproduce than five drifted installs; backup profiles before preview upgrades.
Bottom line: sharing a host key/instance can be OK; sharing an unbounded workspace plus an unauthenticated entry is not.
Where Clash Verge actually sits
| Path | Who generates it | Where Clash belongs |
|---|---|---|
| Open Web UI | Browser ↔ host:3080 (often local via SSH) | Usually no laptop proxy needed just to view UI |
| Model API | Harness on the host | DeepSeek API often direct; fix host egress if not |
| Tools / npm / git / overseas docs | Host shell and children | On the dsh host: Tun or HTTP(S)_PROXY on the start shell |
Laptop Clash + bare host yields “UI fine, tools dead.” Host Clash verified means tunnel viewers need not re-proxy for tool egress. Steps: Harness + Clash Verge; overview Tun & AI; builds download center. Clash “Allow LAN” shares the proxy port—not the Harness control plane (Allow LAN).
Team habits that reduce pain
-
One layer per day: first prove the tunnel opens UI; then run a host egress smoke. Do not change key, node, and
--hosttogether. - Tight permissions: start with read-only tasks; confirm the workspace is not production data before write/exec.
-
Pin the preview: record npm package version or git commit on a shared host so surprise
npxupgrades do not look like “it broke overnight.” - Attribute failures: UI down → tunnel/port/process; auth errors → key; tool timeouts with empty connections → host proxy; hits but still fail → node or target.
- Alongside Claude/Codex: one Clash install can serve all; accept each product separately.
Acceptance and stop rules
Pass: agreed path opens UI; keys stay on the host; read-only smoke works; overseas tools leave host Clash connection records. Stop: do not publish unauthenticated 3080; do not disable corporate EDR for convenience; change only tunnel, key, or proxy per attempt. Backup ~/.dsh/ and the workspace before preview jumps—do not reinstall Clash as superstition.