DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-docker-services

c

dsh-docker-services

Discovered

Portable DeepSeek Harness plugin for securely monitoring and operating Docker services

DeepSeek Harness Docker Services

Open-source-ready guarded Docker operations for DeepSeek Harness (DSH). The repository separates the DSH client plugin from a privileged controller. It is for teams that want useful inventory, health, resources, logs, lifecycle, parameter, secret, and deploy controls without exposing raw Docker, shell, or remote-host access to the UI or model.

What it provides

  • Inventory displays controlled and unmanaged containers, status/health, resource fields, image/digest, deployment repo/branch/SHA/time/test state, and an optional internal or Tailscale URL.
  • Per-service action allowlists cover logs, start/stop/restart, schema-driven non-secret parameters, and write-only secret status/set/rotate/test.
  • Deploy calls are exact-revision guarded (repo, branch, full SHA), leased and idempotent. Only authoritative hook output can supply image digest, verified reachability/branch binding, deployment time, and passing test state.
  • Local Docker, constrained SSH helper, and mTLS JSON adapter reference implementations; all use typed operations only.
  • Signed trusted-proxy identity/RBAC, bounded opaque errors, protected redacted logs, fsynced hash-chained audit with keyed checkpoints, atomic no-follow writes, package/consumer/container checks, and CI.
  • A fixed-identity local proxy gives Harness only a private, authenticated socket; the signing key and controller socket remain outside Harness.

Quick start

npm ci --ignore-scripts
npm run ci
cp examples/controller.json /etc/dsh-docker-services/controller.json
cp examples/proxy.json /etc/dsh-docker-services/proxy.json

Then replace the example values, create the dedicated controller account and hooks, and follow deployment instructions. Read the threat model before granting Docker/socket access.

Project layout

  • packages/plugin: DSH plugin; no Docker or secret filesystem access.
  • packages/controller: privileged allowlist enforcement and adapters.
  • packages/proxy: unprivileged fixed-identity HMAC bridge for one Harness domain.
  • packages/shared: versioned protocol and configuration validation.
  • examples: host unit, container deployment, and generic configuration.

This project intentionally does not ship a universal deploy script: deployment semantics are workload-specific and must be reviewed as administrator-owned, fixed hooks. See releasing for artifact separation.

Comments

Loading…

Similar plugins

dsh-dev-toolbox

by Qingzhou-Joshua

DeepSeek Harness plugin—a simple toolkit for developers.

Manifest valid

★ 0

MIT

TypeScript

Aug 14, 2026

dsh plugin --profile web add dsh-dev-toolbox

by sugarforever

DeepSeek Harness Plugin for Lark Integration

Tools & CapabilitiesManifest valid

★ 26

↓ 172/wk

MIT

TypeScript

Sep 7, 2026

dsh plugin --profile web add @sugarforever/dsh-lark

by elonnzhang

DeepSeek Harness plugin for session-scoped system prompt inspection

Terminal & ClientsSessions & MessagesManifest valid

★ 1

MIT

TypeScript

Sep 28, 2026

dsh plugin --profile web add dsh-system-prompt

by Decodo

DeepSeek Harness (dsh) plugin: Decodo as the provider behind the built-in web_fetch tool

Manifest valid

★ 0

MIT

TypeScript

Oct 9, 2026

dsh plugin --profile web add @decodo/dsh-web-fetch

by openma-ai

mcp apps support plugin for dsh (DeepSeek Harness)

Manifest valid

★ 3

MIT

TypeScript

Aug 22, 2026

dsh plugin --profile web add @openma/dsh-mcp-apps

by Skylarking

DeepSeek Harness plugin: desktop plugin inventory

Manifest valid

★ 0

TypeScript

Aug 20, 2026

dsh plugin --profile web add @skylarking/dsh-client-ui-desktop-plugin-inventory