dsh-deployment-rollback-proof
Manifest validOffline content-addressed proof that failed deployments converged to one last-known-good artifact
DSH Deployment Rollback Proof
Offline, deterministic evidence that every declared deployment target stopped serving one failed artifact and converged within RTO to the same last-known-good digest.
This plugin does not execute rollback, authenticate receipts, grant authorization, observe live infrastructure, or prove application correctness. It verifies an explicit, hash-only manifest. That boundary is deliberate:
dsh-rollbackrestores file mutations; this plugin never mutates a deployment.dsh-recovery-proofverifies isolated recovery drills; this plugin verifies post-incident deployment-target convergence.- The DeepSeek Harness rollback handbook is a runbook; this plugin produces a machine-readable settlement verdict.
dsh-artifact-promotion-proofproves positive promotion settlement; this plugin proves failed-version removal and last-known-good restoration.
Evidence model
The manifest declares the failed digest, last-known-good digest, incident/authorization/plan receipt hashes, RTO and freshness limits, exact target set and replica counts. One observation per target binds a rollback receipt and health-probe hash to the incident and plan. The verifier checks:
- exact target coverage and contiguous observation sequence;
- minimum distinct observers;
- environment binding and one last-known-good digest across all targets;
- zero active failed-artifact replicas and exact known-good replica convergence;
- incident/plan binding, chronology, RTO and evidence freshness.
Only hashes, counts, timestamps and verdicts enter the report. Keys named like secret, authorization, raw, body, content, log, prompt or chat, plus secret-shaped values, are rejected.
Use
npm test
node bin/dsh-deployment-rollback-proof.mjs inspect examples/rolled-back.json
node bin/dsh-deployment-rollback-proof.mjs verify examples/rolled-back.json
DSH installs the bundle from cordis.patch.yml and exposes:
dsh_deployment_rollback_inspectdsh_deployment_rollback_verify
The standalone stdio MCP server exposes deployment_rollback_inspect and deployment_rollback_verify. The DSH verifier writes only beneath an explicit workspace-relative artifactDir, rejects path escape/symlinks, creates a content-addressed report exclusively, and verifies it by read-back.
Manifest
See examples/rolled-back.json. Inputs are claims bound by hashes, not authenticated facts. A rolled-back verdict means only that the supplied structured evidence satisfies the declared policy.
Security
See SECURITY.md. Node.js 22 or later is required. Licensed under MIT.
Comments
Loading…
From the same category
by zhu1090093659
DeepSeek Harness (DSH) Web Plugin Aggregation Ecosystem · Everything is a plugin, distributed via the Creative Workshop
★ 8.3k
↓ 203/wk
Apache-2.0
TypeScript
Oct 3, 2026
dsh plugin --profile web add dsh-webA collection of independent Web UI plugins and skins, including task boards, Git graphs, mobile access, and live token stats.
★ 7.4k
↓ 203/wk
Apache-2.0
TypeScript
dsh plugin --profile web add dsh-webby dsh-market
The plugin market inside DeepSeek Harness — browse, search, one-click install · DSH 可视化插件市场
★ 5.4k
↓ 165.2k/wk
MIT
TypeScript
Oct 2, 2026
dsh plugin --profile web add dshmarketby crafter-station
A public gallery of animated pets for Codex, Claude Code, DeepSeek Harness, Hermes, OpenCode, Gemini CLI, and more.
★ 4.2k
MIT
TypeScript
Sep 28, 2026
by superdesigndev
OpenRouter for agent tools. Join community here: https://discord.gg/6mQYYfFMAn
★ 4.1k
NOASSERTION
Python
Oct 3, 2026
dsh plugin --profile web add treg-dshby xiaobright
Two-phase DeepSeek Harness preset: Minimal-aligned bootstrap, then full Standard tools (Project2 98/99)
★ 3.8k
JavaScript
Sep 10, 2026