DSH Plugins Marketplace

DSH Plugins

Plugins

/

Security & Audit

/

dsh-jumpserver

d

dsh-jumpserver

Manifest valid

Query and manage JumpServer through conversation: assets, users, accounts, permissions, sessions, command audit logs, command filters, and RBAC roles, authenticated with an AccessKeyID/AccessKeySecret

UI (client)hasBundlePatch

dsh-jumpserver

简体中文

A DeepSeek Harness plugin for querying and managing JumpServer assets through conversation, authenticated with a JumpServer AccessKeyID/AccessKeySecret pair (HTTP Signature).

Why dsh-jumpserver

  • Inspect JumpServer assets, users, accounts, permissions, sessions, command audit logs, user groups, command filters, asset-tree nodes, and RBAC roles/bindings through conversation.
  • Manage assets, accounts, users, permissions, user groups, command groups, command filters, asset-tree nodes, and custom RBAC roles/bindings, plus password/MFA/SSH-key resets for users.
  • Every write operation triggers a mandatory native user-approval prompt — the model cannot bypass it.
  • Secrets, passwords, public keys, MFA secrets, and account passphrases are redacted from read responses before they reach the model.
  • Authenticate with JumpServer's native HTTP Signature scheme (hmac-sha256); the AccessKeySecret stays in the local DSH credential store.

Requirements

ComponentSupported baseline
Node.js20.11 or newer
DeepSeek Harness0.1.2-rc.1
JumpServerREST API v1 (Access Key authentication)

Installation (for the agent)

For local development, install from the local path:

npm ci
dsh plugin --profile add link:/absolute/path/to/dsh-jumpserver

Once published, install a released, immutable tag whenever possible:

dsh plugin --profile add github:we39/dsh-jumpserver#v<version>

Install the mutable development branch only for testing:

dsh plugin --profile add github:we39/dsh-jumpserver

Restart the selected DSH profile after installation. On Windows, use an absolute link:C:/path/to/dsh-jumpserver path.

Configuration

In DSH Web, open Settings → Plugins → JumpServer asset lookup.

Configure:

  • JumpServer URL: the absolute base URL, for example https://jumpserver.example.com.
  • Access Key: create one from the JumpServer web console under your personal API Key list.
  • Secret Key: paired with the Access Key above.

The Access Key/Secret Key use DSH's privileged loopback credential RPC — write-only, the stored values are never read back or displayed. The URL is stored in the jumpserver settings namespace as a non-secret field, so it is read back in plaintext and shown in the card for verification.

HTTP and HTTPS both work out of the box — internal deployments without TLS certificates can use an http:// URL with no extra setup. To enforce HTTPS only, disable it in plugin configuration:

allowInsecureHttp: false

The credential reference names default to JUMPSERVER_ACCESS_KEY_ID / JUMPSERVER_ACCESS_KEY_SECRET and can be changed with akRef / skRef in the plugin configuration.

JumpServer permissions

Create the AccessKey under a JumpServer account that only has read access to the assets you want visible to the assistant. Avoid using a super-admin account's key for this integration.

Tools

53 tools (12 read-only / 41 write) across 10 domains. All write tools require native user approval.

DomainToolsScope
Assets5assets, details, create/update/delete
Users7users, details, create/update/delete, password/MFA/SSH-key reset
Accounts5asset accounts, details, create/update/delete
Permissions5asset-permission rules, details, create/update/delete
Sessions & Audit2terminal sessions, command audit logs
User Groups5groups, details, create/update/delete
Command Groups5command-pattern groups, details, create/update/delete
Command Filters5security filters, details, create/update/delete
Asset Tree6nodes, details, create/update/delete, move
RBAC8roles, bindings, create/update/delete

See docs/tools.md for the full per-tool reference (name, method, path, description).

Session termination and ticket approval are intentionally out of scope.

Security and data boundaries

  • The AccessKeySecret never enters tool arguments, model messages, logs, or Git.
  • Account secrets/passphrases and user passwords/public keys/MFA secrets are explicitly excluded from every read tool's output, field by field.
  • Authenticated requests reject HTTP redirects to avoid forwarding signed requests to another origin.
  • Non-loopback HTTP is disabled by default (see allowInsecureHttp).
  • Requests have cooperative cancellation, timeouts, and bounded response sizes.
  • Error responses expose only a bounded status/detail description.
  • id parameters are validated as JumpServer UUIDs before being placed in a request path, preventing path injection.
  • All returned fields (names, addresses, comments, usernames, etc.) are treated as untrusted data, not model instructions.

Development

npm ci
npm run verify

Tests use Node's built-in test runner and mocked JumpServer responses.

Structure

  • index.js — generic execution engine + full endpoint catalog + write-approval gateway
  • client.js — settings-page form card (slot key jumpserver)
  • cordis.patch.yml — bundle patch (insert id jumpserver / name dsh-jumpserver)
  • docs/tools.md — full tool reference
  • test/index.test.js — node:test unit tests

License

MIT

Comments

Loading…

Similar plugins

dsh-session-control

by GooDAnDReaDY

Session management for the DeepSeek Harness sidebar: pin and label conversations, search their contents, jump by keyboard, read and export archived transcripts

UI & ExperienceTerminal & ClientsSessions & MessagesManifest valid

★ 0

↓ 275/wk

MIT

JavaScript

Sep 26, 2026

dsh plugin --profile web add @goodandready/dsh-session-control

by slywalker2006

Server-grade gateway that turns DeepSeek Harness into a multi-tenant platform: remote access + auto HTTPS, subuser permissions & quotas, sandbox enforcement, encrypted auth, audit log.

Security & AuditManifest valid

★ 66

GPL-3.0

TypeScript

Sep 29, 2026

dsh plugin --profile web add dsh-passwords

by Asaiuta

Aggregate and natively control multiple remote DeepSeek Harness (DSH) servers' sessions from one official Web UI — hub gateway + official-UI bridge. 多服务器 DSH 会话聚合与原生操控

Terminal & ClientsManifest valid

★ 4

↓ 111/wk

MIT

JavaScript

Aug 15, 2026

dsh plugin --profile web add dsh-session-hub

by PerryLink

Pushes DSH approval and question cards to IM channels (WeChat first) and answers them from chat, with a session console, per-channel security, and an open push service.

Tools & CapabilitiesTerminal & ClientsManifest valid

★ 0

↓ 666/wk

Apache-2.0

TypeScript

Sep 25, 2026

dsh plugin --profile web add dsh-reach

by JohnXu22786

Safe, audited SQLite/PostgreSQL/MySQL access for dsh agents: schema introspection, enforced read-only queries, a write approval gate, and a durable JSONL SQL audit trail.

Tools & CapabilitiesManifest valid

★ 1

↓ 107/wk

MIT

TypeScript

Sep 29, 2026

dsh plugin --profile web add dsh-db-connector

by XiLuovo

Session timeline down the left of the conversation: every user message at a glance, current-message tracking, hover preview of the message and its reply, click to jump, collapsible.

UI & ExperienceSessions & MessagesManifest valid

★ 4

↓ 107/wk

MIT

JavaScript

Aug 24, 2026

dsh plugin --profile web add dsh-session-timeline