DSH Plugins Marketplace

DSH Plugins

Plugins

/

Development & Infrastructure

/

dsh-pve

w

dsh-pve

Manifest valid

Manage Proxmox VE through conversation: 116 read + 116 write tools covering VMs, containers, storage, nodes, clusters, backups and firewalls, with API-token or username/password (ticket) auth.

UI (client)hasBundlePatch

dsh-pve

简体中文

A DeepSeek Harness plugin for inspecting and managing Proxmox VE (PVE) through conversation, authenticated with a PVE API token or a username/password (ticket) login.

Why dsh-pve

  • Inspect nodes, QEMU VMs, LXC containers, storage, network, firewall, cluster, backup, HA, replication, Ceph, users, groups, roles and pools through conversation.
  • Manage power state, clone, migrate, snapshot, resize and move disks, create/delete guests and storages, and manage backup/replication/firewall rules.
  • Every write operation triggers a mandatory native user-approval prompt — the model cannot bypass it.
  • Credentials (API token secret or login password) are kept in the local DSH credential store and never echoed back to the browser or the model.

Requirements

ComponentSupported baseline
Node.js20.11 or newer
DeepSeek Harness0.1.2-rc.1
Proxmox VEPVE2 JSON API (API Token auth on 6.0+, username/password ticket auth on 5.x)

Installation (for the agent)

Once installed, the agent gains 232 pve_* tools automatically.

Local development:

npm ci
dsh plugin --profile <name> add link:/absolute/path/to/dsh-pve

Published, pinned tag (recommended):

dsh plugin --profile <name> add github:we39/dsh-pve#v<version>

Development branch (testing only):

dsh plugin --profile <name> add github:we39/dsh-pve

Restart the selected profile after installation. For a no-packaging dev loop, load the overlay directly:

dsh --profile <name> --patch ./cordis.patch.yml

Configuration

In DSH Web: Settings → Plugins → Proxmox VE control.

FieldDescription
Base URLe.g. https://pve.example.com:8006
AuthenticationAPI Token (PVE 6.0+) or Username / password (PVE 5.x compatible)
Token IDuser@realm!tokenid, e.g. monitor@pve!dsh — token mode only
Token SecretThe token UUID; stored write-only — token mode only
Usernamee.g. root@pam — password mode only
PasswordThe login password; stored write-only — password mode only
Skip TLS verificationEnable for self-signed internal hosts (5.x and 6.0+)

PVE 6.0+ → create an API token (Datacenter → Permissions → API Token) with the least privilege required. PVE 5.x has no API token → switch to username/password mode.

Tools

232 tools (116 read-only / 116 write) across 13 domains. All write tools require native user approval.

DomainToolsScope
Cluster & overview8version, status, resources index, tasks, log, nextid, options
Nodes & tasks23status, config, services, disks, syslog, apt, SMART, task polling
Network12interface CRUD + reload, DNS, hosts, time
VMs (QEMU)22config, power, snapshot, clone, migrate, resize, move-disk, guest-agent, monitor
Containers (LXC)15config, power, snapshot, clone, migrate, resize
Storage11CRUD, content/volumes, upload, RRD
Firewall76rules / aliases / ipset / options / log across cluster·node·VM·CT scopes
Access control21users, groups, roles, domains, ACL
Pools5resource pools
HA13resources, groups, status, migrate / relocate
Backup6vzdump jobs + run-now
Replication9job CRUD, schedule-now, status / log
Ceph11status, OSD, pools, MON / MDS / FS, logs

See docs/tools.md for the full per-tool reference (name, method, path, description).

Async operations return a UPID:... task id — the agent polls pve_task_status / pve_task_log to confirm completion.

Security

  • Mandatory approval on every write operation — the model cannot bypass it.
  • Secrets, tokens, and passwords are redacted before any response reaches the model.
  • All PVE-returned data is treated as untrusted, never as instructions.

Development

npm install
npm run verify   # node --check + node:test

Structure

  • index.js — generic execution engine + full endpoint catalog + write-approval gateway
  • client.js — settings-page form card (slot key pve)
  • cordis.patch.yml — bundle patch (insert id pve / name dsh-pve)
  • docs/tools.md — full tool reference
  • test/index.test.js — node:test unit tests

Comments

Loading…

Similar plugins

dsh-perm-guard

Auto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 p

Security & AuditDevelopment & InfrastructureTerminal & ClientsManifest valid

★ 1

MIT

JavaScript

dsh plugin --profile web add dsh-perm-guard

by Unintendedz

Archive, cross-session read, and copy-ID tools for DeepSeek Harness conversations.

Manifest valid

★ 0

MIT

JavaScript

Sep 10, 2026

dsh plugin --profile web add dsh-session-tools

Multi-workspace manager: bind a docs anchor plus ordered code-project repositories into one session, injecting their absolute paths, a recursive file index, a server/client endpoint index and optional

UI & ExperienceManifest valid

★ 1

NOASSERTION

TypeScript

dsh plugin --profile web add dsh-workspace-combiner

by MrWeiCodes

Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions,

Security & AuditManifest valid

★ 10

↓ 415/wk

MIT

JavaScript

Sep 25, 2026

dsh plugin --profile web add @mrweicodes/dsh-permgate

by SanYe-SanJiu

Windows-only process control for the harness: a sidebar button that shuts DSH down through the host's own graceful exit path, an app-window / normal-tab switch on the Plugins card that rewrites the de

UI & ExperienceManifest valid

★ 0

MIT

JavaScript

Sep 24, 2026

dsh plugin --profile web add dsh-power-switch

by Earnest02522

Archived-conversation manager for DeepSeek Harness: view (grouped by workspace), restore, and reveal transcript folders of archived conversations. Zero-build, copy-to-install plugin.

Sessions & MessagesManifest valid

★ 6

↓ 367/wk

MIT

JavaScript

Aug 28, 2026

dsh plugin --profile web add dsh-archive-manager