ai-eks/dsh-auth-tunnel
Password-gated public access for the DSH Web GUI through quick or named Cloudflare Tunnels, with HTTP/WebSocket proxying and an in-app directory picker.
Exposes the DeepSeek Harness Web GUI through a password-protected Cloudflare Tunnel without modifying deepseek-harness itself. The bundle inserts and enables the auth-tunnel row in quick mode and replaces the Host-native directory picker with an in-app browser picker — no source edit or extra profile row required. Long random shared password is stored as a DSH credential and every request is gated through it.
Install
dsh plugin --profile web add dsh-auth-tunnel@nextdsh plugin --profile web add dsh-auth-tunnel@next (npm dsh-auth-tunnel 0.1.0-rc.8, verified npm 2026-08-31). Git source: dsh plugin --profile web add github:ai-eks/dsh-auth-tunnel (targets Harness 0.1.1-rc.2; older Harness pins need an immutable tag, e.g. #v0.1.0-rc.8). Requires cloudflared on PATH and a shared password stored as a DSH credential.
Compatibility
DSH web profile (created if missing); requires dsh CLI + pnpm on PATH and cloudflared; password stored in $DSH_HOME/.credentials.yaml as DSH_WEB_PASSWORD; MIT.
Details
- Repo: ai-eks/dsh-auth-tunnel
- Category: Development & Runtime
- Stars: 4
- Version: npm dsh-auth-tunnel 0.1.0-rc.8
- Last push: 2026-08-31
- First seen: 2026-08-14
Recent updates
Password-gated Cloudflare Tunnel for the Web GUI; quick-mode default with in-app browser picker; credential-based shared password; no deepseek-harness source edits.
FAQ
- Do I need a Cloudflare account?
- You need the cloudflared binary on PATH (or an absolute executable configured for the plugin). The plugin creates the Web profile when it is missing.
- How is the password stored?
- Store DSH_WEB_PASSWORD: '<long-random-password>' in $DSH_HOME/.credentials.yaml (defaults to ~/.dsh). The plugin reads it as a DSH credential.
- Which Harness versions are supported?
- The main branch targets Harness 0.1.1-rc.2; Harness 0.1.0-rc.8 and earlier must pin a compatible immutable tag or revision (e.g. #v0.1.0-rc.8 for rc.8).
Alternatives
xbzbing/dsh-auth-gateway · suntianc/dsh-codex-auth · dongsheng123132/dsh-policy-drift-proof