runzhliu/deepseek-harness-docker

Community Docker and Kubernetes packaging for DeepSeek Harness (@deepseek-ai/dsh), with a hardened image, Comp

deepseek-harness-docker packages a pinned Harness runtime for Docker Compose, direct Docker use, headless jobs, and Kubernetes. The hardened image runs as uid 1000, stores DSH state separately from the mounted workspace, drops Linux capabilities, enables no-new-privileges, and uses a read-only root with tmpfs. Compose adds loopback-only Web and browser ports plus health checks; the Helm chart uses a single StatefulSet, persistent volume, service, and NetworkPolicy so the append-only session store is not accidentally scaled across writers.

Web UI Enhancements ★ 25 updated 2026-09-21 ✅ runtime-tested
View on GitHub ↗

Install

docker compose pull && DSH_WORKSPACE=/absolute/path/to/your/project docker compose up -d --no-build

Replace the workspace placeholder with an explicit absolute project path. The Compose Web service binds to loopback and persists DSH_HOME; inspect compose.yaml before launch.

Compatibility

Docker on linux/amd64 or linux/arm64; Docker Compose for a local single-user Web instance; Helm for a single-replica Kubernetes StatefulSet. The Web UI has no authentication and must not be directly exposed to a LAN or the public Internet.

Details

Recent updates

The current repository verifies amd64 and arm64 builds, native PTY startup, Compose health and restart persistence, strict Helm lint, pinned rc.6 builds, and a smoke path covering CLI, effective configuration, browser assets, and HTTP reachability.

FAQ

How do I start the Compose deployment?
From the repository, run docker compose pull and then DSH_WORKSPACE=/absolute/path/to/project docker compose up -d --no-build.
Can I expose its Web port publicly?
No. The README says the Web UI has no authentication and must remain a local single-user service unless a separate trusted access layer is added.
Why is the DSH version pinned?
The repository warns that release candidates change quickly; a fixed version keeps builds and failures reproducible.

Alternatives

AlliotTech/deepseek-harness-docker · hongfeiyucode/deepseek-harness-desktop · 6Mikao9/dsh-wsl-workspace

More plugins in Web UI Enhancements

Browse more in Web UI Enhancements

Guides for Web UI Enhancements plugins