tensorlakeai/dsh-tensorlake-sandbox

A deepseek harness plugin for tensorlake sandbox

@tensorlakeai/dsh-sandbox moves DeepSeek Harness file, subprocess, Bash, terminal, and LSP operations into one short-lived Tensorlake microVM: sandbox-aware Bash execution delegates to the Tensorlake subprocess provider while still satisfying the permission-preset capability contract, and the model-facing working directory is the same remote Linux path. It is an installable dsh bundle and does not require changes to the Harness installation. Credentials (TENSORLAKE_API_KEY, DEEPSEEK_API_KEY, other credential-shaped env vars, DSH_* variables) are never copied into sandbox processes.

Infrastructure & Deployment ★ 6 updated 2026-08-14 ⏳ pending
View on GitHub ↗

Install

npm install --global @deepseek-ai/dsh && dsh plugin --profile headless add @tensorlakeai/dsh-sandbox

npm package @tensorlakeai/dsh-sandbox 0.1.0 (registry-verified 2026-08-24). Install dsh and add the bundle to the profile you run: npm install --global @deepseek-ai/dsh, dsh plugin --profile headless add @tensorlakeai/dsh-sandbox, then TENSORLAKE_API_KEY=... DEEPSEEK_API_KEY=... dsh --profile headless "build and test this repo". Development: npm install && npm run build && dsh plugin --profile headless add . from a checkout. Verify with dsh --profile headless --dump-config: the layer disables the host subprocess and fs-sandbox providers, inserts the Tensorlake runtime/subprocess/filesystem rows, and keeps bash-sandbox mounted in danger-full-access mode. Requires a Tensorlake project with TENSORLAKE_API_KEY and DEEPSEEK_API_KEY in the host environment.

Compatibility

Node.js ^22.19.0 or >=24.0.0, @deepseek-ai/dsh 0.1.0-rc.6 or later. Moves file, subprocess, Bash, terminal, and LSP operations into one short-lived Tensorlake microVM; no changes to the Harness installation. Config fields: apiKey (TENSORLAKE_API_KEY), cwd (/home/tl-user/workspace), timeoutSecs (600), cpus, memoryMb, diskMb; DSH_TENSORLAKE_CWD overrides the shared workspace. Ephemeral sandbox starts on profile boot and terminates when dsh exits. Known limitation: tensorlake@0.5.103 pins undici@8.3.0 and nanoid@3.3.11 with high-severity advisories (npm audit) — review upstream advisories before production use.

Details

Recent updates

The current English README documents: prerequisites, install, smoke test (pwd/id/file-read expectations), configuration table, cordis.patch.yml overrides, runtime requirements (the managed Ubuntu image with bash/Node/GNU coreutils), known limitations (transitive advisory pins), development, and the three Loader entry points.

FAQ

Does it require changes to the Harness installation?
No — @tensorlakeai/dsh-sandbox is an installable dsh bundle; it replaces the host subprocess and fs-sandbox providers with Tensorlake-backed ones inside the profile composition.
What runs inside the microVM?
File, subprocess, Bash, terminal, and LSP operations run in one short-lived Tensorlake microVM with a shared Linux working directory (default /home/tl-user/workspace). The sandbox is created on profile boot and terminated when dsh exits.
Are my API keys exposed to the sandbox?
No — the package never copies TENSORLAKE_API_KEY, DEEPSEEK_API_KEY, other credential-shaped environment variables, or DSH_* variables into sandbox processes. Keep credentials in environment variables or a secret manager.

Alternatives

flymysql/dsh-remote · MAXeaglet/dsh-bash-terminal · AcidGr/dsh-web-lan-access

More plugins in Infrastructure & Deployment

Browse more in Infrastructure & Deployment

Guides for Infrastructure & Deployment plugins