OutLawZhangSan-liii/dsh-tailnet-gateway ↗★ 0

dsh-tailnet-gateway

Reach a loopback-bound DeepSeek Harness from your own Tailscale devices, gated on the identity tailscaled stamps. Dependency-free plugin; binds loopback only. 适合需要在异地通过Tailscale安全访问本地DSH服务的用户。

Package
dsh-tailnet-gateway
Compatibility
Unverified
Version
0.1.0
License
MIT
Last updated
Sep 28, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:OutLawZhangSan-liii/dsh-tailnet-gateway

Configuration

KeyDefaultMeaning
enabledtrueRun the listener at all.
host127.0.0.1Bind address. Clamped to loopback; a non-loopback value is refused.
port7242The port tailscale serve publishes. 0 requests an OS-assigned port.
requireLogintrueDemand the Tailscale identity. Turning this off makes the listener an open loopback proxy.
allowedLogins[]Tailscale logins allowed. Empty means any account on the tailnet.
allowedPeers[]Optional per-device gate: tailnet IPs as tailscale status reports them.
upstreamPort3080The dsh web port being fronted.

Hardening

On a single-user tailnet the defaults are already correct. To narrow further, fill allowedPeers with your phone's tailnet address — that is what makes "my phone, never that VPS" expressible even when the VPS is signed in as you:

      config:
        upstreamPort: 3080
        allowedLogins: ['you@example.com']
        allowedPeers: ['100.64.0.7']

Fill it before relying on it: a peer allowlist that does not match the machine you are calling from locks you out of the tailnet surface. The local desktop at 127.0.0.1:3080 still works, so the fix is a local edit.