OutLawZhangSan-liii/dsh-tailnet-gateway ↗★ 0
dsh-tailnet-gateway
Reach a loopback-bound DeepSeek Harness from your own Tailscale devices, gated on the identity tailscaled stamps. Dependency-free plugin; binds loopback only. 适合需要在异地通过Tailscale安全访问本地DSH服务的用户。
インストール
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:OutLawZhangSan-liii/dsh-tailnet-gatewayドキュメント
README 全文を読む ↗Configuration
| Key | Default | Meaning |
|---|---|---|
enabled | true | Run the listener at all. |
host | 127.0.0.1 | Bind address. Clamped to loopback; a non-loopback value is refused. |
port | 7242 | The port tailscale serve publishes. 0 requests an OS-assigned port. |
requireLogin | true | Demand the Tailscale identity. Turning this off makes the listener an open loopback proxy. |
allowedLogins | [] | Tailscale logins allowed. Empty means any account on the tailnet. |
allowedPeers | [] | Optional per-device gate: tailnet IPs as tailscale status reports them. |
upstreamPort | 3080 | The dsh web port being fronted. |
Hardening
On a single-user tailnet the defaults are already correct. To narrow further,
fill allowedPeers with your phone's tailnet address — that is what makes
"my phone, never that VPS" expressible even when the VPS is signed in as you:
config:
upstreamPort: 3080
allowedLogins: ['you@example.com']
allowedPeers: ['100.64.0.7']
Fill it before relying on it: a peer allowlist that does not match the
machine you are calling from locks you out of the tailnet surface. The local
desktop at 127.0.0.1:3080 still works, so the fix is a local edit.