dsh-jumpserver
JumpServer connector for DSH Desktop 0.2.x: conversation-isolated SSH/PTY sessions, audited operations, and native settings/sidebar console. 适合需要通过 SSH/PTY 安全连接 JumpServer 并执行审计操作的用户。
같은 패키지 이름의 다른 저장소
설치
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:pc439527/dsh-jumpserver配置(设置页)
| 配置 | 默认 | 说明 |
|---|---|---|
| 启用 JumpServer | true | 关闭后所有工具返回 DISABLED |
| host / port | - / 2222 | 传输网关 |
| username | - | JumpServer 登录用户名 |
| password / passwordEnv | 只写 SecretField / JUMPSERVER_PASSWORD | 写入凭据域(credential-ref),连接时解析、不缓存,永不进入任何响应 / 日志 / 终端 / tool result |
| profiles / activeProfileId | [] / - | 多账号 { id, label, host, port, username, passwordEnv },选中者优先 |
| hostFingerprint / knownHostsPath | - / ~/.dsh/jumpserver/known_hosts.json | 固定指纹 / TOFU 存储 |
| connectTimeout / commandTimeout / idleTimeout | 15s / 60s / 30min | 连接 / 命令 / 空闲超时 |
| permissionMode | READ_ONLY | 只读 / AUTO / 完全开放 |
| privilegedReadInReadOnly | false | READ_ONLY 下是否放行 sudo + 只读命令 |
| manualPermissionMode | CONFIRM_MODIFY | 人工终端输入策略(FOLLOW_AGENT / CONFIRM_MODIFY / FULL_ACCESS) |
| allowedTargets / deniedTargets | [] / [] | 目标范围;deny 优先 |
| batchConcurrency / maxSessions | 1 / 4 | 单次批量并行目标数 / 同时进入目标数上限 |
| timeZone | Asia/Shanghai | 审计时间显示时区(存储始终 UTC) |
| assetCacheTtlSeconds / assetGroups | 300 / {} | 资产缓存时长 / 资产组别名 |
| runbooks | {} | 命名 runbook:{ title, steps[] },可带 expect 断言 |
| riskJudge | {} | 可选语义裁决,默认关闭;API Key 只经 credential-ref 解析 |
| consoleEnabled / consolePort | true / 8766 | 内置控制台,仅绑定 127.0.0.1;端口被占用时自动回退到随机回环端口 |
| autoReconnect / enableAudit | true / true | 空闲断线自动重连 / 命令审计 |
| autoOpenTerminal / terminalScrollback | true / 5000 | 授权后自动打开控制台 / 终端保留行数 |