Deploying DeepSeek Harness Web for a Team
Gate host on loopback, members via SSH; version and secrets in the Runbook before anyone opens a browser.
For team use of DeepSeek Harness Web, start on a gate host (often 127.0.0.1:3080) and let members enter via SSH local forward. Pin Node/package versions; guard keys and workspaces. Do not bare-expose an unauthenticated Agent Web surface on the LAN. Write Chinese ops notes with a translation IME; install from the download page.
1 Teams need a reproducible Web entry, not ad-hoc npx on every laptop
Public quick start: npx @deepseek-ai/dsh web; UI often at http://127.0.0.1:3080. A team needs who starts it, which version, where keys live, and which workspace.
DeepSeek Harness (dsh) is in developer preview—deepseek.com/harness and github.com/deepseek-ai/deepseek-harness. Capabilities mount as plugins; Web is one UI shape. Preview builds rename flags and menus. Internal Runbooks must record verification date + package version, not a lone npx line.
One laptop on npx and another on an old source branch wastes the afternoon on “I have Trajectory, you don’t.” Pick a gate machine (hardware or controlled VM) before arguing about browsers.
2 Preferred topology: gate host listens on 3080, members use SSH forward
Loopback is not decoration—the Agent can touch files and shell, and keys sit with the process.
On the gate host, install the agreed Node major (README is strict), start Web with the pinned method, confirm 127.0.0.1:3080 locally, then set model provider and workspace in Settings.
Members should not hit an arbitrary NIC port. Use SSH local forwarding so remote 127.0.0.1:3080 maps to a local port, then open that URL. UI behavior matches a local launch without dumping an unauthenticated Web surface on the LAN.
If someone wants --host on all interfaces: read whether your build allows it and whether auth exists. Without auth and network policy, treat it as a lab experiment—not the default Runbook.
3 Keys, workspace, session dirs: checklist before “we’re live”
A loading Web UI is not the same as a safe shared entry.
Store API keys per official precedence (env or credential files under the dsh home—paths follow current docs). Never paste secrets into chat or Wiki screenshots. A redacted UI descriptor is not “safe to commit.”
Pre-split workspaces: read-only samples, writable sandboxes, production read-only mounts. The gate process cwd is what the Agent sees first; changing it is a published change, not a verbal aside.
Session logs often land under a user-level sessions tree (compression varies by version). Agree on backup and redaction—logs may hold prompts, tool output, and paths. On-call rotation hands off machine + OS user + workspace, not just a bookmark.
4 Ops writing with a translation IME—without reteaching mixed typing
Runbooks, incident notes, “don’t kill the process yet”—that is where the IME earns its keep.
Write Chinese ops text in Runbooks and on-call channels with a translation IME. Copy paths, package names, and CLI subcommands as English half-width originals so chat apps do not inject full-width junk.
System-level mixed-typing tips live in deepseek-harness-coding-input-method; this article does not repeat them. Keep deploy docs and secret edits in separate editors; do not test translation candidates inside password fields.
If one member cannot type in the browser or a remote-desktop session: use on-site app-specific / not-working guides before reinstalling Harness.
Continue Checking
FAQ
Can we bind Harness Web to 0.0.0.0 for the whole team?
The common default is loopback 127.0.0.1:3080—sensible, because the process holds model credentials and can touch the workspace. Whether all-interface binds are allowed depends on your dsh build and current docs. An unauthenticated bind is an Agent tool surface on the LAN. Safer default: run on a gate machine, members enter via SSH local forward.
npx or build from source for a team?
Solo trials can use npx @deepseek-ai/dsh web. For reproducibility and plugin work, clone the repo, follow official pnpm install/build, run pnpm dsh web, and pin versions in the internal Runbook. Preview releases break; chasing latest per laptop creates split worlds.
Port busy or browser did not open?
Change the port per your CLI help (docs often show a port flag), or open the printed URL manually. Blank pages: confirm the process is alive and the plugin tree is healthy (dump-config style commands follow your installed version) before blaming browser extensions.
Where does the translation IME fit in deployment?
Harness runs the Agent and Web UI. The IME only affects how you type Chinese ops notes in the browser, Wiki, or on-call chat. Mixed-typing basics live in a separate article; this one is deploy and boundaries. Install the IME from this site’s download page.
Finish the deploy checklist, then install the translation IME from the download page for Chinese Runbooks
If you are ready to install or update, return to the download page and verify the current public version, platform notes, and on-site release information.