Back to home@bloodtmai-cmyk

dsh-harness-enterprise

面向企业内部管控的 DeepSeek Harness 统一智能工作台入口

Stars
0
Language
TypeScript
Created
Aug 20, 2026
Updated
Aug 20, 2026
GitHub repo

Introduction

Harness Enterprise

A managed DeepSeek Harness entry point for internal enterprise use.
It combines enterprise sign-in, AI Hub policy, approved capabilities, audit delivery, and a hardened desktop runtime.

Independent community project based on DeepSeek Harness. It is not affiliated with, sponsored by, or endorsed by DeepSeek AI.

English | 中文

What this repository is

Harness Enterprise keeps the standard DeepSeek Harness runtime and adds an optional managed desktop distribution. It is intended for organizations that need one internal AI workbench entry point while retaining control over identity, model access, MCP services, Skills, plug-ins, enterprise instructions, updates, and conversation audit delivery.

The project is deliberately not an identity provider, MDM product, business-data proxy, or replacement for downstream authorization. AI Hub governs what the desktop may discover and use; business systems remain responsible for their own data permissions.

Components

ComponentResponsibility
Standard HarnessUpstream-compatible Web, Host, agent, tools, and plug-in runtime. Users may configure supported third-party model providers.
Harness Enterprise DesktopElectron shell, enterprise sign-in, Hub synchronization, local runtime hardening, managed updates, and local personal memory.
DSH AI HubSeparate control plane for authorization, model access records, managed artifacts, instructions, releases, and audit.
Enterprise GatewayPluggable authentication and MCP gateway. It validates identity and enforces current Hub policy at tools/list and tools/call.

Managed model access

The two model modes stay separate:

  • Standard Harness retains its native third-party Provider, Base URL, and API Key settings.
  • Managed desktop hides manual model credentials. AI Hub supplies the Provider identifier, OpenAI-compatible gateway URL, and API Key as one authorization record.
  • A cached Key is usable only while Hub still reports an active authorization with complete endpoint metadata.
  • LiteLLM is one possible gateway implementation, not a requirement.

See the desktop documentation for the security and runtime contract.

Run from source

Prerequisites: Node.js 24 and pnpm 11.7.0.

corepack enable
pnpm install --frozen-lockfile
pnpm run build
pnpm dsh web

The standard Web UI listens on http://127.0.0.1:3080 by default. The managed desktop additionally requires a configured AI Hub, enterprise Gateway, and OpenAI-compatible model endpoint:

pnpm run desktop:dev

This repository publishes source code only. It does not provide signed macOS or Windows installers.

Development

pnpm run typecheck
pnpm test
pnpm run verify-third-party-notices
pnpm run verify-translation-pairing
pnpm run verify-community-sanitization

Start with the development guide, architecture documentation, and community release checklist.

Upstream and license

The core runtime comes from DeepSeek Harness and preserves its MIT attribution. This repository is independently maintained by clanie.

Licensed under the MIT License. Third-party terms are recorded in THIRD_PARTY_NOTICES.md. Security reports should follow SECURITY.md.