dsh-maestro-remote
Remote access for DeepSeek Harness: cloudflared tunnel, LAN and public proxies with a PIN gate, QR pairing and Maestro PWA branding
- Stars
- 1
- Language
- TypeScript
- Created
- Aug 25, 2026
- Updated
- Oct 6, 2026
Introduction
@ddtcorex/dsh-maestro-remote
Remote access plugin for the DeepSeek Harness: a Cloudflare tunnel (quick or named) plus a LAN remote proxy so a DSH session can be reached from outside the machine, gated by a second PIN with QR provisioning.
Part of the Maestro Harness suite (dsh-maestro-*). Three Cordis patch rows:
dsh-maestro-remote-rpc (loopback RPC), dsh-maestro-tunnel (the tunnel and LAN proxy provider)
and maestro-patch (the zero-fork patch shim absorbed from dsh-maestro-patch).
What it provides
- Tunnel lifecycle (
maestroTunnelservice): start/stop/status of a cloudflared quick tunnel or a named tunnel with a single ingress to the PIN-gated remote proxy, which exempts/hooks/gitlab-mrand/hooks/gitlab-mr/triggerfrom the PIN so GitLab can post webhooks; auto-restore of a previously running named tunnel on boot. - Remote proxy: request handler for the tunnel target with PIN auth (constant-time comparison), reloadable config.
- cloudflared fetcher: resolves the binary from PATH or installs it into a cache dir.
Settings
Config persists through the embedded settings store: a committed, hash-sealed copy of
dsh-maestro-core's store (src/host/vendor/store.ts), reading and writing the shared
namespaced document ~/.dsh/dsh-maestro-config/settings.json through a flat
MaestroUserConfig adapter, see src/host/config-store.ts. This package does not depend on a
published settings library. Machine runtime state
(lastTunnelRunning) deliberately lives in this package's own sidecar
(~/.dsh/dsh-maestro-remote/runtime.json) so editing settings can never silently flip
tunnel state.
Install
dsh plugin --profile web add @ddtcorex/dsh-maestro-remote
Development
pnpm install
pnpm verify # tsc --noEmit
pnpm test # vitest run
pnpm build # tsc host + tsc client + esbuild bundle -> lib/ and lib/client.js
A tunnel change must be validated live (real start/stop + proxy round-trip), not just by unit tests — see AGENTS.md.
License
MIT