DeepSeek Harness image powered by Websoft9
149
/workspace as the initial workspace directory.W9_URL to the real external hostname you use to open the app, otherwise DSH may reject browser API calls with HTTP 403.DSH_TRUSTED_HOSTS defaults to ${W9_URL}. If the app is reachable by more than one browser authority, extend it as a comma-separated list.W9_DEEPSEEK_API_KEY_SET during installation if you want the built-in DeepSeek provider to work immediately after the first boot.DSH_FORCE_LOOPBACK_UI=true by default so the public Websoft9 URL can open the Models/settings pages without requiring an SSH tunnel.token= query parameter in the container logs on startup.401 Unauthorized, open the container logs and copy the latest dsh web: http://127.0.0.1:3081/?token=... URL suffix.http://127.0.0.1:3081 with your Websoft9 access URL, then open that URL in the browser.ssh -N -L 3081:127.0.0.1:3081 root@YOUR_SERVER_IP
http://127.0.0.1:3081/?token=... with the latest token printed in the container logs./workspace unless you accept the risk.Websoft9 packages this app from the official DeepSeek Harness Docker image and makes some improvements below.
/var/lib/dsh./workspace and is backed by a dedicated named volume.W9_DEEPSEEK_API_KEY_SET as the install-time input and maps it to the container's DEEPSEEK_API_KEY environment variable.W9_URL is used as the trusted browser host for DSH's Host/Origin security checks and should match the real access domain or host:port.DSH_TRUSTED_HOSTS can add extra allowed browser authorities when the app is accessed through multiple domains, IPs, or forwarded ports.DEEPSEEK_BASE_URL is unrelated to browser access. It overrides the outbound LLM API endpoint used when DSH talks to a DeepSeek-compatible model provider.DSH_FORCE_LOOPBACK_UI=true treats the public browser page like a loopback management surface, enabling Host-backed settings such as Models/provider configuration.${W9_REPO}:${W9_VERSION} image; the local Dockerfile is kept for repository-controlled image builds, not for docker compose up on the target host.Apps run as containers; rebuild after any configuration change.
Supported versions: 0.1.7-rc.2, latest.
The latest tag is not guaranteed to remain valid; pin a specific version for production.
| Purpose | Port |
|---|---|
| Web Console | 3080 |
Data is kept inside the container; a named volume is recommended for persistence.
Environment variables are defined in the app's .env file; see the reference section at the end of .env for supported variables.
Configuration files live inside the image; mount a single file read-only to override, and never replace the whole directory.
DeepSeek Harness Administrator Guide by Websoft9
App fails to start?
docker compose logs.Port not reachable?
Root page returns 401 Unauthorized?
token= login URL from docker compose logs dsh and open it through the published Websoft9 URL.UI keeps showing Connecting or /api/... returns 403?
W9_URL to the exact external hostname or host:port used by the browser, then redeploy so DSH trusts that Host/Origin.DSH_TRUSTED_HOSTS and redeploy.Models page says no API key for deepseek-official?
W9_DEEPSEEK_API_KEY_SET and redeploy, or enter the key later through Settings -> Models when the current upstream build allows the onboarding flow.Settings page says settings are unavailable in this browser or 加载提供商目录失败?
DSH_FORCE_LOOPBACK_UI=true, so the public Websoft9 URL should be able to open Host-backed settings such as the Models/provider directory.DSH_FORCE_LOOPBACK_UI=true and redeploy, or use loopback access through an SSH tunnel.Content type
Image
Digest
sha256:bd8ff1d69…
Size
370 MB
Last updated
1 day ago
docker pull websoft9dev/dsh:0.1.7-rc.2