
JupyterHub-style multi-user front for DeepSeek Harness (dsh): PAM login, per-user isolated instances, cookie-routed HTTP/WS proxy — zero...
dsh-hub is a multi-user front for DeepSeek Harness (dsh) that follows the JupyterHub model. It provides PAM login, one isolated dsh instance per system user, and a cookie-routed HTTP/WebSocket proxy. It requires zero modifications to dsh, so upstream upgrades and per-user plugin installs continue to work. The architecture mirrors JupyterHub: PAM authentication, a spawner that runs dsh web with the user's uid/gid and a per-user DSH_HOME, and an HTTP proxy that routes HTTP and WebSocket traffic by session cookie. A built-in idle culler can terminate idle instances. The trust model uses origin-rewrite to present the proxy as a loopback same-origin client, with SameSite=Lax session cookies for CSRF protection. Isolation is enforced by running each dsh instance as the user's own uid/gid with DSH_HOME=~/.dsh, binding to 127.0.0.1 on a random port, and using an iptables owner-guard to drop connections from other local users. Login rate-limiting and an optional allow-list provide additional access control. Users access dsh-hub by browsing to http://<server-ip>:3080 and logging in with their system username and password. Conversations survive browser close because server-side drivers keep running in the spawned dsh process, and re-login reattaches to the same instance. Configuration is managed through environment variables, and production deployment uses systemd.
Teams use dsh-hub to provide each system user with an isolated DeepSeek Harness instance.
Teams use dsh-hub to authenticate users with their existing system credentials via PAM.
Teams use dsh-hub to access dsh through a browser without modifying dsh.
Teams use dsh-hub to keep dsh sessions running even after the browser is closed.
Teams use dsh-hub to enforce per-user isolation with separate uid/gid and iptables.
Teams use dsh-hub to restrict access to a specific set of users.
Teams use dsh-hub to automatically cull idle instances.
Lynote combines AI-draft rewriting and AI-text detection with note-taking, transcription, video summaries, and study tools.
LMSYS Chatbot Arena is a crowdsourced open platform for LLM evals. Collected over 1,000,000 human pairwise comparisons to rank LLMs with the Bradley-Terry model and display the model ratings in Elo-scale.
Zhipu Qingyan is a GLM-based AI assistant whose official description emphasizes understanding goals, breaking down tasks, and using tools.
字节跳动AI助手