dsh-hub logo

dsh-hub

Free

JupyterHub-style multi-user front for DeepSeek Harness (dsh): PAM login, per-user isolated instances, cookie-routed HTTP/WS proxy — zero...

Quick Facts

Pricing
Free
19
views
0
favorites
Added
Aug 2026
Official URL
github.com

Tool overview

Overview

dsh-hub is a multi-user front for DeepSeek Harness (dsh) that follows the JupyterHub model. It provides PAM login, one isolated dsh instance per system user, and a cookie-routed HTTP/WebSocket proxy. It requires zero modifications to dsh, so upstream upgrades and per-user plugin installs continue to work. The architecture mirrors JupyterHub: PAM authentication, a spawner that runs dsh web with the user's uid/gid and a per-user DSH_HOME, and an HTTP proxy that routes HTTP and WebSocket traffic by session cookie. A built-in idle culler can terminate idle instances. The trust model uses origin-rewrite to present the proxy as a loopback same-origin client, with SameSite=Lax session cookies for CSRF protection. Isolation is enforced by running each dsh instance as the user's own uid/gid with DSH_HOME=~/.dsh, binding to 127.0.0.1 on a random port, and using an iptables owner-guard to drop connections from other local users. Login rate-limiting and an optional allow-list provide additional access control. Users access dsh-hub by browsing to http://<server-ip>:3080 and logging in with their system username and password. Conversations survive browser close because server-side drivers keep running in the spawned dsh process, and re-login reattaches to the same instance. Configuration is managed through environment variables, and production deployment uses systemd.

Features

  • AI assistant
  • Natural language interface
  • Workflow automation

Tags

ai-agent
deepseek
dsh
jupyterhub
multi-user
ai
ai assistant
automation

Use Cases

  • Teams use dsh-hub to provide each system user with an isolated DeepSeek Harness instance.

  • Teams use dsh-hub to authenticate users with their existing system credentials via PAM.

  • Teams use dsh-hub to access dsh through a browser without modifying dsh.

  • Teams use dsh-hub to keep dsh sessions running even after the browser is closed.

  • Teams use dsh-hub to enforce per-user isolation with separate uid/gid and iptables.

  • Teams use dsh-hub to restrict access to a specific set of users.

  • Teams use dsh-hub to automatically cull idle instances.

User Reviews

No reviews yet. Be the first to share your experience!

Rankings & collections