jumpserver-east/jumpserver-dsh
JumpServer DSH
Operate JumpServer assets through KoKo. Traffic does not bypass the bastion. Command filters, ACL, and session recording still apply.
Install
npx @deepseek-ai/dsh plugin --profile web add github:jumpserver-east/jumpserver-dshRestart `dsh web` after install. Bundle APIs can change during the developer preview.
README badge
[](https://dshhub.dev/plugins/jumpserver-dsh)Paste this into your README. The star count updates with every catalog sync.
From the README
Excerpt from jumpserver-east/jumpserver-dsh, cleaned of badges and images.
jumpserver-dsh
DeepSeek Harness 插件:让 agent 通过 JumpServer 管理资产,并经 KoKo 堡垒在资产上执行命令 / 读写文件。流量不直连资产 IP,命令过滤、ACL、会话审计仍然生效。
本版本支持 SSH / SFTP 主机,以及经 KoKo 的 数据库(MySQL、MariaDB、PostgreSQL、Redis、MongoDB、Oracle、SQL Server 等)。RDP / 图形协议不在范围内。未授权时数据库会话只能查询;INSERT / UPDATE / DELETE 等写操作需要显式打开 JUMPSERVER_ENABLE_DB_WRITE。
兼容版本
插件调用 JumpServer Core REST API v1(Access Key 签名、用户资产授权、connection-token、client-url、主机资产 CRUD)。Core 与 KoKo 须为同一发行版本。
| 产品 | 支持的版本 |
|---|---|
| JumpServer | v3.10 LTS(v3.10.0 ~ 当前 v3.10.22)、v4.10 LTS(v4.10.0 ~ 当前 v4.10.18) |
| DeepSeek Harness | >= 0.1.0-rc.6(开发预览,接口可能变化) |
安装
dsh plugin 会把命令转给 pnpm,在目标 profile 目录里装包。本机需要 Node.js、pnpm(macOS 可用 brew install pnpm),以及 DeepSeek Harness CLI。
dsh 不是系统自带命令。没装过全局包时用:
npx @deepseek-ai/dsh <子命令>
也可以 npm install -g @deepseek-ai/dsh,之后直接打 dsh。不要用 Homebrew 的 dsh 配方,那是另一个 Unix 工具。
下面命令里的 dsh 都可以换成 npx @deepseek-ai/dsh。web profile 的配置在 ~/.dsh/profiles/web/(Windows 为 %USERPROFILE%\.dsh\profiles\web\)。
从 npm 安装
dsh plugin --profile web add @jumpserver-east/jumpserver-dsh
0.1.1 起已内置不带原生编译脚本的 ssh2,从 npm 安装一般不必改 allowBuilds。刚发布的 24 小时内,pnpm 11 可能报 ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION,等过截止时间或临时加 minimumReleaseAge: 0。
从 GitHub 安装
dsh plugin --profile web add github:jumpserver-east/jumpserver-dsh
pnpm 会把仓库拉到临时目录,先跑插件自己的 pnpm install,再执行 prepare(tsc)。实测会依次碰到两道拦:
- 构建授权
报ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED。把 pnpm 打印的 key 写进该 profile 的pnpm-workspace.yaml后重跑:
allowBuilds:
jumpserver-dsh: true
若打印的是带 tarball URL 的长 key,按它原样加一行。
- 包太新
报ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION。pnpm 11 默认拒绝 lockfile 里发布时间不足约 24 小时的包。DeepSeek Harness 刚发 rc 时,@deepseek-ai/*很容易踩中。
可以等过截止时间再装,或在该 profile 的pnpm-workspace.yaml里临时加minimumReleaseAge: 0后重试。也可以改走下面的本地安装——本地link:不会在临时目录里按插件 lockfile 再装一遍。
可以用 github:jumpserver-east/jumpserver-dsh#<sha> 钉死提交。
从本地仓库安装
适合改插件,或 GitHub 安装被年龄检查拦住时。
cd jumpserver-dsh
pnpm install --config.minimum-release-age=0
pnpm build
dsh plugin --profile web add .
--config.minimum-release-age=0 只在本仓库 pnpm install 也触发同样检查时需要;包够老了可以去掉。add . 必须在仓库目录执行(. 相对的是当前工作目录,不是 profile 目录)。
成功后 profile 的 package.json 应类似:
{
"dependencies": {
"@jumpserver-east/jumpserver-dsh": "link:/绝对路径/jumpserver-dsh"
},
"dsh": {
"profile": {
"bundles": [
"@deepseek-ai/dsh-base",
"@deepseek-ai/dsh-web-app",
"@jumpserver-east/jumpserver-dsh"
]
}
}
}
dsh plugin add 会自己核对 bundles。若命令很慢或中途失败,可以在 profile 目录直接 link,再把 @jumpserver-east/jumpserver-dsh 写进 dsh.profile.bundles:
cd ~/.dsh/profiles/web
pnpm add /绝对路径/jumpserver-dsh
改本地代码后执行 pnpm build,再重启 dsh。
本地 add . 是 link:,一般不必再为 ssh2 改 allowBuilds。GitHub 安装仍要批准插件自己的 prepare(tsc)。
配置
dsh 的「插件配置」页不会根据插件 Config 自动出表单,目前只展示 Host 白名单里的官方卡片(Shell、Agent loop、Web search)。第三方插件进不了这一页,所以 JumpServer 没有设置页。装好后新建下面的 .env,再重启 dsh。
需配置 — $DSH_HOME/.env
dsh 主目录默认为:
- macOS / Linux:
~/.dsh - Windows:
%USERPROFILE%\.dsh
在该目录新建 .env(安装插件时不会自动生成,可对照本仓库的 .env.example):
…
