dsh-multi-tenant
DeepSeek Harness(DSH)多租户原语:租户身份、不可变会话所有权、失败闭合授权和可替换的所有权存储契约。
guomonth
@guomonth
⬇ 2
★ 6
main
安装
dsh plugin --profile web add github:guomonth/dsh-multi-tenant
需要可复现安装时,可在仓库后追加 #commit 固定提交。
DeepSeek Harness(DSH)多租户原语:租户身份、不可变会话所有权、失败闭合授权和可替换的所有权存储契约。
该插件未提供要点说明,请参考仓库 README。
cordisdeepseek-harnessdsh-pluginmulti-tenantsaasai-agents
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/guomonth/dsh-multi-tenant |
| 许可证 | MIT |
| 主要语言 | main |
| 下载量 | 2 |
| GitHub 星标 | 6 |
| 最近推送 | 2026-08-19 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-03),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
[简体中文](./README.zh-CN.md) | English # dsh-multi-tenant Composable multi-tenant plugin primitives for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) (DSH). > **Phase: kernel prerelease line.** `0.1.0-rc.1` is publicly published; the > current convergence candidate is **`0.1.0-rc.2`**. The DSH target remains > **`0.1.0-rc.7`**. See [ROADMAP.md](./ROADMAP.md) and > [`docs/reference/release.md`](./docs/reference/release.md). ## What this is A **plugin family with a small kernel**, not a promise to implement an entire SaaS platform. `dsh-multi-tenant` owns only the tenant/session primitives this repository can enforce directly: minimal tenant/user identity, immutable session ownership, fail-closed authorization, and the `TenantSessionStore` provider contract. Other capabilities enter the project only when their boundary is real and useful. A DSH/third-party dependency is handled through a minimal contract/conformance proposal; a surface we cannot reliably enforce is documented as a boundary instead of being absorbed into a local fork. ## Guiding principles - **Control → enforce** — strict fail-closed rules with executable invariants. - **Ecosystem → standardize** — define the smallest useful seam/contract and collaborate upstream. - **Outside control → bound** — state the threat-model/support boundary plainly. Complexity is not evidence. - **Fast-follow prereleases** — pin explicit DSH prereleases and revalidate only affected seams. - **One-way dependency** — no JWT/PostgreSQL/HTTP/MCP/Redis dependency in the kernel. - **Default ≠ only** — replaceable providers prove conformance with the shared contract suite. ## Release scope - `dsh-multi-tenant` — published kernel: ownership, authorization, store seam, testing utilities. - `dsh-multi-tenant-web` — private experimental enforcement spike; production principal binding waits for a DSH request/connection-scope seam. The 0.1 line does **not** claim shell/filesystem/process/container/network isolation, billing/UI/organization management, host-global resource tenancy, general RBAC, or cross-user team ACLs. Roles/permissions are deliberately not part of the kernel `TenantPrincipal`. ## Packages | Package | Distribution | Role | | --- | --- | --- | | [`packages/multi-tenant`](./packages/multi-tenant) | npm `dsh-multi-tenant@next` | Kernel: `ctx.multiTenant` + `ctx.tenantSessionStore`, claim-once ownership, fail-closed authorization, provider contract/testing. | | [`packages/multi-tenant-web`](./packages/multi-tenant-web) | private workspace | Experimental tenant-bound `ApiProxy` research; production principal binding is DSH-transport-gated. | See [CONTRIBUTING.md](./CONTRIBUTING.md) for development policy and [`docs/specs/architecture.md`](./docs/specs/architecture.md) for layer ownership. ## Development ```sh pnpm install pnpm typecheck pnpm test pnpm build ``` ## License MIT
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。