Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #cordis#deepseek-harness#dsh-plugin#multi-tenant#saas#ai-agents

dsh-multi-tenant

DeepSeek Harness(DSH)多租户原语:租户身份、不可变会话所有权、失败闭合授权和可替换的所有权存储契约。

guomonth @guomonth ⬇ 2 ★ 6 main

安装

dsh plugin --profile web add github:guomonth/dsh-multi-tenant
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

DeepSeek Harness(DSH)多租户原语:租户身份、不可变会话所有权、失败闭合授权和可替换的所有权存储契约。

该插件未提供要点说明,请参考仓库 README。

cordisdeepseek-harnessdsh-pluginmulti-tenantsaasai-agents
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/guomonth/dsh-multi-tenant
许可证MIT
主要语言main
下载量2
GitHub 星标6
最近推送2026-08-19
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-03),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

[简体中文](./README.zh-CN.md) | English

# dsh-multi-tenant

Composable multi-tenant plugin primitives for
[DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) (DSH).

> **Phase: kernel prerelease line.** `0.1.0-rc.1` is publicly published; the
> current convergence candidate is **`0.1.0-rc.2`**. The DSH target remains
> **`0.1.0-rc.7`**. See [ROADMAP.md](./ROADMAP.md) and
> [`docs/reference/release.md`](./docs/reference/release.md).

## What this is

A **plugin family with a small kernel**, not a promise to implement an entire
SaaS platform. `dsh-multi-tenant` owns only the tenant/session primitives this
repository can enforce directly: minimal tenant/user identity, immutable session
ownership, fail-closed authorization, and the `TenantSessionStore` provider
contract.

Other capabilities enter the project only when their boundary is real and useful.
A DSH/third-party dependency is handled through a minimal contract/conformance
proposal; a surface we cannot reliably enforce is documented as a boundary
instead of being absorbed into a local fork.

## Guiding principles

- **Control → enforce** — strict fail-closed rules with executable invariants.
- **Ecosystem → standardize** — define the smallest useful seam/contract and collaborate upstream.
- **Outside control → bound** — state the threat-model/support boundary plainly. Complexity is not evidence.
- **Fast-follow prereleases** — pin explicit DSH prereleases and revalidate only affected seams.
- **One-way dependency** — no JWT/PostgreSQL/HTTP/MCP/Redis dependency in the kernel.
- **Default ≠ only** — replaceable providers prove conformance with the shared contract suite.

## Release scope

- `dsh-multi-tenant` — published kernel: ownership, authorization, store seam, testing utilities.
- `dsh-multi-tenant-web` — private experimental enforcement spike; production principal binding waits for a DSH request/connection-scope seam.

The 0.1 line does **not** claim shell/filesystem/process/container/network
isolation, billing/UI/organization management, host-global resource tenancy,
general RBAC, or cross-user team ACLs. Roles/permissions are deliberately not
part of the kernel `TenantPrincipal`.

## Packages

| Package | Distribution | Role |
| --- | --- | --- |
| [`packages/multi-tenant`](./packages/multi-tenant) | npm `dsh-multi-tenant@next` | Kernel: `ctx.multiTenant` + `ctx.tenantSessionStore`, claim-once ownership, fail-closed authorization, provider contract/testing. |
| [`packages/multi-tenant-web`](./packages/multi-tenant-web) | private workspace | Experimental tenant-bound `ApiProxy` research; production principal binding is DSH-transport-gated. |

See [CONTRIBUTING.md](./CONTRIBUTING.md) for development policy and
[`docs/specs/architecture.md`](./docs/specs/architecture.md) for layer ownership.

## Development

```sh
pnpm install
pnpm typecheck
pnpm test
pnpm build
```

## License

MIT

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。