sandbase-harness
sandbaseai
Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:ch3vr0n5/dsh-docker-services
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
Open-source-ready guarded Docker operations for DeepSeek Harness (DSH). The repository separates the DSH client plugin from a privileged controller. It is for teams that want useful inventory, health, resources, logs, lifecycle, parameter, secret, and deploy controls without exposing raw Docker, shell, or remote-host access to the UI or model.
npm ci --ignore-scripts
npm run ci
cp examples/controller.json /etc/dsh-docker-services/controller.json
cp examples/proxy.json /etc/dsh-docker-services/proxy.json
Then replace the example values, create the dedicated controller account and hooks, and follow deployment instructions. Read the threat model before granting Docker/socket access.
packages/plugin: DSH plugin; no Docker or secret filesystem access.packages/controller: privileged allowlist enforcement and adapters.packages/proxy: unprivileged fixed-identity HMAC bridge for one Harness domain.packages/shared: versioned protocol and configuration validation.examples: host unit, container deployment, and generic configuration.This project intentionally does not ship a universal deploy script: deployment semantics are workload-specific and must be reviewed as administrator-owned, fixed hooks. See releasing for artifact separation.
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: devops、docker。