Skip to the content.

Task book for your AI

← English docs · 中文

Copy the whole block below, replace the <...> placeholders with your own values, and hand it to any coding agent (Codex, dsh, …).

I want to run the official DeepSeek Harness (dsh) on GitHub Codespaces, and I want you to set up both the
cloud side and my local machine.

[ABOUT ME]
- GitHub username: <your-username>
- Private repo I already created: <your-username>/<repo-name>
- Codespace name: <copy it from https://github.com/codespaces>
- Local machine: Windows 11, normal user (no admin)
- I pay for usage with my own DeepSeek API key

[GOALS]
1. Double-clicking one script on my machine opens the cloud dsh web UI — no typing commands.
2. The cloud workspace is a clone of my private repo, and changes are committed + pushed automatically.
3. Do not change system settings, do not require admin, and do not install global software (keep it portable).
4. Keep permissions conservative: new sessions default to workspace-write + ask, no auto review.

[PLEASE DO]
A. In the container (Codespaces)
   - Install Node 22 (>=22.19) and @deepseek-ai/dsh
   - Put three scripts in /workspaces/<repo>/.dsh-cloud/:
       start.sh   ensure dsh is running; last line prints the token URL
       update.sh  upgrade dsh and restart
       sync.sh    idle-batched auto sync (debounce, three modes, generated commit messages,
                  empty-dir .gitkeep handling, config in sync.conf)
   - Create a deploy key scoped to <your-username>/<repo-name> only (not an account token)
   - Clone the workspace to ~/dsh-workspace and make git use that deploy key
   - Write the dsh permission presets: defaultPreset=workspace-write, keep read-only,
     and change danger-full-access approval from never to ask
B. On my machine
   - Download a portable GitHub CLI (unzip into a local folder; do not install system-wide)
   - Walk me through one `gh auth login` (scopes: codespace,repo,read:org,workflow)
   - Generate the SSH key as *me* (Windows rejects keys created by other users)
   - Create a start launcher and an update launcher, with icons, on my desktop:
       start: check/wake the Codespace → run start.sh → gh codespace ports forward 3080:3080
              → open the token URL
       update: run update.sh → same tunnel → open the browser
C. Verify and tell me the result
   - dsh is up in the container (401 without a token, 303 with one)
   - the tunnel opens the dsh UI from my machine
   - the workspace pushes successfully (local HEAD == remote main)

[KNOWN PITFALLS — PLEASE FOLLOW]
1. GitHub's *.app.github.dev URL does not work for dsh: credentials are bound to 127.0.0.1:3080.
   Use `gh codespace ports forward 3080:3080 -c <name>` and the token URL dsh prints.
2. Keep .bat files pure ASCII, use %USERPROFILE% for paths, and give log files ASCII names.
3. The SSH private key must be generated by the person using the machine, in %USERPROFILE%\.ssh.
4. Never use `pkill -f "dsh web"` (it kills its own shell). Find the PID by port instead:
   `ss -ltnp | grep :3080`.
5. git does not track empty directories — the sync script must add .gitkeep first.
6. /workspaces is persistent but $HOME is not: keep scripts in /workspaces.
7. Very long one-shot commands get truncated over a PTY: write files (base64) and avoid a TTY.
8. Whether dsh can read images depends on the model: deepseek-v4-pro is text-only, deepseek-flash
   accepts images (it is the model's declared inputModalities, not a global image switch).

[DELIVERABLES FOR ME]
- Two desktop launchers (start / update)
- A short "how do I use this next time" note
- The cloud scripts committed into my repo (tools/dsh-cloud/) so a new computer can reuse them