Skip to content
dsh.fish
Bundle

dsh-provider-proxy

Provider-scoped HTTP/HTTPS forward proxy middleware for DeepSeek Harness LLM requests

Source
stayhpjinng
License
MIT
Updated
Updated 2 days ago

Readme

# dsh-provider-proxy

DeepSeek Harness LLM middleware that sends only selected provider routes
through an HTTP or HTTPS forward proxy. Other providers keep using the normal
network path, including when requests run concurrently.

The plugin targets DSH `0.1.1-rc.2` and Node `^22.19.0 || >=24`. It is useful
when `HTTP_PROXY` plus `NODE_USE_ENV_PROXY=1` is too broad because that switch
changes networking for the whole DSH process.

## Install

```sh
dsh plugin --profile web add /absolute/path/to/dsh-provider-proxy
```

The package installs as a DSH bundle but stays dormant until a provider proxy
is enabled.

## Settings UI

After restarting `dsh web`, open **Settings → Provider 代理**. Every available
provider has its own:

- on/off switch;
- proxy URL or proxy-URL environment variable;
- optional proxy-authorization environment variable;
- save and reset controls.

Turning a switch off takes effect for new requests immediately and retains the
fields for later use. Streams already in progress are allowed to finish on the
dispatcher they started with. No YAML edit or DSH restart is required for
settings changes.

## Configure one provider

Edit `$DSH_HOME/profiles/web/cordis.patch.yml`:

```yaml
- id: provider-proxy
  config:
    providers:
      openrouter:
        enabled: true
        proxyUrl: http://127.0.0.1:7890
```

The key under `providers` must be the DSH provider route, not the upstream
hostname or model name. For example, a request whose selection is
`openrouter / anthropic/claude-...` uses the `openrouter` key.

To keep the proxy URL outside the profile:

```yaml
- id: provider-proxy
  config:
    providers:
      anthropic:
        enabled: true
        proxyUrlEnv: DSH_ANTHROPIC_PROXY_URL
```

Then start DSH from a shell containing:

```sh
export DSH_ANTHROPIC_PROXY_URL=http://127.0.0.1:7890
dsh web
```

For an authenticated proxy, keep the authorization header in another
environment variable:

```yaml
- id: provider-proxy
  config:
    providers:
      anthropic:
        enabled: true
        proxyUrl: https://proxy.example.com:8443
        proxyAuthorizationEnv: DSH_ANTHROPIC_PROXY_AUTH
```

`DSH_ANTHROPIC_PROXY_AUTH` contains the complete `Proxy-Authorization` value,
for example `Basic <base64-user-colon-password>`. Credentials embedded in a
proxy URL are rejected so they cannot appear in profile dumps.

Set `enabled: false` (or turn off the UI switch) to keep a provider direct
without deleting its proxy fields.

## Scope and limitations

- Supports HTTP and HTTPS forward proxies using Undici `ProxyAgent`.
- Does not support SOCKS or PAC proxy URLs.
- Covers provider implementations that use `globalThis.fetch`, including the
  native DSH DeepSeek adapter and the common fetch-based pi-ai providers.
- Also wraps DSH's `llm.discoverModels()` path, so Models → “Fetch available
  models” uses the selected Provider's proxy when that request names a
  provider route.
- If that Provider already has a non-empty static `models` list, DSH returns
  the catalog without network I/O by design; clear that list when you want to
  probe the provider endpoint and observe the proxy connection.
- It does not rewrite `baseURL`. API relays/reverse proxies should be configured
  directly on the provider instead.
- Provider SDKs that bypass Fetch and open sockets directly need a dedicated
  transport integration; this middleware deliberately does not enable a
  process-wide proxy fallback.

Install

dsh plugin --profile web add github:stayhpjinng/dsh-provider-proxy#7da2ef0923017223f0cf4c88822ca6d55b9c2e2f

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
Source