Files
nexus/knowledgebase/DeepSeek Harness 远程访问配置.md
2026-08-30 20:34:33 +08:00

71 lines
2.7 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#deepseek #dsh #deepseek-harness #web #profile #remote-access #Configuration
## 1. 配置局域网或公网访问
修改配置文件:`~/.dsh/profiles/web/cordis.patch.yml` 添加或修改为 host: '0.0.0.0' 和 port: 3080。
``` YAML
- id: webserver
config:
host: '0.0.0.0'
port: 3080
```
**如何查看当前的生效配置?** 官方 CLI 文档提供了一个非常实用的命令,如果你想验证自己对 `cordis.patch.yml` 的修改是否正确被系统合并,可以运行:
``` bash
dsh --profile web --dump-config
```
这会在终端打印出合并所有 patch 补丁后的完整配置树,你可以直接在里面检查 `webserver` 节点下的 `host` 和 `port` 是否已经被成功改写为 `0.0.0.0` 和你想要的端口。
## 2. 解决 crypto.randomUUID 报
原因:浏览器在非安全上下文(非 127.0.0.1 的 HTTP 环境)下禁用了该 API。
### 方法一:改用 SSH 端口转发(最推荐、最简单)
无需修改服务器任何配置,直接通过 SSH 将服务器的 3080 端口映射到你本地电脑。 在你的**本地电脑**终端运行:
Bash
```
ssh -N -L 3080:127.0.0.1:3080 用户名@你的服务器IP
```
建立连接后,在本地浏览器访问 `[http://127.0.0.1:3080](http://127.0.0.1:3080)`。由于使用的是 `127.0.0.1`,浏览器会开放 `crypto` 权限,工作区将恢复正常。
### 方法二:强制浏览器信任该 IP(适合局域网测试)
- 在浏览器地址栏输入并打开:
- Chrome 浏览器: `chrome://flags/#unsafely-treat-insecure-origin-as-secure`
- Edge 浏览器: `edge://flags/#unsafely-treat-insecure-origin-as-secure`
- 找到 **Insecure origins treated as secure** 选项。
- 在下方的文本框中输入你远程访问的完整地址,例如:`http://192.168.3.189:3080`(请替换为实际 IP 和端口)。
- 将右侧的下拉菜单改为 **Enabled**。
- 点击右下角的 **Relaunch** 重启浏览器。重启后,该地址下的 `crypto.randomUUID` 就能正常使用了。
### 方法三:配置反向代理开启 HTTPS(适合长期/团队使用)
如果你需要让多人通过外网稳定访问,最好的办法是不要让 DSH Web 直接暴露在 HTTP 环境,而是用 Nginx 或 Caddy 在它前面挡一层,并配置 SSL 证书。
以 **Caddy**(最简单的反向代理工具)为例:
1. 在服务器上安装 Caddy。
2. 编写 `Caddyfile`:
Plaintext
```
你的域名.com {
reverse_proxy 127.0.0.1:3080
}
```
3. 启动 Caddy,它会自动为你配置免费的 HTTPS 证书。通过 `[https://你的域名.com](https://你的域名.com)` 访问即可完美绕过该限制。