LangBot Deployment Guide
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser…
$ npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install runzhliu/deepseek-harness-docker deepseek-harness-docker --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deepseek-harness-docker" agent skill from https://github.com/runzhliu/deepseek-harness-docker/tree/main into .claude/skills/deepseek-harness-docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepseek-harness-docker", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install runzhliu/deepseek-harness-docker deepseek-harness-docker --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deepseek-harness-docker" agent skill from https://github.com/runzhliu/deepseek-harness-docker/tree/main into .agents/skills/deepseek-harness-docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepseek-harness-docker", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install runzhliu/deepseek-harness-docker deepseek-harness-docker --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deepseek-harness-docker" agent skill from https://github.com/runzhliu/deepseek-harness-docker/tree/main into .cursor/skills/deepseek-harness-docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepseek-harness-docker", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install runzhliu/deepseek-harness-docker deepseek-harness-docker --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deepseek-harness-docker" agent skill from https://github.com/runzhliu/deepseek-harness-docker/tree/main into .gemini/skills/deepseek-harness-docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepseek-harness-docker", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install runzhliu/deepseek-harness-docker deepseek-harness-dockerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deepseek-harness-docker" agent skill from https://github.com/runzhliu/deepseek-harness-docker/tree/main into .github/skills/deepseek-harness-docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepseek-harness-docker", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install runzhliu/deepseek-harness-docker deepseek-harness-docker --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deepseek-harness-docker" agent skill from https://github.com/runzhliu/deepseek-harness-docker/tree/main into .opencode/skills/deepseek-harness-docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepseek-harness-docker", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deepseek-harness-dockerDeploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser…
Deepseek Harness Docker is an agent skill from runzhliu/deepseek-harness-docker. Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser, optional protected LAN gateway, optional ungoogled-chromium image, and optional plugin market. Use when users ask to run DSH or DeepSeek Harness locally or on a trusted LAN or Kubernetes, mount a writable workspace, configure model credentials safely, enable the embedded browser, minimize browser background egress, choose…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 71 other files, including scripts and assets (for example `.github/dependabot.yml`, `.github/workflows/ci.yml` and `.github/workflows/dockerhub-description.yml`).
It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Docker, DeepSeek and Kubernetes. The repository describes itself as: Community Docker and Kubernetes packaging for DeepSeek Harness (@deepseek-ai/dsh), with a hardened image, Compose stack, Helm chart, Web UI, and headless CLI. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9984408. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
dockermakecurlhelmkubectlgitpodmanFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, curl, helm, kubectl and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DEEPSEEK_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deepseek Harness Docker loads about 2.7k tokens when it runs. Until then it costs about 153 tokens; SKILL.md has 1,153 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
s settings page, environment variables, `.env`, or Kubernetes Secrets. Never write credentials into Dockerfiles, images,Follow the `.env.lan.example` and README procedure. Generate the bcrypt hash without recording its plaintext, keep `.envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from runzhliu/deepseek-harness-docker at commit 9984408, republished under its MIT licence (© runzhliu). 1,153 words, ~2,692 tokens.
.claude/skills/deepseek-harness-docker/SKILL.md (or your agent's skills folder). This skill also uses 69 other files; get the full folder from GitHub.Use the public runzhliu/deepseek-harness-docker project as the source of truth. Treat it as a community containerization project around the official @deepseek-ai/dsh npm package, not as an official DeepSeek image.
3080 and noVNC port 6080 to 127.0.0.1 only. For an explicit trusted-LAN request, use compose.lan.yaml; never publish the native ports.-p 3080:3080, privileged container, or Docker socket mount..env, or Kubernetes Secrets. Never write credentials into Dockerfiles, images, Compose files committed to Git, logs, or answers.dsh-home volume unless the user explicitly asks to delete all Harness settings, credentials, sessions, and browser state.Use the current checkout when it contains compose.yaml and Dockerfile. Otherwise clone the public repository:
git clone https://github.com/runzhliu/deepseek-harness-docker.git
cd deepseek-harness-dockerRead README.md, SECURITY.md, compose.yaml, and .env.example before changing defaults. Prefer the repository's pinned image and DSH versions; do not silently switch to latest.
Use default Compose for a local, single-user WebUI with the embedded Debian Chromium desktop. The image attaches official Playwright MCP Browser Use to the same persistent Chromium used for visible human takeover. Add compose.lan.yaml only for an explicit trusted-LAN request, after choosing one exact bind address, an internal DNS name or IP, a Caddy Basic Auth credential, and a firewall boundary. This mode uses caddy:2.11.4-alpine and still represents one shared trust domain, not multi-tenancy. Select the immutable 0.2.1-alpha.2-r1-ungoogled.1 tag only when the user explicitly prioritizes minimized Google background egress and accepts its contributor-binary and reduced browser-service tradeoffs. Add compose.market.yaml only when the user explicitly wants the community plugin market. Use headless mode for one-shot automation and Helm only when the user requests Kubernetes.
Use compose.bwrap.yaml and immutable image 0.2.1-alpha.2-r1-bwrap.1 only when a Docker host cannot enforce Landlock and the user accepts seccomp=unconfined plus systempaths=unconfined. First distinguish a kernel with Landlock omitted from the active LSM list from a kernel built without Landlock; prefer enabling the existing LSM when possible. Never add SYS_ADMIN, --privileged, or the Docker socket. Require unprivileged user namespaces, run make bwrap-smoke, and confirm /workspace writes succeed while writes to the test's separate outer writable mount fail. Do not apply this overlay to rootless Podman or Kubernetes.
For an explicitly rootless Podman deployment, require Podman 4.5 and podman-compose 1.6.0 or newer, then add compose.podman.yaml. Confirm podman info --format '{{.Host.Security.Rootless}}' returns true. The overlay maps the caller to container UID/GID 1000 and privately labels the workspace on SELinux hosts; authorize one dedicated project directory and never broaden the mount to a shared home or filesystem root. Use make podman-smoke when validation is requested.
Follow the .env.lan.example and README procedure. Generate the bcrypt hash without recording its plaintext, keep .env.lan private, bind DSH_LAN_BIND_ADDRESS to one exact server LAN IP, and prefer an internal DNS name for DSH_LAN_HOST. Start with make lan-up, install the persistent Caddy internal CA root on authorized clients, and use the DSH launch token only through the resulting HTTPS URL. Verify with make lan-smoke. Tell the user that all authenticated clients share the same Harness authority and that mutually untrusted users need isolated instances and volumes.
Confirm Docker and Compose are available:
docker version
docker compose versionResolve the requested workspace to an absolute path and confirm it is the intended writable directory.
Pull and start without rebuilding unless the user asks for a local source build:
DSH_WORKSPACE=/absolute/path/to/project docker compose pull
DSH_WORKSPACE=/absolute/path/to/project docker compose up -d --no-build
docker compose psWait for the deepseek-harness service to become healthy. Verify both surfaces:
test "$(curl --silent --output /dev/null --write-out '%{http_code}' http://127.0.0.1:3080/)" = 401
curl --fail http://127.0.0.1:6080/novnc-debian-1.6.0-2/vnc.html
docker compose logs --tail=120 deepseek-harnessTell the user to open http://127.0.0.1:3080. Configure the model provider and key in Harness settings. Use the WebUI browser action for the embedded Chromium desktop; use http://127.0.0.1:6080/novnc-debian-1.6.0-2/vnc.html?autoconnect=1 only as a direct fallback.
Keep Debian Chromium as the default. For an explicit privacy-focused deployment, select the separate immutable image before pulling and starting:
export DSH_IMAGE_VERSION=0.2.1-alpha.2-r1-ungoogled.1
DSH_WORKSPACE=/absolute/path/to/project docker compose pull
DSH_WORKSPACE=/absolute/path/to/project docker compose up -d --no-buildThis image keeps its browser profile under /home/node/.dsh/chrome-profile-ungoogled. Do not point it at the default Chromium profile. Report that Safe Browsing, sync, push, Widevine, and Web Store integration may be absent or require manual setup. When validating the variant, inspect /proc/net/tcp and /proc/net/tcp6 for remote port 146C (hexadecimal 5228) and confirm /tmp/dsh-desktop/chromium.log has no google_apis/gcm entry.
Keep the default image unchanged and opt in through the overlay:
DSH_WORKSPACE=/absolute/path/to/project \
docker compose -f compose.yaml -f compose.market.yaml pull
DSH_WORKSPACE=/absolute/path/to/project \
docker compose -f compose.yaml -f compose.market.yaml up -d --no-build
docker compose -f compose.yaml -f compose.market.yaml psIf the market reports a pnpm store version mismatch, stop the service and run the repository's explicit repair command from README.md. Do not delete the profile or named volume as a shortcut.
Use the pinned image and pass the provider key from the existing environment without printing it:
docker run --rm \
--env DEEPSEEK_API_KEY \
--mount type=volume,src=dsh-home,dst=/home/node/.dsh \
--mount type=bind,src=/absolute/path/to/project,dst=/workspace \
runzhliu/deepseek-harness:0.2.1-alpha.2-r1 \
--profile headless "summarize this repository"Replace the provider environment variable and model configuration only when the selected provider requires it. Keep secrets out of command output and shell history where possible.
Use the included chart as a single-replica, stateful, private deployment:
helm lint --strict charts/deepseek-harness
helm upgrade --install deepseek-harness charts/deepseek-harness \
--namespace deepseek-harness \
--create-namespace
kubectl -n deepseek-harness rollout status statefulset/deepseek-harness
kubectl -n deepseek-harness port-forward service/deepseek-harness 3080:3080 6080:6080Use an existing Secret for provider credentials and an existing PVC when a persistent writable workspace is required. Preserve the chart's private Service and NetworkPolicy defaults.
make verify before building changes.make build and make smoke for the default image.make ungoogled-build and make ungoogled-smoke for the optional privacy-focused image.make market-build and make market-smoke for the optional market image.latest tag.linux/amd64 and linux/arm64 when publishing multi-platform images.Start with non-destructive evidence:
docker compose config
docker compose ps
docker compose logs --tail=200 deepseek-harness
docker compose ps -q deepseek-harnessPass the container ID reported by the last command to docker inspect; do not assume a fixed Compose project name.
Check these common boundaries:
3080 or 6080 already in use: choose different loopback host ports through DSH_PORT or DSH_DESKTOP_PORT./dev/shm, the 6080 endpoint, and the 9222 Chromium debug endpoint from inside the container.Do not use docker compose down --volumes, remove named volumes, or overwrite profile files without explicit user approval and a clear explanation of the data loss.
State the selected image tag, workspace mount, exposed loopback URLs, container health, and verification performed. Distinguish a successful WebUI health check from a successful real model/tool call; perform the latter only when the user supplied a provider configuration and authorized the test.
© runzhliu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 69 other files (scripts, assets) in the repository root of runzhliu/deepseek-harness-docker.
Open the folder on GitHubat commit 9984408
Deepseek Harness Docker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deepseek Harness Docker this skillrunzhliu/deepseek-harness-docker | 110 | — | ~2.7k | Automated safety check: Notes | MIT | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 16k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Devopsnicepkg/auto-company | 195 | 2 repos | ~814 | Automated safety check: Pass | MIT | |
| Debug Openshell ClusterNVIDIA/OpenShell | 16k | — | ~20k | Automated safety check: Notes | Apache-2.0 | |
| Cleanupericboy0224/learn-docker-and-k8s | 491 | — | ~454 | Automated safety check: Pass | None |
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
nicepkg/auto-company
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).
NVIDIA/OpenShell
Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.
ericboy0224/learn-docker-and-k8s
Clean up Docker resources created by the Learn Docker & K8s game.
sandys/kappal
Deploy docker-compose projects to Kubernetes using Kappal. An agent skill from sandys/kappal.
Works with
Categories
Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser…. Deepseek Harness Docker is an agent skill from runzhliu/deepseek-harness-docker. Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser, optional protected LAN gateway, optional ungoogled-chromium image, and optional plugin market.
Deepseek Harness Docker fits situations like: users ask to run DSH; deepSeek Harness locally; on a trusted LAN; mount a writable workspace.
Run `npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a claude-code`. Or copy the skill folder (the runzhliu/deepseek-harness-docker repository) into .claude/skills/deepseek-harness-docker in your project. Claude Code loads it when a task matches its description.
Run `npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a codex`. Or copy the skill folder (the runzhliu/deepseek-harness-docker repository) into .agents/skills/deepseek-harness-docker in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add runzhliu/deepseek-harness-docker --skill deepseek-harness-docker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepseek-harness-docker, .gemini/skills/deepseek-harness-docker, .github/skills/deepseek-harness-docker and .opencode/skills/deepseek-harness-docker in your project.
Going by SKILL.md and its folder, Deepseek Harness Docker needs the command-line tools its instructions call (docker, make, curl, helm, kubectl and git) and credentials named DEEPSEEK_API_KEY. Our summary lists: Docker; A credential in DEEPSEEK_API_KEY.
SKILL.md contains no URLs. Its commands use docker, curl and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Deepseek Harness Docker is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deepseek Harness Docker: LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Build Openshell Mxc Windows (NVIDIA/OpenShell, 16k stars), Devops (nicepkg/auto-company, 195 stars) and Debug Openshell Cluster (NVIDIA/OpenShell, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
runzhliu (a GitHub user) maintains it in runzhliu/deepseek-harness-docker, which has 110 GitHub stars. The repository was last updated on October 9, 2026.
Source: runzhliu/deepseek-harness-docker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.