- resolveTelemetryPatch: extracted pure switch resolution (unit-tested); fails loud when DSH_TELEMETRY_DISABLED is set but the row is absent, and documents that ANY non-empty value (including '0'/'false') disables. - runHeadless: SIGINT/SIGTERM now dispose the tree before exit so the telemetry tail and shutdown marker drain (Node's default signal exit skips disposal). - web.cordis.yml: explicit maxQueueSize beside maxExportBatchSize (the single-batch drain invariant no longer leans on an SDK default), comment covers exportTimeoutMillis's role and links the Agent Note. - apps/web scaffold: disable telemetry-otel — fixture sessions must never leave the process. - apps/cli README (en/zh + pairing): document the default endpoint, both env seams, and the no-redaction disclosure.
250 lines
8.8 KiB
YAML
250 lines
8.8 KiB
YAML
# `dsh web` — the browser surface, as a patch list over `base.cordis.yml`.
|
|
# The launcher includes the base and applies this file, then any `--config`
|
|
# overlay, then AppCLIEntry's profile-json and CLI-flag patches, as sibling patch
|
|
# lists at ONE include level: patches never cross an include boundary, so
|
|
# stacking overlays as nested includes would silently stop reaching base rows.
|
|
#
|
|
# A patch replaces the targeted row's whole `config`, so each row below restates
|
|
# every key it owns. `--dev` appends the dsh-client-hmr row in code
|
|
# (AppCLIEntry).
|
|
|
|
# ── surface-specific values the base deliberately omits ─────────────────────
|
|
|
|
# TODO: Re-enable shared HMR for Web after its reload lifecycle is tested.
|
|
- id: hmr
|
|
disabled: true
|
|
|
|
# Session query is a TUI capability; Web owns its own session presentation.
|
|
- id: session-query-sqlite
|
|
disabled: true
|
|
|
|
- id: tools
|
|
config:
|
|
# TEMPORARY workaround: DSH_TOOLS_MODE (native|code|both) opts a whole dsh
|
|
# process into Code Mode while per-session tool-mode selection is being
|
|
# designed; unset keeps the schema default (native). Remove the env seam
|
|
# once the web UI owns the choice per session.
|
|
mode: !!js process.env.DSH_TOOLS_MODE
|
|
|
|
- id: llm-deepseek
|
|
config:
|
|
apiKey: !!js process.env.DEEPSEEK_API_KEY
|
|
baseURL: !!js process.env.DEEPSEEK_BASE_URL
|
|
|
|
# The web surface replaces the unrestricted local executors with the shared
|
|
# sandbox policy. Its default preserves the previous unrestricted behavior;
|
|
# DSH_PERMISSION_MODE and the browser permission picker can confine a session.
|
|
- insert:
|
|
- id: sandbox
|
|
name: '@deepseek-ai/dsh-sandbox-local'
|
|
|
|
- id: sandbox-policy
|
|
name: '@deepseek-ai/dsh-sandbox-policy'
|
|
config:
|
|
mode: !!js process.env.DSH_PERMISSION_MODE ?? 'danger-full-access'
|
|
workspaceRoot: !!js process.cwd()
|
|
|
|
- id: bash-sandbox
|
|
name: '@deepseek-ai/dsh-bash-sandbox'
|
|
|
|
- id: approval
|
|
name: '@deepseek-ai/dsh-user-approval'
|
|
config:
|
|
policy: !!js "(process.env.DSH_PERMISSION_MODE ?? 'danger-full-access') === 'danger-full-access' ? 'never' : 'ask'"
|
|
|
|
- id: permission
|
|
name: '@deepseek-ai/dsh-permission'
|
|
config:
|
|
presets:
|
|
read-only:
|
|
sandbox: read-only
|
|
approval: ask
|
|
workspace-write:
|
|
sandbox: workspace-write
|
|
approval: ask
|
|
danger-full-access:
|
|
sandbox: danger-full-access
|
|
approval: never
|
|
|
|
- id: fs-sandbox
|
|
name: '@deepseek-ai/dsh-fs-sandbox'
|
|
|
|
- id: bash-local
|
|
disabled: true
|
|
|
|
- id: fs-local
|
|
disabled: true
|
|
|
|
# ── web-only host rows, the transport layer, and the browser roster ─────────
|
|
|
|
# `dshClient` rows are the browser roster the modules node half scans into
|
|
# window.__DSH_BOOT__; the modules row is simultaneously a host row.
|
|
- insert:
|
|
- id: session-projection
|
|
name: '@deepseek-ai/dsh-session-projection'
|
|
|
|
- id: code-runtime
|
|
name: '@deepseek-ai/dsh-code-runtime-worker'
|
|
|
|
- id: storage
|
|
name: '@deepseek-ai/dsh-storage'
|
|
|
|
- id: storage-json
|
|
name: '@deepseek-ai/dsh-storage-json'
|
|
config:
|
|
root: './.storages'
|
|
|
|
- id: storage-domain
|
|
name: '@deepseek-ai/dsh-storage-domain'
|
|
config:
|
|
backend: json
|
|
|
|
- id: workspace
|
|
name: '@deepseek-ai/dsh-workspace'
|
|
|
|
- id: session-projection-cache
|
|
name: '@deepseek-ai/dsh-session-projection-cache'
|
|
config:
|
|
writeEveryEvents: 200
|
|
writeIntervalMs: 5000
|
|
|
|
# Session telemetry: mirrors every session-log event (assistant/chunk
|
|
# projected to first-of-step) plus ops markers onto OTLP/HTTP log records,
|
|
# streaming on the batch processor's cadence (10s/batch here) — not at
|
|
# exit; a crash loses at most the last unexported interval. No
|
|
# telemetry/record redaction rule is mounted yet, so exports are the raw
|
|
# captured copy; the deployment stance, env seams, and follow-ups are
|
|
# pinned in the web-telemetry-default-mount Agent Note.
|
|
# DSH_TELEMETRY_OTLP_URL overrides the production endpoint, and a
|
|
# non-empty DSH_TELEMETRY_DISABLED — any value, including '0'/'false' —
|
|
# opts the process out (AppCLIEntry patches the row disabled; config
|
|
# cannot disable a row). The exporter/processor values bound the
|
|
# shutdown drain to ~1s against an unreachable collector:
|
|
# exporter.timeoutMillis is both the per-attempt socket timeout and the
|
|
# retry deadline (1s effectively disables the SDK's 5-try backoff),
|
|
# maxExportBatchSize == maxQueueSize (both explicit) makes the drain a
|
|
# single batch, and exportTimeoutMillis is the processor's own cap on
|
|
# that one export cycle — the second bound when the exporter's clock
|
|
# alone does not fire.
|
|
- id: telemetry-otel
|
|
name: '@deepseek-ai/dsh-session-telemetry-otel'
|
|
config:
|
|
exporter:
|
|
url: !!js process.env.DSH_TELEMETRY_OTLP_URL ?? 'https://harness-telemetry.deepseeksvc.com/v1/logs'
|
|
compression: gzip
|
|
timeoutMillis: 1000
|
|
processor:
|
|
scheduledDelayMillis: 10000
|
|
maxQueueSize: 2048
|
|
maxExportBatchSize: 2048
|
|
exportTimeoutMillis: 1500
|
|
|
|
- id: tool-todo
|
|
name: '@deepseek-ai/dsh-tool-todo'
|
|
|
|
# Resolve bind host, SSH launch, and display once at boot, then mount the
|
|
# matching dual-face directory picker. Mount -native or -browse directly in
|
|
# an overlay to pin the interaction.
|
|
- id: directory-picker
|
|
name: '@deepseek-ai/dsh-host-directory-picker-auto'
|
|
|
|
# The API gateway: the transport-agnostic dispatch face every client shape
|
|
# shares. provider/model are the host default routing — the profile json's
|
|
# mapping target (user config overrides these engineering defaults).
|
|
- id: api-gateway
|
|
name: '@deepseek-ai/dsh-host-apiproxy'
|
|
config:
|
|
provider: deepseek-official
|
|
model: deepseek-v4-flash
|
|
|
|
# ── layer 2: transport/service ──────────────────────────────────────────────
|
|
|
|
# Plain route-registration carrier. distIndex is an assembly fact, not user
|
|
# config — AppCLIEntry resolves the frontend dist and patches it in; host and
|
|
# port arrive as CLI-flag patches over these defaults.
|
|
- id: webserver
|
|
name: '@deepseek-ai/dsh-host-webserver'
|
|
config:
|
|
host: 127.0.0.1
|
|
port: 3080
|
|
|
|
# ── browser plugin roster (dshClient rows; node halves are layer-2 hosts) ──
|
|
|
|
# Dual-face: node half scans this very tree for dshClient rows, composes
|
|
# window.__DSH_BOOT__, serves /plugins/<id>/client.js; browser half is the
|
|
# module table the shell kernel constructs before cordis exists (§4.7 —
|
|
# adopted as a plugin entry by the kernel, never fetched).
|
|
- id: modules
|
|
name: '@deepseek-ai/dsh-client-modules'
|
|
|
|
# Owns both ends of the web transport: node half binds the gateway to the
|
|
# webserver under /api; browser half is the fetch/SSE client.
|
|
- id: connection
|
|
name: '@deepseek-ai/dsh-client-connection'
|
|
|
|
- id: client-runtime
|
|
name: '@deepseek-ai/dsh-client-runtime'
|
|
|
|
- id: ui-theme
|
|
name: '@deepseek-ai/dsh-client-ui-theme'
|
|
|
|
- id: locale
|
|
name: '@deepseek-ai/dsh-client-locale'
|
|
|
|
- id: ui-layout
|
|
name: '@deepseek-ai/dsh-client-ui-layout'
|
|
|
|
- id: ui-sidebar
|
|
name: '@deepseek-ai/dsh-client-ui-sidebar'
|
|
|
|
- id: ui-settings
|
|
name: '@deepseek-ai/dsh-client-ui-settings'
|
|
|
|
- id: ui-settings-general
|
|
name: '@deepseek-ai/dsh-client-ui-settings-general'
|
|
|
|
- id: ui-models
|
|
name: '@deepseek-ai/dsh-client-ui-models'
|
|
|
|
- id: ui-conversation
|
|
name: '@deepseek-ai/dsh-client-ui-conversation'
|
|
|
|
|
|
- id: ui-workspace
|
|
name: '@deepseek-ai/dsh-client-ui-workspace'
|
|
|
|
# Input triggers: the '/' | '@' pipeline (ui-slash), the command surface over
|
|
# it (ui-command), and the two reference sources (ui-skill / ui-subagent).
|
|
- id: ui-slash
|
|
name: '@deepseek-ai/dsh-client-ui-slash'
|
|
|
|
- id: ui-command
|
|
name: '@deepseek-ai/dsh-client-ui-command'
|
|
|
|
- id: ui-skill
|
|
name: '@deepseek-ai/dsh-client-ui-skill'
|
|
|
|
- id: ui-subagent
|
|
name: '@deepseek-ai/dsh-client-ui-subagent'
|
|
|
|
# Goal surface: GoalBar in the input dock over the goal session projection.
|
|
- id: ui-goal
|
|
name: '@deepseek-ai/dsh-client-ui-goal'
|
|
|
|
# Model selection: the /model popupSelect + composer seat over session.models.
|
|
- id: ui-model
|
|
name: '@deepseek-ai/dsh-client-ui-model'
|
|
|
|
- id: ui-permission
|
|
name: '@deepseek-ai/dsh-client-ui-permission'
|
|
|
|
# Plan control: the composer plan seat over the plan projection + /plan channel.
|
|
- id: ui-plan
|
|
name: '@deepseek-ai/dsh-client-ui-plan'
|
|
|
|
- id: ui-question
|
|
name: '@deepseek-ai/dsh-client-ui-question'
|
|
|
|
- id: ui-trajectory
|
|
name: '@deepseek-ai/dsh-client-ui-trajectory'
|