Files
deepseek-harness/packages/api
imccyu 97eb14a007 build(release): make the release set publishable under the private scope
Every package under packages/, apps/, and vendor/ drops "private": true and
declares publishConfig.access "restricted": the repository now states which
packages it publishes instead of deciding it at publish time. Each one also
declares its repository and directory, which is how a consumer of a private
package reaches its source.

The Landlock packages move to restricted with them. They have never been
published, so nothing anonymous depends on them today, and the whole
@deepseek-ai scope stays private.

The workspace constraint that required every package to be private now applies
to non-members only, and asserts the publishable trio on each release member.
2026-08-11 00:09:31 +08:00
..

api/ — Remote API layers

English | 中文

The application-facing Remote stack. remotes owns BFF policy and the selected business API, while gateway implements the TypeRT unary RPC endpoints shared by Host and Client environments.

Package Role ctx key
remotes/ Host Agent/Session lookup policy and Client Remote contribution assembly no service; configures ctx.typert and consumes ctx.remote
gateway/ Host TypeRT dispatcher and Client Remote endpoint ctx.typertGateway / ctx.remote

The runtime dependency direction is remotes → gateway → connection → webserver: the BFF consumes the shared TypeRTClientRemote contract, Gateway delegates transport to Connection, and Connection mounts on the HTTP server. Cordis service injection and Client module metadata preserve this order without importing the concrete Gateway from the Remotes Client entry.

Known Limitations and Deferred Work

  • Connection and WebServer remain at client/connection and host/webserver; a later package-only move can place them under api/connection and api/webserver without changing their service contracts.
  • The legacy API Proxy remains at host/apiproxy as the fallback for methods not yet migrated to Remote. It consumes the Host resolver owned by api-remotes so migrated and legacy methods retain one Agent/Session identity policy.