Skip to main content

dsh-tensorlake-sandbox

7Stars2Forks0Issues0Watchers

Execute DSH files, subprocesses, Bash commands, terminal, and LSP operations in an ephemeral Tensorlake remote Linux sandbox, keeping the local host free from any file or process interactions.

Evidence4/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
License
MIT
Branch
main
ai-agentsai-infrastructuredeepseekdeepseek-harnessdshdsh-plugindsh-pluginsharness

Install

cmdweb profile
$ dsh plugin --profile web add @tensorlakeai/dsh-sandbox

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin tensorlakeai/dsh-tensorlake-sandbox for me: review the repository at https://github.com/tensorlakeai/dsh-tensorlake-sandbox first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Positioning

Move all DSH file, subprocess, Bash, terminal, and LSP operations to a short-lived Tensorlake remote Linux sandbox for execution—the local machine no longer touches any host files or processes, suitable for users who want AI to run entirely in a cloud isolated environment.

Core Capabilities

  • When the dsh profile starts, immediately create a Tensorlake remote sandbox (Linux microVM); DSH automatically destroys it on exit, with the sandbox ID printed in both the creation and destruction log lines
  • Replace the host's file and process execution layer: Bash, file read/write, subprocess spawning, and interactive terminals all run inside the sandbox; models and tools see the same remote Linux working directory for all paths
  • Provide atomic remote file read/write capabilities: writes use a temporary directory + replace/hardlink atomic publish pattern to avoid half-finished overwrites; support NUL-terminated stat / find / base64 control script for reading metadata
  • Replicate complete process and terminal semantics: including process groups from subprocess forking, POSIX sessions, PTY terminals, streaming stdout/stderr, signal forwarding (TERM/KILL), process group exit codes and signal name recognition
  • Refuse to transparently pass environment variables with DSH_* prefix and credential forms into sandbox processes—explicit overrides can only be injected by the caller themselves; also validate that cwd is writable before sandbox startup, and use sudo escalation if necessary before transferring ownership back to the image user
  • Lock sandbox policy to danger-full-access and approval policy to never, while exposing only danger-full-access in permission presets—avoid inconsistent messaging of "host restricted, sandbox fully open"

Technical Implementation

  • Language: TypeScript (ESM, compiled output via tsdown)
  • Key Dependencies: [email protected] (remote sandbox SDK) / @deepseek-ai/cordis (plugin service container) / @deepseek-ai/dsh-fs and @deepseek-ai/dsh-subprocess (host-defined file and process capability interfaces) / @deepseek-ai/schemastery (configuration Schema)
  • Architecture Pattern: Use cordis.patch.yml to shut down host subprocess / fs-sandbox, lock the three-stage policies of sandbox-policy / approval / permission, then insert three Cordis services: tensorlake-runtime / tensorlake-subprocess / tensorlake-filesystem, with all layers sharing the same SDK handle (ctx.tensorlake.getSandbox())
  • Entry Files: src/runtime.ts (shared sandbox owner, includes SDK creation and proxy readiness retry) / src/filesystem/index.ts (remote filesystem provider) / src/subprocess/index.ts (remote subprocess and terminal provider)

Use Cases

Users who want to use DSH without letting AI touch local files or processes at all—for example, consolidating build, test, and script execution into a single remote temporary machine; also suitable for running DSH in shared CI or evaluation environments, ensuring each task starts from a clean Linux image and leaves no trace on exit.

Prerequisites & Compatibility

DependencyMinimum VersionNotes
Node.js^22.19.0 or >=24.0.0Enforced by package.json engines
DeepSeek Harness>=0.1.0-rc.6Host profile's optional cordis/fs/subprocess/schemastery dependencies are resolved by DSH modules
Tensorlake Platform CredentialsN/AHost environment must have TENSORLAKE_API_KEY set, read at runtime via environment variable
Model CredentialsN/ADefault DeepSeek model provider requires DEEPSEEK_API_KEY in the environment
PlatformCross-platformDSH itself supports multiple platforms, but all execution actually happens on remote Linux images (default Ubuntu)—local environment only handles SDK calls

Installation

dsh plugin --profile web add github:tensorlakeai/dsh-tensorlake-sandbox

Configuration Options

ConfigTypeDescriptionDefault
apiKeystringTensorlake platform credential, used only by host SDK, never injected into sandbox processesReads from TENSORLAKE_API_KEY environment variable
cwdstringShared remote working directory, all file and process operations anchor to this/home/tl-user/workspace
timeoutSecsnumber (seconds)Sandbox idle timeout; auto-terminates when exceeded600
cpusnumberVirtual CPU countTensorlake server default
memoryMbnumberMemory quota (MiB)Tensorlake server default
diskMbnumberRoot disk quota (MiB)Tensorlake server default
pollMsnumber (milliseconds)Remote subprocess status polling interval20
DSH_TENSORLAKE_CWDenvironment variableSimultaneously modifies runtime cwd and sandbox policy workspaceRoot to avoid driftUses default value when not set

Sandbox permission presets and approval policies are locked by this plugin to danger-full-access + never and do not accept other combinations; to customize, you must rewrite the entire sandbox-policy / approval / permission layer configuration in the profile.

FAQ

Q: After installation, when I run a task and see the sandbox ID log, what's the significance?

A: The startup log prints Tensorlake sandbox created: <sandbox-id>, and when DSH exits it prints Tensorlake sandbox terminated: <sandbox-id>. Matching IDs indicate the sandbox was created normally and recovered; if only the creation line appears, destruction failed—check upstream logs for debugging.

Q: Can I read/write files on my local hard drive?

A: No. All file operations happen on Linux paths inside the sandbox (default /home/tl-user/workspace); models and tools see this remote path. To change the working directory, use the DSH_TENSORLAKE_CWD environment variable to simultaneously override runtime cwd and sandbox policy workspace directory, preventing policy and execution layer misalignment.

Q: Can I change the permission preset?

A: The plugin locks danger-full-access sandbox + never approval policy, and only exposes danger-full-access in permission presets. cordis.patch.yml is a one-time replacement—to change it, you must rewrite all three sections of sandbox-policy, approval, and permission, otherwise they'll be overwritten back to defaults.

Q: What's the default sandbox configuration? How do I increase memory or CPU?

A: Defaults only set a 600-second idle timeout; CPU/memory/disk use Tensorlake server defaults. Override cpus / memoryMb / diskMb of tensorlake-runtime in the profile's cordis.patch.yml. Note timeoutSecs must be a positive integer, and like cwd must be a positive finite value.

Q: Will credentials enter the sandbox? Is it safe?

A: The plugin code will not automatically pass TENSORLAKE_API_KEY, DEEPSEEK_API_KEY, other credential-form environment variables, or DSH_* variables into sandbox processes; explicit injection can only be done separately through DSH tools or service calls. The sandbox itself is a remote isolated microVM, but you should still evaluate the npm audit report for dependencies passed through the Tensorlake SDK before production use.

Q: Will uninstalling affect DSH itself?

A: No. Uninstalling the plugin just restores the layers it replaced; the DSH installation directory won't be modified. To clean up, just remove the plugin and restart dsh—no extra commands needed.

Difficulty Level

Advanced—requires a Tensorlake platform account, API key, and some awareness of sandbox resource allocation; first-time users may get stuck on credentials and environment variables. Customization requires understanding the cordis.patch.yml replacement semantics in DSH profiles.

Known Issues & Limitations

  • [email protected] (current SDK version) has transitive dependencies on [email protected] and [email protected]; npm audit --omit=dev will report high-severity vulnerabilities; the upstream hasn't released an audit-clean Tensorlake SDK yet—please review relevant security advisories before production use and upgrade promptly when Tensorlake releases new versions
  • Two TODOs exist in the source code: process group signaling at src/subprocess/remote:29 currently uses bash built-in kill, with potential PGID reuse race conditions—waiting for daemon-native's process group signal interface in the future; sandbox initialization rollback at src/runtime.ts:323 doesn't do dual-failure retry, relying only on Tensorlake's built-in timeout cleanup
  • Sandbox permission policy and approval policy are locked by the plugin to danger-full-access + never, suitable only for "fully trust sandbox boundary" use cases; if the host itself uses restricted modes like workspace-write, installing this plugin will force switching to full-access mode—please confirm this is expected in advance

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/tensorlakeai/dsh-tensorlake-sandbox)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory