xiajiajun516/dsh-config-manager

Backup / export / import / migrate your DeepSeek Harness (DSH) configuration - dual-face Cordis plugin (host engine + Web UI). One-click restore on any machine.

Bundle verified Unknown TypeScript v0.1.28
Bundle verified

Listed

3

Tools

Bundle verified

โ˜… 3 View on GitHub
Versionv0.1.28
LanguageTypeScript
LicenseUnknown
View on GitHub

Preview

Preview 1 of 2: xiajiajun516/dsh-config-manager
Preview 2 of 2: xiajiajun516/dsh-config-manager

What it does

One-click backup, export, import and migration of a whole DSH config: settings, plugins, MCP, skills and workspaces. Secrets are excluded by default and, if you opt in, are AES-256-GCM encrypted rather than written in the clear; imports preview first and auto-backup with rollback, profiles hold multiple setups, and remote sync pushes portable config through a private Git repo with secrets excluded.

Best for

  • Users migrating a complete DSH configuration between machines with an import preview and rollback protection.
  • People maintaining separate work and personal DSH setups through profiles.
  • Teams syncing portable, secret-free configuration through a private Git repository.

Not ideal for

  • Migration of browser-resident UI state such as task-board data or panel widths.
  • Users expecting per-project `AGENTS.md` or `CLAUDE.md` files to migrate with global DSH configuration.
  • Unattended cross-machine secret migration without retaining the encrypted-backup password or re-entering excluded credentials.

README

๐ŸŽ’ DSH Config Manager

Pack up your DSH configuration and take it anywhere โ€” restore your whole environment on a new machine with one click.

English ยท ็ฎ€ไฝ“ไธญๆ–‡


What is this? ๐Ÿค”

DSH is your AI assistant workbench โ€” it holds your settings: model configs, plugins, skills, workspacesโ€ฆ

DSH Config Manager is its โ€œmoving serviceโ€:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ‘  one-click    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ‘ก one-click    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Machine A    โ”‚ โ”€โ”€โ”€โ”€ export โ”€โ”€โ”€โ–บ โ”‚ dsh-config.zip   โ”‚ โ”€โ”€โ”€โ”€ import โ”€โ”€โ”€โ–บ โ”‚  Machine B    โ”‚
โ”‚  my config    โ”‚                  โ”‚   (one file)     โ”‚                  โ”‚  all restored โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โš ๏ธ Security first: no secrets (API Key / Token / Password) are exported by default. See Security.


โœจ Highlights

Icon Feature In one line
๐Ÿš€ One-click Export Package your recommended config into a ZIP
๐Ÿ“ฆ One-click Import Restore your environment on another machine
๐Ÿ‘€ Preview before import Full preview first โ€” never touches your config silently
โš”๏ธ Conflict handling Keep Current / Use Imported โ€” you decide
๐Ÿ—บ๏ธ Path auto-mapping Detects dead absolute paths and lets you remap them
๐Ÿ”’ Secret safety API Keys are not exported by default โ€” non-encrypted imports ask you to re-enter; encrypted backups restore them with the password
โ†ฉ๏ธ Automatic rollback Failed import restores everything automatically
๐Ÿ“ธ Snapshot restore Undo an import: whole-file restore + uninstall added plugins (CLI & GUI)
๐Ÿ”„ Remote Sync Push/pull portable config via Git private repo or WebDAV (secrets never sync)
๐Ÿ—‚๏ธ Profiles Save multiple setups (Work / Personal) and switch anytime
๐ŸŒ Bilingual UI Interface, reports and error details follow the DSH app language (ไธญๆ–‡ / English)

๐Ÿ“ธ Screenshots

Export Import Preview
One-click Export Import Preview
Snapshot Restore Remote Sync
Snapshot Restore Remote Sync

๐Ÿ”„ How it works?

Export (pack it up)
Read your config โ†’ strip secrets (safe) โ†’ build manifest โ†’ compute checksums โ†’ pack into ZIP
Import (restore the environment)

Every step confirms and backs up first โ€” it never modifies your config directly:

Select ZIP โ†’ validate file โ†’ check integrity โ†’ check schema โ†’ compatibility check
    โ†’ scan contents โ†’ build import plan โ†’ preview & confirm
    โ†’ auto-backup current config โ†’ apply โ†’ validate โ†’ done
                      โ”‚
                      โ””โ”€ failed midway? โ†’ automatically restored (rollback)

๐Ÿ“ฅ Installation

Itโ€™s a standard DSH plugin โ€” two steps:

# โ‘  Install the plugin
dsh plugin --profile web add dsh-config-manager@latest --config.auto-install-peers=false

# โ‘ก Restart DSH (a "Backup & Migration" entry appears in Settings)

๐Ÿ’ก Just copy-paste the command: --config.auto-install-peers=false skips a few DSH core packages that arenโ€™t on the public registry yet (the DSH runtime provides them), and @latest ensures you get the newest build.

๐Ÿ› @latest installed an old version? Thatโ€™s pnpm 11โ€™s minimumReleaseAge supply-chain policy, not a cache issue: versions published less than ~30 days ago are excluded from resolution until whitelisted. Two fixes:

  • Install an exact version once (it auto-whitelists, then @latest works):
    dsh plugin --profile web add dsh-config-manager@0.1.8 --config.auto-install-peers=false
    
  • Or disable the age gate with a one-liner (adds minimumReleaseAge: 0 at the top of the profileโ€™s pnpm-workspace.yaml):
    $f = "$env:USERPROFILE\.dsh\profiles\web\pnpm-workspace.yaml"
    $c = Get-Content $f -Raw
    if ($c -notmatch '(?m)^minimumReleaseAge:') {
      Set-Content -LiteralPath $f -Value ("minimumReleaseAge: 0`n" + $c) -Encoding utf8
      Write-Output "Added minimumReleaseAge: 0"
    } else {
      Write-Output "Already present, nothing to do"
    }
    

๐Ÿš€ Quick start (3-minute tour)

Machine A (export)
  1. Open DSH โ†’ Settings โ†’ "Backup & Migration"
  2. Click "Export Configuration" โ†’ choose "Quick Export"
  3. You get dsh-config-2026-08-14.zip (the report confirms no secrets inside)

Copy the ZIP to Machine B (import)
  1. Open DSH โ†’ "Backup & Migration" โ†’ "Import Configuration"
  2. Select the ZIP โ†’ wait for analysis โ†’ review the "Import Preview"
  3. Path issues? โ†’ choose new paths (batch mapping supported)
  4. Conflicts? โ†’ choose Keep Current / Use Imported
  5. Confirm import โ†’ wait
  6. Re-enter any missing API Keys as prompted
  7. โœ… Settings / plugins / MCP / skills / workspace / global instructions (AGENTS.md) are back

๐Ÿงฉ Features

๐Ÿ“ค Export (two modes)
Mode Description
Quick Export (recommended) One-click: settings / UI / models / plugins / MCP / skills / agent presets / global instructions (AGENTS.md) / workspacesโ€ฆ
Custom Export Tick the categories you want

Output: dsh-config-<date>.zip with manifest + per-category data + SHA-256 checksums.

๐Ÿ“ฅ Import (safe flow)
  • Nothing is written before confirmation โ€” analyze & preview are zero-write
  • Backup before applying โ€” the target config is snapshotted automatically
  • Automatic rollback on failure โ€” full rollback or skip-and-continue, your choice
๐Ÿ‘€ Import Preview (dry run)

Shown fully before importing:

โœ“ 18 settings will be updated    โœ“ 6 plugins already installed
โš  2 plugins need installation    โš  3 secrets need re-entry
โš  1 path needs mapping           โš  2 conflicts need attention
โš”๏ธ Conflict handling

When the target already has a same-named item, you choose:

Option Meaning
Keep Current Leave the targetโ€™s config untouched
Use Imported Overwrite with the backupโ€™s value

Note: a โ€œdecide later / reviewโ€ option is intentionally not offered โ€” an undecided conflict would block the import from proceeding. Every conflict must be resolved before continuing.

๐Ÿ—บ๏ธ Path mapping

C:\Users\alice\projects doesnโ€™t exist on the new machine? The plugin:

  1. Detects the dead absolute paths automatically
  2. Lets you pick new paths
  3. Supports batch prefix mapping (C:\Users\alice\ โ†’ /Users/bob/ in one shot)
๐Ÿ”’ Secrets
Scenario Behavior
Default backup No secret values at all โ€” only records which keys are needed
Encrypted backup (explicit opt-in) scrypt + AES-256-GCM, random salt & IV per export; secrets never leave as plaintext, and the password is never written to the file
Encrypted backup import The export-time password is required: enter โ†’ verify โ†’ credentials are restored; no password, no import
After non-encrypted import โ€œ3 secrets need re-entryโ€ โ€” values stay in memory only
๐Ÿ”„ Remote Sync (Git / WebDAV)

Push / pull your portable config between machines through either of two channels โ€” usage is identical except for the transport itself:

  Git private repo WebDAV
Endpoint repoUrl webdav.url
Credentials auth token in DSH credentials (DSH_CONFIG_MANAGER_SYNC_TOKEN) username stored in the config (echoed in the UI); password never synced / never logged โ€” DSH credentials DSH_CONFIG_MANAGER_SYNC_WEBDAV_PASSWORD
  • Same snapshot retention for both channels: only the newest 10 snapshots are kept on the remote (MAX_REMOTE_SNAPSHOTS=10); older ones are deleted automatically.
  • Switching channels starts fresh: Git and WebDAV do not share snapshots or a common ancestor. When you switch transport, sync begins again from the new remoteโ€™s empty baseline โ€” push a fresh snapshot first.
  • WebDAV auth uses HTTP Basic: the username is stored in the config and may be echoed back into the UI, while the password is read live from the DSH credentials slot DSH_CONFIG_MANAGER_SYNC_WEBDAV_PASSWORD โ€” it never appears in any sync file or log.
  • Plugins auto-install: when pulling diffs, plugins that are new in the backup are installed automatically on confirm โ€” no manual per-item ticking in the diff list. Only version-conflict plugins still ask you to pick โ€œKeep Current / Use Importedโ€.
๐Ÿ—‚๏ธ Profiles

Save multiple configurations (Work / Personal) and switch anytime; switching includes preview + auto-backup + rollback.

๐Ÿ“ธ Snapshot restore (undo an import)

Every import creates a safety snapshot first. If something feels off afterwards, restore the target back to its pre-import state:

Action What it does
Whole-file restore settings.yaml / settings.json / cordis.patch.yml blobs are written back to $DSH_HOME; files that didnโ€™t exist at snapshot time but appeared after import are removed
Plugin uninstall Plugins added during import are removed via the official dsh plugin remove (baseline comparison; old snapshots without a baseline only get a hint)
File compensation skills / agentPresets / agentInstructions / pluginFiles / sessions blobs are written back to their original paths
Credentials DSH never reads credential values back โ€” you get a manual re-entry hint instead

GUI: Settings โ†’ โ€œBackup & Migrationโ€ โ†’ Snapshots & Restore tab โ†’ pick a snapshot โ†’ preview the plan (dry-run, zero writes) โ†’ confirm.


๐Ÿšจ CLI โ€” the first line of defense when DSH is broken

The GUI lives inside DSH โ€” it canโ€™t help you if DSH wonโ€™t start. The dsh-config-manager CLI is completely independent of the DSH runtime (pure Node + the core engine, zero @deepseek-ai/* imports โ€” it runs even when the DSH peer packages are broken or missing). That makes it your first rescue tool when the config is corrupted, the GUI wonโ€™t boot, or you changed machines and need to bring an environment back.

It is a standalone npm tool, installed separately from the plugin. Install it once on any machine that might need rescuing:

# --omit=peer: the offline CLI only needs js-yaml, not the DSH peer packages
npm install -g dsh-config-manager@latest --omit=peer

โš ๏ธ Installing/updating the plugin (dsh plugin --profile web add ...) only enables the GUI โ€” it does not create the dsh-config-manager command. Run the install command above, then any of the commands below.

All commands (also shown by dsh-config-manager help):

dsh-config-manager help                                        # list all commands & options
dsh-config-manager snapshots [--data-dir <dir>]                # list snapshots (newest first)
dsh-config-manager restore [--id <id>] [--dry-run]
                           [--profile <name>] [--settings <path>]
dsh-config-manager reinstall [--version <v>] [--yes] [--list]
                             [--wipe-config] [--dry-run]       # one-click reinstall of DSH itself

reinstall โ€” rescue when DSH is broken. It reinstalls the @deepseek-ai/dsh launcher across platforms (uses the right command per OS: PowerShell on Windows, bash on Unix). By default it reinstalls the launcher + clears global caches; interactively it asks which dangerous clean-up items to include (settings / plugins / session data & credentials) โ€” those are not selected by default, and any destructive choice requires a second confirmation by typing YES before anything runs. Before wiping any ~/.dsh data it makes an emergency backup at .reinstall-backup (the snapshots/ folder is deliberately never touched).

# see the selectable clean-up items
dsh-config-manager reinstall --list

# interactive: pick items, confirm, then reinstall DSH
dsh-config-manager reinstall

# non-interactive: everything checked, skip confirmation
dsh-config-manager reinstall --yes

# wipe config data too (equivalent to checking all data items) โ€” interactive confirm still required
dsh-config-manager reinstall --wipe-config

# preview the exact plan without running anything
dsh-config-manager reinstall --dry-run

Snapshot restore. List and restore the safety snapshots (offline โ€” the restore engine is part of the CLI, so it works whether or not DSH can start):

dsh-config-manager snapshots                                  # list snapshots (newest first)
dsh-config-manager restore --dry-run                          # preview the plan (zero writes)
dsh-config-manager restore --id <snapshot-id>                 # execute (current files are backed up first)

Every overwrite/delete is first copied to <snapshotDir>/pre-restore/ so you can manually change your mind. Exit code is 1 if any action failed; the report honestly lists restored / removedPlugins / manualHints / failed / skipped.

A typical rescue flow when DSH wonโ€™t start: โ‘  dsh-config-manager reinstall to bring the launcher back (plus any clean-up), โ‘ก dsh web to start DSH again, โ‘ข re-add the plugin from the registry, and โ‘ฃ pull a snapshot from the remote repo (or run dsh-config-manager restore) to bring your config back. The CLI works at every step regardless of DSHโ€™s health.


๐Ÿ›ก๏ธ Security

  • The default backup contains no secret values โ€” a hard invariant, enforced at export
  • Not exported by default: API Keys / passwords / tokens / cookies / sessions / device unique ID / logs & cache / plugin binaries
  • A ZIP is untrusted input: defends against Zip Slip, malicious paths, zip bombs, corrupt archives โ€” any trigger rejects the whole file
  • Logs are fully redacted โ€” secret values never reach logs
  • Encrypted backup (explicit opt-in): secrets are exported only as scrypt + AES-256-GCM ciphertext โ€” random salt & IV per export, never plaintext; the password lives in memory only

๐Ÿค Compatibility

Status Meaning
โœ… Excellent Same platform, complete sections, supported schema
๐Ÿ‘ Good Backup from an older DSH
โš ๏ธ Partial Cross-platform / missing sections / backup newer than target
โŒ Unsupported Schema beyond the supported range (cannot import)

โ“ FAQ

Q: Will my API Key be in the backup? Not by default. The default backup never contains any secret value โ€” only records which keys youโ€™ll need to re-enter. If you explicitly choose an encrypted backup, secrets are included, but only as scrypt + AES-256-GCM ciphertext (random salt & IV per export) โ€” never plaintext.

Q: Will importing overwrite my existing config? Not silently. Conflicts ask you to choose (Keep Current / Use Imported); the target is auto-backed-up and can roll back.

Q: Does it work across platforms (Windows โ†’ macOS)? Yes. Dead absolute paths are detected and remapped (batch replacement supported).

Q: Can a corrupted ZIP still be imported? No. A checksum mismatch rejects the import outright (protects against corruption or tampering).

Q: Will re-importing duplicate things? No. Items are deduplicated by stable IDs (plugin ID / MCP name / skill nameโ€ฆ); existing items are skipped.

Q: Does importing an encrypted backup require the password? Yes. The import wizard asks for the export-time encryption password and verifies it before the import can proceed; the password is never saved โ€” memory only. A wrong or missing password blocks the import (credentials are restored from the backup instead of being re-entered when the password is correct).


๐Ÿ“‹ Known limitations (user-facing)

  1. Installing / updating plugins or MCP takes effect after restarting DSH
  2. Some UI state is not migrated (e.g. task board data, panel widths โ€” they live in the browser, not in DSHโ€™s config files)
  3. keybindings / workflow configs / commands โ€” DSH has no such concepts, so nothing is exported for them. Global agent rules are covered by Agent Instructions (~/.dsh/AGENTS.md, injected into every session); per-project AGENTS.md/CLAUDE.md belong to each projectโ€™s repo and are not migrated
  4. History/session migration is off by default (v1 copies files only)
  5. Encrypted backups: a lost password means the secrets.enc canโ€™t be decrypted (by design โ€” keep your password safe)
  6. Snapshot restore is offline and honest: entries the offline engine canโ€™t restore (settings namespaces / patch lines when the snapshot has no whole-file backup, workspace records stored in DSH storages) are reported as skipped with a pointer to online rollback; credential values are never auto-written (manual re-entry hint only); old snapshots without a plugin baseline only get a hint to remove added plugins manually

Maintainers & developers: see DEVELOPERS.md for build, testing, auto-publishing and full technical notes.


Product principles: better to migrate one config less than to break your existing config. Every import follows Analyze โ†’ Preview โ†’ Backup โ†’ Apply โ†’ Validate โ†’ Rollback(if needed); every secret follows never export by default / never log / never expose / never silently transfer.

Frequently Asked QuestionsFAQ

Use the verified command dsh plugin --profile default add github:xiajiajun516/dsh-config-manager in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.