description: "OpenSSH connection configuration and remote helper lifecycle for deployments composing POSIX file, process and sandbox providers."
English | 中文
dsh-ssh connects a POSIX Harness host to an installed helper on a POSIX SSH host. One deployment-owned OpenSSH alias supplies authentication and host identity; the paired filesystem, subprocess and sandbox providers use that connection. The connection verifies installed artifact digests before readiness; the helper owns remote cleanup when the connection closes or its lease expires.
Compose this service with fs-ssh, subprocess-ssh and sandbox-ssh in a custom dsh profile. The host runs the Harness, model transport and Session storage; the remote machine supplies the files and processes. Headless profiles support this arrangement.
Both endpoints require Linux or macOS. The local ssh command must support connection multiplexing and Unix-socket forwarding; the server must permit that forwarding. Configure the alias, credentials and known-host entry before startup: the service enables BatchMode, requires strict host-key checking, disables agent forwarding and adds no interactive authentication flow.
Install the built helper and its matching runtime dependencies on the remote host. Keep Node, helper, bootstrap and their dependencies outside the workspace and writable temporary roots. They must also remain outside a backend’s replaced temporary tree, such as bwrap’s private /tmp; the workspace may still be under /tmp. Digest verification detects an unexpected installed artifact after helper startup; it does not make writable deployment files safe to execute or authenticate a malicious SSH host.
| Field | Default | Meaning |
|---|---|---|
host |
required | Existing OpenSSH host alias |
node, helper, workspace |
required | Absolute remote Node executable, bundled helper entry and default workspace |
helperHash |
required | Lowercase SHA-256 of the installed helper entry |
bootstrapPath, bootstrapHash |
omitted | Paired remote PTC entry and its lowercase SHA-256 |
requestTimeoutMs |
30000 |
Connection and administrative-request deadline, from 1 through 2,147,483,647 ms |
maxFrameBytes |
67108864 |
Per-message JSON payload ceiling, at most 64 MiB |
maxPending |
128 |
Ordinary outstanding requests; heartbeat and bounded cleanup requests have reserved capacity |
leaseMs |
30000 |
Helper heartbeat lease, from 3000 to 600000 ms |
For PTC, configure both bootstrap fields and pass the verified ctx.ssh.nodeExecutable and ctx.ssh.bootstrapPath to NodePtcRuntime. Basic filesystem and Bash use may omit the pair. The bootstrapPath getter refuses an unconfigured PTC deployment.
None, as host aliases, authentication and stream capabilities are private deployment details and consumers own every model-visible operation.
This provider contributes no request-prefix content. Its consumers own model-visible tools and results.