Skip to main content
DeepSeek Harness creation mode is an agent creation method in Studio for configuring, previewing, and deploying a containerized agent runtime based on DeepSeek Harness. This mode generates a complete container project including a Dockerfile, configuration files, and a runtime adapter, which can be deployed directly to an AgentKit Runtime or exported as a ZIP for local build and execution.
This feature is currently in Beta; the configuration page displays a Beta badge.

When to use

Creation entry point

On the Studio “Agents” page, click “Create agent” and select “Quick create” from the creation menu. In the agent type selection dialog, choose “DeepSeek Harness” and click “Continue” to enter the DeepSeek Harness configuration page.

Configuration

The configuration page is organized into sections, each corresponding to a category of native DeepSeek Harness settings. Fields left blank inherit the default values from the deployed image.

Session defaults

The default model, Agent preset, and permissions apply to new sessions. The preset must exist in the deployed Harness.

DeepSeek model service

Parameters for the DeepSeek official provider.

Custom model providers

Add custom model services with their endpoints, protocols, and model IDs, including compatible Volcengine and BytePlus services. Each custom provider includes: Each provider can configure multiple models with:

Command execution

Timeout and output limits for shell command execution.

Tool calls

Sub-agent model selection

Controls which models sub-agents may select. When model selection is enabled, at least one provider/model pair must be added as an allowed model. Parameters for the DeepSeek native web search tool.

Preview, export, and deploy

After configuration, the page footer provides three actions: When configuration validation fails, the page highlights fields requiring correction and expands the corresponding sections for immediate fixes.

Deploy to AgentKit

Selecting deploy enters the deployment configuration page. The deployment flow matches custom creation: you can select the deployment region, network mode, and Runtime name. During deployment, Studio builds the container image through CodePipeline, pushes it to the container registry, and creates an AgentKit Runtime.
Deployment creates cloud resources and incurs costs. Verify the region, Runtime name, and required secret environment variables before proceeding.
The following secret environment variables are required during deployment (determined automatically from the configuration):
  • DEEPSEEK_API_KEY: API key for the DeepSeek official provider (required when using the default provider)
  • Custom provider secret environment variables: each custom provider has a corresponding secret environment variable that must be supplied at deployment
Secret values are passed through environment variables only at deployment time; they are never written to settings.yaml, the Dockerfile, or build arguments.

Container runtime

The deployed container is built from a Node.js image and installs the DeepSeek Harness npm package as the runtime base layer. The container runs as the node user with /workspace as the working directory. On startup, the exported settings.yaml is copied to the DeepSeek Harness configuration directory, ensuring each start uses the exported configuration to override any existing settings. The DeepSeek Harness native web service runs privately on 127.0.0.1:3080 inside the container. The runtime adapter is loaded as a native plugin and exposes HTTP endpoints on port 8000, which can be overridden via the _FAAS_RUNTIME_PORT or PORT environment variable.

HTTP endpoints

POST /invocations request body:
Request body
Success response:
Success response
If a session already has an active invocation, 409 is returned. Malformed input returns 400. Agent execution timeout returns 504. If the agent turn does not complete successfully, 502 is returned. The default invocation timeout is 300 seconds, configurable via the DSH_INVOCATION_TIMEOUT_MS environment variable. Client disconnection or timeout cancels the active turn.

Persistence

Session and workspace files depend on mounted persistent storage. Without persistent storage, container replacement loses local sessions. Multi-replica deployments require session routing or shared storage.
Runtime gateway authentication protects the invocation API. When running locally, bind the container port to the loopback address. The adapter itself does not implement an additional authentication layer.

Local build and run

The exported project includes a Dockerfile that can be built directly. In the project directory:
When using the default DeepSeek provider, set DEEPSEEK_API_KEY and run:
When using custom providers, also pass the corresponding secret environment variables with -e.
Never put secret values in the Dockerfile, settings.yaml, or build arguments. The .env.example file lists environment variable names only and is not loaded automatically.

Configuration scope

The editor covers common native DeepSeek Harness settings, including default model, preset, permissions, DeepSeek model service, custom model providers, command execution, tool calls, sub-agent model selection, and web search. Other native plugin and preset-file settings are outside the editor’s scope. Presets must exist in the deployed Harness; custom presets and extra plugins must be explicitly installed and added to the build context.
Last modified on September 19, 2026