Editor's note

TencentCloud/tencentcloud-agentobs-sdk-dsh

session、agent loop、LLM stream

This is a DeepSeek Harness (DSH) plugin. Review its GitHub README, installation information, maintenance status, and public security signals here.

Tencent Cloud CLS observability for DeepSeek Harness

Tencent Cloud Service CLS observability for DeepSeek Harness

tencentcloud-agentobs-sdk-dsh 是一个 DeepSeek Harness (DSH) 可观测插件,直接将 GenAI trace 数据上报到腾讯云日志服务 (CLS)。

它观察 DSH 原生的 session、agent loop、LLM stream 和 tool 生命周期,将其转换为腾讯云AI Agent可观测规范的 5 层 span 层级模型(entry → agent → step → chat → tool),并通过 tencentcloud-cls-sdk-js 直接上报到 CLS,无需额外部署 OTLP 收集器或 sidecar

数据模型

DSH session/event + llm/stream
                │
                ▼
      CLS Trace Coordinator
                │
                ▼
    CLS 5-layer span model
    (entry/agent/step/chat/tool)
                │
                ▼
    tencentcloud-cls-sdk-js
                │  Protobuf upload
                ▼
    Tencent Cloud CLS

一次 DSH turn 产生的 trace 结构:

ENTRY
└── AGENT (invoke_agent)
    └── STEP (react round_N)
        ├── CHAT (chat model_name)
        └── TOOL (execute_tool tool_name)

安装

前置依赖

全局安装 DeepSeek Harness CLI:

npm install -g @deepseek-ai/dsh

安装插件

dsh plugin --profile web add tencentcloud-agentobs-sdk-dsh
dsh plugin --profile headless add tencentcloud-agentobs-sdk-dsh
dsh plugin --profile harness add tencentcloud-agentobs-sdk-dsh

注意:安装或更新插件后,需要重启 DSH 服务才能生效。

pnpm 构建脚本问题

pnpm v9+ 默认禁止依赖包运行 install 脚本。如果安装时遇到以下错误:

[ERR_PNPM_IGNORED_BUILDS] Ignored build scripts: protobufjs@6.11.6
Run "pnpm approve-builds" to pick which dependencies should be allowed to run scripts.

在对应 profile 目录执行一次即可(后续安装/更新不再需要):

cd ~/.dsh/profiles/web
echo "enable-scripts=true" >> .npmrc
pnpm install

headless / harness profile 同理,将路径改为 ~/.dsh/profiles/headless~/.dsh/profiles/harness

卸载插件

dsh plugin --profile web remove tencentcloud-agentobs-sdk-dsh
dsh plugin --profile headless remove tencentcloud-agentobs-sdk-dsh
dsh plugin --profile harness remove tencentcloud-agentobs-sdk-dsh

配置

环境变量(推荐)

export CLS_ENDPOINT=ap-guangzhou.cls.tencentcs.com
export CLS_TOPIC_ID=your-topic-id
export CLS_SECRET_ID=your-secret-id
export CLS_SECRET_KEY=your-secret-key
export CLS_SERVICE_NAME=dsh-agent

dsh --profile web

插件配置文件

编辑 $DSH_HOME/profiles/<profile>/cordis.patch.yml

- id: cls-observability
  config:
    endpoint: ap-guangzhou.cls.tencentcs.com
    topicId: your-topic-id
    secretId: your-secret-id
    secretKey: your-secret-key
    serviceName: dsh-agent
    captureContent: true
    batchMaxSize: 32
    flushIntervalMs: 5000
    debug: false

显式插件配置优先于环境变量。

关闭内容捕获

默认情况下,prompts、responses、tool arguments/results 附加到 span。如需关闭:

export OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false
dsh --profile web

或在插件配置中设置 captureContent: false

配置项

设置默认值说明
enabledtrue禁用采集但不卸载插件
endpointCLS_ENDPOINTCLS API 接入点
topicIdCLS_TOPIC_IDCLS 日志主题 ID
secretIdCLS_SECRET_ID腾讯云 SecretId
secretKeyCLS_SECRET_KEY腾讯云 SecretKey
serviceNamedeepseek-harness服务名
captureContenttrue捕获 prompts/responses/tool 内容(设为 false 关闭)
contentMaxChars128000单个内容属性最大字符数
batchMaxSize32每批上报最大 span 数
maxQueueSize2048队列上限,超限丢弃最旧 span
flushIntervalMs5000定时刷新间隔(毫秒)
retryTimes3上报重试次数
debugfalse启用调试日志

隐私说明

内容捕获默认开启。源代码、凭证、个人数据等敏感内容可能被发送到 CLS。如需关闭,设置 captureContent: false 或环境变量 OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false。请确保 CLS 的数据保留和访问控制策略符合安全要求。

兼容性

组件支持范围
DeepSeek Harness>=0.1.0-rc.6 <0.2.0
Node.js>=18.0.0

开发

pnpm install
pnpm run check
pnpm test
pnpm run build

License

Apache-2.0

REPOSITORY SIGNALS

Security & install evidence

This score is based solely on public repository metadata and the install evidence registered here — it is not a code security audit.

Traceable source

From a public plugin catalog, linked to a public GitHub repository.

License

The repository declares the Apache-2.0 license.

Maintenance activity

Code updates within the last 180 days.

Install evidence

No verifiable install metadata registered yet — please review the repository instructions manually.

Install lifecycle scripts

The inspected package metadata declares no install lifecycle scripts.