Native service managers
Runs through Windows SCM, systemd, and launchd without an extra service wrapper.
Native lifecycle control plane
Any core. Always current. Always running.
Install, switch, validate, and supervise proxy cores with one native service and one replaceable Web UI.
curl -fsSL https://sempre.run/install | sh
Sempre 2.0 · unsigned binaries · review release notes before privileged installation
01 / CONTROL
Observe runtime state, traffic, connections, rules, logs, and installed versions from the same local interface.
Runs through Windows SCM, systemd, and launchd without an extra service wrapper.
Validates a new deployment before activation. A failed start stays selected and is reported without rewriting configuration.
Install or replace the Web UI independently without changing the service or managed core.
One operating model across Windows, Linux, and macOS on amd64 and arm64.
02 / ARCHITECTURE
A single Rust binary owns installation, service registration, validation, deployment, supervision, and failure reporting.
Registered directly with each operating system. No NSSM, no third-party service host.
03 / DELIVERY
The installer detects the machine, locks the latest release tag, verifies the matching bundle, then delegates to Sempre's idempotent installer.
04 / PROVENANCE
Every target ships with checksums, a CycloneDX SBOM, and GitHub build provenance. Bundle verification happens before the privileged installer starts.
View the latest releasegh attestation verify <binary> --repo tinymins/sempre