Native lifecycle control plane

Sempre

Any core. Always current. Always running.

Install, switch, validate, and supervise proxy cores with one native service and one replaceable Web UI.

Quick start One command, verified release.
curl -fsSL https://sempre.run/install | sh
SHA-256 verified before execution Inspect script

Sempre 2.0 · unsigned binaries · review release notes before privileged installation

Sempre control plane overview
SUPERVISORRunning
ACTIVE COREsing-box 1.13.15
ENTER THE CONTROL PLANE

01 / CONTROL

The control plane stays online while the core changes underneath it.

Observe runtime state, traffic, connections, rules, logs, and installed versions from the same local interface.

01

Native service managers

Runs through Windows SCM, systemd, and launchd without an extra service wrapper.

02

No silent rollback

Validates a new deployment before activation. A failed start stays selected and is reported without rewriting configuration.

03

Replaceable Web UI

Install or replace the Web UI independently without changing the service or managed core.

04

Three operating systems

One operating model across Windows, Linux, and macOS on amd64 and arm64.

Sempre control plane overview
Sempre Web UI · actual interface

02 / ARCHITECTURE

One ownership chain. No wrapper stack.

A single Rust binary owns installation, service registration, validation, deployment, supervision, and failure reporting.

01
Browser / CLIOperator interface
02
Sempre APIlocalhost:33211
03
sempre daemonSupervisor + diagnostics
04
core@versionManaged process
Windows SCMsystemdlaunchd

Registered directly with each operating system. No NSSM, no third-party service host.

03 / DELIVERY

Same install contract on every supported machine.

The installer detects the machine, locks the latest release tag, verifies the matching bundle, then delegates to Sempre's idempotent installer.

Windowsamd64 / arm64Windows SCMReady
Linuxamd64 / arm64systemdReady
macOSamd64 / arm64launchdReady

04 / PROVENANCE

The short command does not shorten the verification chain.

Every target ships with checksums, a CycloneDX SBOM, and GitHub build provenance. Bundle verification happens before the privileged installer starts.

View the latest release
VERIFY gh attestation verify <binary> --repo tinymins/sempre
SHA256SUMSCycloneDXAttestation