Configuration you can see before it changes anything.
Sinter is a single Rust binary that plans, applies, and audits Linux configuration over SSH.
One binary · Zero agents · Plan / Apply / Audit · SSH
See it run
$ sinter validate recipe.yaml
ok: 3 resource(s), 0 handler(s), 0 var(s)
$ sinter plan --host web01 recipe.yaml
== Sinter PLAN ==
target facts: hostname=web01 os=Ubuntu family=debian version=24.04 arch=x86_64
CHANGED hello [file]
current: absent
desired: 18 bytes
ok vim [package] package already in desired state
ok sshd [service] service already matches desired state
summary: 1 changed, 0 possible, 0 failed, 0 indeterminate, 3 total
status: success
$ sinter apply --host web01 --sudo recipe.yaml
== Sinter APPLY ==
CHANGED hello [file]
ok vim [package] package already in desired state
ok sshd [service] service already matches desired state
summary: 1 changed, 0 possible, 0 failed, 0 indeterminate, 3 total
status: success
$ sinter audit --host web01 recipe.yaml
== Sinter AUDIT ==
PASS hello [file]
reason: file matches desired state
PASS vim [package]
reason: package already in desired state
PASS sshd [service]
reason: service matches desired state
summary: 3 total, 3 compliant, 0 drifted, 0 not_auditable, 0 not_applicable, 0 errors
status: no_driftReal output from an Ubuntu 24.04 host — validate, plan, apply, audit.
Three commands. One loop.
- PLANread-only
Observes the target and reports exactly what would change — nothing is modified.
- APPLYexplicit mutation
Converges the target toward the declared state, fails fast on the first error.
- AUDITread-only
Compares actual state with the recipe and reports compliance or drift.
A recipe is just YAML
Declare the state. Sinter handles observation and convergence — no agent or runtime on the managed host.
version: 1
resources:
- id: hello
type: file
with:
path: /home/ops/hello.txt
content: "hello from sinter\n"
mode: "0644"
- id: vim
type: package
with:
name: vim
state: present
- id: sshd
type: service
with:
name: ssh.service
state: runningHow Sinter works
- Recipedesired state · YAML
- load
- Sintersingle binary · runs on your machine
- SSH←observeconverge (apply only)→
- Linux targetno agent · no daemon
- PLANread-only preview
- APPLYexplicit mutation
- AUDITPASS / DRIFT report
Sinter loads the recipe, observes the target over SSH, and reports or converges. Nothing runs on the target permanently.
Built to fail closed
- Strict SSH host-key verification — unknown or mismatched keys refuse, never prompt.
- Unsafe paths and unexpected symlinks stop execution instead of guessing.
- Files are published atomically — no half-written configuration.
- Failures and indeterminate states are reported honestly, never hidden.
AI integration
Two separate surfaces: one lets AI read this documentation, the other lets AI use bounded Sinter capabilities.
Website WebMCP
AI → Sinter documentation. Browser-side Site Tools let an agent look up Sinter docs — read-only, documentation only.
Does Sinter support Rocky Linux 10?
sinter_get_compatibility
Yes. Rocky Linux 10 on x86_64 is supported and acceptance-tested, using the dnf backend.
Core MCP
AI → bounded Sinter capabilities, without arbitrary SSH authority.
sinter mcpnamed targetPLAN / AUDIT- Validate and inspect recipes
- Plan changes against supplied facts
- List administrator-named targets
- Run read-only plan and audit on those targets
Named targets only · read-only Plan/Audit · no Apply · no arbitrary SSH or commands
Supported platforms
Ubuntu 24.04 & 26.04 · Rocky Linux 9 & 10 · RHEL 9 & 10 · AlmaLinux 9 & 10
amd64/x86_64 — supported, acceptance-tested
Oracle Linux (x86_64, dnf) is expected compatible but not acceptance-tested.
Install
curl -fsSL https://sinter.fulltrust.co.jp/install.sh | shLinux x86_64. The installer verifies checksums and version before placing the binary.
Documentation
Guides, concepts, recipe format, and the full resource reference.
Sinter is an agentless configuration-management tool for Linux servers managed over SSH.