Installation
Install
Section titled “Install”Sinter v1.3.0 ships one sinter-v1.3.0-linux-x86_64.tar.gz artifact
covering every supported Linux x86_64 platform line — Ubuntu 24.04 / 26.04
LTS, Rocky Linux 9 / 10, RHEL 9 / 10, and AlmaLinux 9 / 10.
curl -fsSL https://sinter.fulltrust.co.jp/install.sh | sh$HOME/.local/bin/sinter --versionThe installer selects the latest stable official GitHub release, verifies
SHA256SUMS before extraction, and installs without sudo into $HOME/.local/bin.
If needed, add that directory to PATH yourself; shell profiles are not edited.
For inspect-before-run and manual downloads, see
Installation.
Inspect before running
Section titled “Inspect before running”curl -fsSLo install.sh https://sinter.fulltrust.co.jp/install.shless install.shsh install.shVersion and destination
Section titled “Version and destination”SINTER_VERSION=v1.3.0 sh install.shSINTER_INSTALL_DIR="$HOME/bin" sh install.shInstaller support is Linux x86_64/amd64 only. It requires curl, GNU tar and coreutils (including sha256sum). Unsupported OS/architectures fail; no ARM artifact exists. The destination must be an absolute trusted directory. An existing regular user-owned executable can be replaced atomically; symlinks and nonregular objects are refused. Network/checksum/layout failures leave the existing executable intact. No sudo, PATH or shell-profile modification occurs. Checksums detect corruption and release consistency, not compromise of GitHub.
Manual release installation
Section titled “Manual release installation”ASSET=sinter-v1.3.0-linux-x86_64.tar.gzcurl -fLO "https://github.com/hagix9/sinter/releases/download/v1.3.0/$ASSET"curl -fLO https://github.com/hagix9/sinter/releases/download/v1.3.0/SHA256SUMSgrep -F " $ASSET" SHA256SUMS | sha256sum -c -tar -xzf "$ASSET"sudo install -m 0755 "${ASSET%.tar.gz}/sinter" /usr/local/bin/sinter/usr/local/bin/sinter --versionThe environment applies to installation only, not persistent host configuration. Historical v0.2.1 assets keep their original distro-specific names.
Controller on macOS (or other environments)
Section titled “Controller on macOS (or other environments)”No macOS release artifact exists. Build from source instead — see below. Managed hosts remain the supported Linux targets regardless of where the controller runs.
Build from source
Section titled “Build from source”Requires a Rust toolchain (rustup or your distribution’s packages):
git clone https://github.com/hagix9/sinter.gitcd sintercargo build --locked --release./target/release/sinter --versionCopy target/release/sinter somewhere on your PATH to use it like an
installed binary.
Managed host requirements
Section titled “Managed host requirements”The target does not need Sinter installed. It needs:
- an OpenSSH server whose host key is already in your
known_hosts - systemd
/bin/sh- the
attrpackage (/usr/bin/getfattr) — Sinter inspects extended attributes and POSIX ACLs before writing any path and refuses paths it cannot prove safe. Checktest -x /usr/bin/getfattron each target. If missing, installattrwithsudo apt install attr(Ubuntu) orsudo dnf install attr(RHEL family: Rocky, RHEL, AlmaLinux) - passwordless
sudo -nif you use--sudo - a user account whose public key you have authorized, reachable with your SSH agent or a key file
SSH credentials
Section titled “SSH credentials”Sinter uses SSH for both transport and authentication. Two identities are involved, and they are checked separately:
- Host identity (the target’s host key). Sinter verifies the server
against your
known_hostsfile (default~/.ssh/known_hosts, or--known-hosts). Unknown or changed host keys fail closed; Sinter never auto-enrolls. - User authentication (your private key). Sinter tries, in order:
your ssh-agent (if one is running), each
--identityfile, then the default~/.ssh/id_ed25519and~/.ssh/id_rsa. The corresponding public key must already be authorized on the target for the target user — Sinter does not provision keys.
Sinter refuses unknown or changed SSH host keys. Non-default SSH ports require
an explicit [host]:port entry in known_hosts.