Installation
Sentinel ships as a single binary. Pick the channel that fits you, then verify what you downloaded before you run it.
Prerequisites
Sentinel orchestrates your database's own client tools rather than reimplementing them. Whichever
way you install it, the tools for the engines you use must be on your PATH:
| Engine | Tools needed |
|---|---|
| PostgreSQL | pg_dump, pg_restore, psql |
| MySQL | mysqldump, mysql |
| MariaDB | mariadb-dump, mariadb |
| MongoDB | mongodump, mongorestore |
Check what Sentinel can see once installed:
sentinel version --tools
Download a prebuilt binary
The recommended route. No Go toolchain required. Every release publishes binaries for Linux, macOS,
and Windows (amd64 and arm64, except windows/arm64), each covered by a SHA-256 checksums.txt.
Download the asset for your platform from the latest release, then verify and install it:
VERSION=1.4.0 # no leading "v"
OS=linux # linux | darwin | windows
ARCH=amd64 # amd64 | arm64
BASE=https://github.com/denisakp/sentinel/releases/latest/download
curl -LO "$BASE/sentinel-$VERSION-$OS-$ARCH.tar.gz"
curl -LO "$BASE/checksums.txt"
sha256sum -c checksums.txt --ignore-missing
Then extract and put it on your PATH:
tar -xzf "sentinel-$VERSION-$OS-$ARCH.tar.gz" # unzip on Windows
sudo mv sentinel /usr/local/bin/
sentinel version
You should see the version, commit, and build date reported.
Verify the release signature
The checksum above proves your archive matches the published list. This check proves something stronger: that the list itself came from Sentinel's release workflow, and not from someone who replaced both files.
Each recent release signs checksums.txt with cosign keyless
signing, publishing a checksums.txt.sigstore.json bundle alongside it. You need cosign v3 or later
no Go toolchain and no Sentinel install.
BASE=https://github.com/denisakp/sentinel/releases/latest/download
curl -LO "$BASE/checksums.txt"
curl -LO "$BASE/checksums.txt.sigstore.json"
cosign verify-blob \
--certificate-identity-regexp 'https://github.com/denisakp/sentinel/.github/workflows/release.yml@refs/tags/.*' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--bundle checksums.txt.sigstore.json \
checksums.txt
You should see Verified OK. Verification fails closed: a tampered checksums.txt, or a signature
from any other identity or issuer, is rejected. Once verified, check your archive against it with
sha256sum -c checksums.txt --ignore-missing.
Releases published before signing was introduced ship no signature bundle. If a release has no
checksums.txt.sigstore.json asset, the checksum-only path above is what you have.
Verify build provenance
The signature proves who published the release. This proves how the binary was built: from which source commit, by which workflow, with no manual step in between. The two checks are independent; neither replaces the other, and you can use either or both.
Each recent release ships a SLSA build-provenance attestation
(multiple.intoto.jsonl), generated by a process with its own identity, separate from the job that
built the binaries. A compromise of the build job alone could not also forge it.
You need slsa-verifier:
VERSION=1.4.0
OS=linux; ARCH=amd64
BASE=https://github.com/denisakp/sentinel/releases/latest/download
curl -LO "$BASE/sentinel-$VERSION-$OS-$ARCH.tar.gz"
curl -LO "$BASE/multiple.intoto.jsonl"
slsa-verifier verify-artifact "sentinel-$VERSION-$OS-$ARCH.tar.gz" \
--provenance-path multiple.intoto.jsonl \
--source-uri github.com/denisakp/sentinel \
--source-tag "v$VERSION"
A tampered archive, or an attestation from an unexpected repository or tag, is rejected.
Releases published before this feature ship no provenance attestation.
Install with go install
If you already have Go 1.24 or later:
go install github.com/denisakp/sentinel@latest
sentinel version will report devA go install build is compiled without the release build flags, so sentinel version reports the
dev / unknown / unknown development fallback instead of a real version, commit, and build date.
Use a prebuilt release binary if you need accurate version reporting; for example when
troubleshooting or filing an issue.
Build from source
For development only. Requires Go 1.24 or later.
git clone https://github.com/denisakp/sentinel.git
cd sentinel
go mod download
go build -o sentinel ./...
./sentinel version
Next
With a working binary, go to the Quickstart and take a real backup.
{/* sources: README.md §Installation, §Verify the release signature, §Verify build provenance, internal/cli/version.go, internal/version/ */}