Turn scattered
infrastructure
operations
into workflows your
team can control

Semaphore UI gives your team one self-hosted place to run,
share, schedule, secure, and audit operational workflows.

Task Templates

Name Run Status
AnsibleAnsible
TerraformTerraform
OpenTofuOpenTofu
TerragruntTerragrunt
Bash scriptBash
PowerShellPowerShell
PythonPython

Use Semaphore UI with Ansible, Terraform, OpenTofu, Terragrunt, Bash, PowerShell, and Python, while keeping your automation in Git and your existing toolchain intact.

Run infrastructure work
through workflows,
not workarounds

Infrastructure workflows not workarounds
INFRASTRUCTURE & DEVOPS

Simplify routine ops

When routine ops pile up, it is easy to miss steps, lose context, or overlook failures. Turn recurring jobs into reusable workflows with inputs, secrets, schedules, logs, and access control.

SITE RELIABILITY ENGINEERING

Make every run traceable

When jobs fail or incidents happen, missing context slows everyone down. See what ran, who launched it, when it happened, what changed, and whether it succeeded or failed.

SUPPORT & OPERATIONS

Enable safe self-service operations

Infra teams should not be the bottleneck for every routine request. Let approved users run checks, restarts, and cleanups without Linux access, SSH, credentials, or CLI.

Semaphore UI trusted by thousands of teams worldwide

#1
Alternative to AWX / AAP
14K+
Stars on GitHub ↗
6M+
Pulls on Docker Hub ↗
100K+
Installations

Easy to set up

Deploy Semaphore UI on Linux or Windows, with Docker, or on Kubernetes using the official Helm chart — and keep it easy to maintain.

Simple to use

Everything your team needs to run automation day to day: tasks, logs, schedules, Git, API, and notifications in a clean UI without unnecessary complexity.

Self-hosted by design. Secure by default

Run Semaphore inside your own network and keep all operational data under your control.

DockerHelm chart

Flexible deployment

Host Semaphore on a server, VM, container, or Kubernetes cluster.

Go programming language

Lightweight Go application

Written in pure Go, Semaphore is simple to deploy, update, and maintain.

LinuxWindows

Windows and Linux friendly

Work across Windows, Linux, and your existing automation stack.

One platform to define, run, control, and scale infrastructure jobs

DEFINE
Web UI & git

Keep automation in Git, make it usable in the UI

Keep scripts, playbooks, and IaC projects in Git, then add templates, variables, credentials, and inventories in Semaphore's UI.

Terraform provider

Replace manual clicks with Terraform-managed configuration

Manage projects, templates, inventories, and more with Terraform, so setup changes are easier to review, repeat and maintain.

MCP

Set up automation faster with AI assistance

Use the Semaphore MCP server to inspect and update projects, templates, inventories, repositories, schedules, and task context.

RUN
Schedules

Replace scattered cron jobs

Schedule patching, backups, checks, cleanup, and other routine jobs with run history and logs.

Workflows

Coordinate multi-step operations

Connect jobs, approvals, dependencies, and handoffs into repeatable workflows.

API Integrations & Webhooks

Trigger jobs from any system

Start tasks from CI/CD, incident tools, and other workflows through Semaphore's API.

CONTROL
Secrets Management

Protect secrets and credentials

Store SSH keys, tokens, passwords, and sudo credentials in the encrypted Key Store, or connect HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and more.

Access Control

Control who can view, run, and manage jobs

Use RBAC, projects, LDAP/AD, OIDC, and custom roles to give people the right level of access.

Audit

Trace every job run

Review status, output, errors, logs, and run history to debug failures and verify changes.

Notifications

Alert teams when jobs need attention

Send job updates to Slack, Teams, email, or webhooks.

SCALE
Project Runners

Run jobs near your infrastructure

Execute automation on tagged project runners inside the right subnet, private network, or isolated project environment.

High Availability

Reduce downtime for critical automation

Use high availability, disaster recovery, backups to keep Semaphore reliable in production.

Support

Resolve issues faster with expert support

Use Pro support to resolve issues faster, or add Enterprise onboarding, migration help, and guidance to ramp up your team.

Why Engineers choose Semaphore?

Practical infrastructure automation
Easy to set up
Less ops mess
Scheduled jobs
Ansible, Terraform, scripts
Clear logs
Self-service runs
Webhooks & integrations
@marcosmas28
@marcosmas28
GitHub Discussion #2149
ANSIBLELOGSSCHEDULESLACK ALERTS

“I’ve been testing its features and I really like this app. It has everything I need to run my ansible playbooks: log viewer, scheduler, github integration, and slack alerts…”

A
u/Anxious-Condition630
Reddit · r/Netbox
NETBOXANSIBLEGITLABWEBHOOK

“Semaphore and Netbox is all you need. No extra containers or helpers. Semaphore executes the Ansible Playbooks, by pulling them in from a Gitlab Repo in our case…”

R
u/redditphantom
Reddit · r/ansible
SCHEDULEFAILURE LOGSEASY SETUP

“As I said my main use is to view failures on scheduled items and address them as well as seeing the historic failures as a trend. I am sure there are ways to do this on the cli but it was so easy to set up semaphore that I kept going with it.”

S
u/Same_Quit3052
Reddit · r/ansible
POWERSHELLTERRAFORMWEBHOOK

“I’m running it on prod at work. The OSS version. Works fine for us. Using it for ansible, some power shell stuff and terraform. Also, using the integration feature to act as a webhook so external entities can start the templates.”

R
u/Ramiraz80
Reddit · r/ansible
EASY SETUPDELEGATIONNON LINUX

“We use SemaphoreUI, for our ansible needs at my workplace :) What we needed was a tool, that would allow non linux users to run predefined playbooks, and only call us when something fails. Semaphore is great for that :) What we also needed, was a tool, that was easy to set up, and didn't require a whole fleet of servers just to run.”

I
u/i8ad8
Reddit · r/selfhosted
AUTOMATATIONSCHEDULEDISK CHECKS

“I discovered Semaphore UI and started using its scheduling feature to run regular maintenance playbooks. It's been a great way to automate updates, disk checks, and other housekeeping without writing extra cron jobs or scripts.”

S
u/salt_life_
Reddit · r/ansible
TRACK JOBSCREDENTIALSINVENTORY

“I run semaphore UI over GitHub actions as I feel like it’s a better UI over tracking job status as a whole and I like that I can maintain things like credentials and one-off inventory that I wouldn’t want to manage via git.”

K
u/kY2iB3yH0mN8wl2h
Reddit · r/ansible
WINDOWSPOWERSHELLANSIBLESIMPLE

“We are using semaphoreui.com for windows servers. it does powershell quite nicely and ansible as well. No need for complex AAP or AWX deployments where you more or less need K8 just to get started.”

@goug76
@goug76
GitHub Discussion #2017
MANAGE SERVERS WITH EASE

“By the way I absolutely love Semaphore, makes managing all my servers a breeze. Keep up the GREAT work!”

Choose the level of control your infrastructure requires

Choose the plan that matches your operational, security, and deployment requirements.

CORE AUTOMATION

Community

Bring scripts, playbooks, and routine jobs into one interface.

web UIAPItask templatesscheduleskey storagegitlogsworkflows2FARBACOIDC / SSOLDAP/AD
ADVANCED OPERATIONAL CONTROL

Pro

Add built-in controls, isolated execution, visibility, and product support.

isolated executionlog exportbuilt-in Terraform statesupportHashiCorp Vaulttask execution summaries
LARGE-SCALE INFRASTRUCTURE REQUIREMENTS

Enterprise

Adapt Semaphore to complex infrastructure, identity, availability, and deployment requirements.

High Availabilityair-gappedcustom rolesgranular permissionsAWS Secrets ManagerAzure Key VaultDevolutions Serveridentity group mappingSLAmigration assistance
LinuxInstall Semaphore UI on Linux from a binary.WindowsInstall Semaphore UI on Windows from a binary.macOSInstall Semaphore UI on macOS from a binary.DockerRun Semaphore UI with Docker Compose.HelmDeploy Semaphore UI with its Helm chart.AnsibleRun Ansible playbooks with task templates.TerraformRun Terraform and OpenTofu code with task templates.TerragruntNo dedicated Terragrunt guide; see custom Bash templates.PulumiNo dedicated Pulumi guide; see custom Bash templates.PowerShellRun PowerShell scripts on Windows hosts or runners.PythonRun Python scripts with task templates.Bash scriptRun shell scripts with Bash task templates.KubernetesInstall Semaphore UI on Kubernetes using Helm.PostgreSQLConfigure PostgreSQL as the Semaphore UI database.MySQLConfigure MySQL as the Semaphore UI database.SQLiteConfigure SQLite as the Semaphore UI database.RedisCoordinate Enterprise high availability nodes with Redis.KafkaNo dedicated Kafka guide; see custom Bash templates.CircleCINo dedicated CircleCI guide; see HTTP task triggers.TeleportNo dedicated Teleport guide; see SSH credentials in the Key Store.ZITADELConfigure single sign-on with ZITADEL.Microsoft AzureConfigure single sign-on with Microsoft Azure.LDAPAuthenticate users through an LDAP directory.OpenID ConnectConfigure OpenID Connect single sign-on.

Built to work with your infrastructure stack

Semaphore UI connects the tools teams already use for automation, code, inventory, secrets, identity, notifications, APIs, and deployment.

WebhooksTrigger task templates from incoming webhooks.NGINXConfigure NGINX as a reverse proxy for Semaphore UI.ApacheConfigure Apache as a reverse proxy for Semaphore UI.GitConnect Git repositories over HTTPS or SSH.JavaNo dedicated Java guide; see custom Bash templates.GitHubTrigger Semaphore UI tasks with GitHub webhooks.BitbucketConnect Bitbucket repositories using an access token.GitLabConfigure single sign-on with GitLab.Google CloudConfigure single sign-on with Google.PrometheusScrape process and task metrics with Prometheus (2.20+).authentikConfigure single sign-on with authentik.Kubernetes OperatorsThe Kubernetes guide covers Helm deployment; no operator guide is available.HashiCorp VaultRetrieve credentials from HashiCorp Vault.Azure Key VaultSync Azure Key Vault secrets into the Key Store.SecurityLearn about authentication, access control and security.SentryNo dedicated Sentry guide; see logging and audit export options.SlackSend task notifications to Slack.Microsoft TeamsSend task notifications to Microsoft Teams.TelegramSend task notifications to Telegram.Rocket.ChatSend task notifications to Rocket.Chat.EmailSend task notifications by email.GotifySend task notifications to Gotify.SwaggerExplore the Semaphore UI API with Swagger.PostmanTest the API with the official Postman collection.

Community you can learn from, build with, and contribute to

Popular in homelabs and proven in real infrastructure work, Semaphore UI has an active community sharing tutorials, walkthroughs, use cases, and hands-on reviews. Learn from them, build on them, and contribute improvements back.

FAQ

What is Semaphore UI?

Semaphore UI is an open-source, self-hosted web UI and API for running infrastructure automation. It helps teams run Ansible playbooks, Terraform, OpenTofu, Terragrunt, PowerShell, Bash scripts, and Python tasks from one controlled interface.

Is Semaphore UI only for Ansible?

No. Semaphore UI supports Ansible, Terraform, OpenTofu, Terragrunt, Bash, PowerShell, and Python. Teams can use the same interface to run playbooks, infrastructure-as-code workflows, scheduled jobs, and operational tasks.

Is Semaphore UI self-hosted?

Yes. Semaphore UI is self-hosted and open source. It is written in Go, runs on Linux, macOS, and Windows, and supports SQLite, MySQL, and PostgreSQL.

How is Semaphore UI different from running automation in CI/CD?

CI/CD is usually optimized for application delivery: build, test, deploy. Semaphore UI is designed for infrastructure and operations work: provisioning, maintenance, remediation, scheduled jobs, ad hoc runbooks, and repeatable tasks that need controlled execution, variables, credentials, logs, and team access. You can keep CI/CD focused on delivery and move operational workflows into a dedicated self-hosted automation layer.

Can we keep our existing playbooks, scripts, and IaC repositories?

Yes. Semaphore UI works with your existing repositories and automation. You can define task templates around your playbooks, scripts, and infrastructure-as-code workflows, pass variables, schedule runs, and trigger tasks through the API.

Can we run automation inside our private network?

Yes. Because Semaphore UI is self-hosted, your automation, credentials, repositories, inventories, and execution environment stay under your control. Tasks can run on the main Semaphore UI server or on separate runners. With Project Runners in Pro, you can assign dedicated runners to specific projects or task templates, so automation can execute closer to the right subnet, environment, or infrastructure boundary. For stricter security requirements, Enterprise also supports air-gapped/offline and multi-instance license options.

Can support or ops teams run approved actions without SSH access?

Yes. You can turn restarts, checks, cleanups, diagnostics, maintenance tasks, or recovery steps into task templates, then let the right users run them through Semaphore UI without giving them direct server access, raw credentials, or broad production permissions.

Can Semaphore UI work with dynamic inventory?

Yes. Semaphore UI supports file-based Ansible inventories, which means you can use Ansible dynamic inventory plugins and external inventory sources as part of your automation workflows. For example, you can pull infrastructure data directly from NetBox using the netbox.netbox.nb_inventory plugin and run playbooks against automatically discovered hosts instead of maintaining inventory by hand. See the NetBox dynamic inventory example in the documentation: https://semaphoreui.com/docs/user-guide/netbox. Semaphore UI can also be used with other Ansible inventory plugins and scripts configured in your automation environment, while still providing centralized credentials, variables, schedules, logs, and task execution.

How does Semaphore UI handle secrets and credentials?

Semaphore UI includes a Key Store for credentials used by tasks, including repository access, remote host access, sudo credentials, and Ansible Vault passwords. Secrets can be stored in Semaphore’s encrypted database, and Semaphore also supports external secret storage with HashiCorp Vault. For teams with stricter secret-management requirements, Enterprise can use Devolutions Server, AWS Secrets Manager and Azure Key Vault as an external secret storage option. Secrets are passed to jobs at runtime, so teams can run approved automation without exposing raw credentials in scripts, terminals, or shared documentation.

How can we buy Semaphore UI Pro or Enterprise?

You can buy Semaphore UI Pro directly from the pricing page. After purchase, you receive a license key that can be used to activate Pro features in your self-hosted instance. If your company needs an invoice, bank transfer, custom terms, offline licensing, multiple instances, or Enterprise support, contact the team from the pricing page to arrange the right option.