# AI-Infra-Guard Deployment Profiles: Docker, Standalone Binary, and Python Module Options

> Explore AI-Infra-Guard deployment profiles: Docker, standalone binary, and Python module. Choose the best option for your development, testing, or production needs.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: getting-started
- Published: 2026-08-25

---

**AI-Infra-Guard supports six distinct deployment profiles ranging from containerized pre-built images to standalone Go binaries and Python scanning modules, enabling flexible installation strategies for development, testing, and production environments.**

Tencent/AI-Infra-Guard is a hybrid-stack AI security scanning platform that offers multiple deployment configurations to accommodate different infrastructure requirements. Understanding the available **deployment profiles for AI-Infra-Guard** allows operators to choose between containerized orchestration, native binary execution, or modular Python-based scanning depending on their specific security assessment needs.

## Overview of AI-Infra-Guard Deployment Profiles

The repository structure supports six primary deployment configurations defined across [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml), [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), and various Python module directories. Each profile serves distinct operational contexts, from rapid containerized deployment to customized source-based installation.

## Docker-Based Deployment Profiles

The Docker configurations provide the fastest path to production deployment using the `zhuquelab/aig-server` and `zhuquelab/aig-agent` images.

### Pre-Built Image Profile (docker-compose.images.yml)

The pre-built profile utilizes published container images without requiring local compilation. According to [`readme/README_ZH.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/readme/README_ZH.md), this profile deploys both the server and agent components with a single command.

```bash
docker-compose -f docker-compose.images.yml up -d

```

The [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) file defines two services:

- **server**: Uses `zhuquelab/aig-server:latest` with environment variables including `AIG_SERVER=0.0.0.0:8088`, `AIG_API_KEY=default_api_key`, and extensive Redis configuration options
- **agent**: Uses `zhuquelab/aig-agent:latest` connecting to `server:8088` via the `AIG_SERVER` environment variable and sharing logging parameters like `AIG_LOG_MAXSIZE=10M` and `AIG_LOG_ROTATE_DAILY=true`

This profile includes comprehensive Redis sentinel, cluster mode, and TLS configuration options (lines 61-84 of the compose file), making it suitable for production environments requiring high availability.

### Local Build Profile (docker-compose.yml)

For development or customization, the local build profile compiles images from the repository's `Dockerfile` rather than pulling pre-built images. As documented in the Chinese README, operators execute:

```bash
docker-compose up -d

```

This profile builds the server binary from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) and agent components from local source, enabling modifications to the Go codebase before deployment.

## Standalone Binary Deployment Profiles

When containerization is unnecessary or prohibited, AI-Infra-Guard supports direct compilation and execution of Go binaries.

### Go Server Profile (cmd/cli/main.go)

The standalone server profile compiles the main CLI application responsible for Web services, task management, and rule engine execution. Build and launch using:

```bash
go build -o ai-infra-guard ./cmd/cli/main.go
./ai-infra-guard webserver --server 127.0.0.1:8088

```

This profile exposes the Web interface on the specified address (default `127.0.0.1:8088`) and requires the `AIG_AGENT_PROVIDER` configuration for agent connectivity. Note that [`readme/README_ZH.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/readme/README_ZH.md) explicitly warns against binding to non-localhost addresses in production without proper network isolation.

### Go Agent Profile (cmd/agent)

The agent profile establishes WebSocket connections to an existing server instance for distributed scanning operations. Compilation and execution follow this pattern:

```bash
go build -o agent ./cmd/agent
AIG_SERVER=127.0.0.1:8088 ./agent

```

The agent binary requires the `AIG_SERVER` environment variable pointing to the server address and shares configuration parameters like `AIG_GUARDIAN_ENABLED=true` and `AIG_MAX_PARALLEL=4` with the server component.

## Python Module Deployment Profiles

AI-Infra-Guard includes three specialized Python subsystems for MCP (Model/Code/Product/Network) scanning, agent-based workflows, and prompt security evaluation.

### MCP Scanner Profile (mcp-scan/main.py)

The MCP scanner performs repository-level analysis for model and code vulnerabilities. Deployment requires:

```bash
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

```

This profile operates independently of the Go server and requires only local Python dependencies.

### Agent Scanner Profile (agent-scan/main.py)

For agent-assisted scanning workflows, deploy the agent scanner using:

```bash
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/project --agent_provider /path/to/provider.yaml

```

This profile connects to the provider configuration specified in the YAML file, integrating with the broader AI-Infra-Guard architecture described in [`AGENTS.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AGENTS.md).

### Prompt Security Profile (AIG-PromptSecurity/main.py)

The prompt security module evaluates AI model inputs for injection vulnerabilities:

```bash
pip install -r AIG-PromptSecurity/requirements.txt

```

This profile functions as a standalone security tool or integrates with the main scanning pipeline.

## Hybrid Deployment Architecture

Production deployments typically combine multiple profiles according to [`AGENTS.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AGENTS.md) and the Docker compose specifications. A common hybrid configuration runs the Docker-based server ([`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml)), connects native Go agents for specific network segments, and invokes Python scanners ([`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py) or [`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py)) for targeted repository analysis. This architecture leverages the containerized infrastructure for core services while maintaining flexibility for specialized scanning tasks.

## Summary

- **Pre-built Docker Profile**: Fastest deployment using `zhuquelab/aig-server:latest` and `zhuquelab/aig-agent:latest` images via [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml)
- **Local Docker Build Profile**: Source-based containerization for development and customization using the default [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml)
- **Standalone Go Server**: Native binary compiled from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) for Web service and rule engine execution
- **Standalone Go Agent**: WebSocket-connected scanner compiled from `cmd/agent` for distributed operations
- **Python MCP Scanner**: Repository analysis tool in `mcp-scan/` for model/code/product/network scanning
- **Python Agent Scanner**: Workflow-integrated scanner in `agent-scan/` requiring provider YAML configuration
- **Hybrid Architecture**: Combines Docker services with standalone binaries and Python modules for comprehensive coverage

## Frequently Asked Questions

### What is the difference between the pre-built and local build Docker profiles?

The pre-built profile pulls published images from `zhuquelab/aig-server` and `zhuquelab/aig-agent`, enabling immediate deployment without compilation. The local build profile compiles the Go source code from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) and `cmd/agent` during the Docker build process, allowing custom modifications and development testing before image creation.

### Can I run the AI-Infra-Guard server without Docker?

Yes. Compile the standalone binary using `go build -o ai-infra-guard ./cmd/cli/main.go` and execute `./ai-infra-guard webserver --server 127.0.0.1:8088`. This deployment profile requires manual configuration of Redis and environment variables otherwise managed by Docker Compose.

### How do the Python scanning modules integrate with the Go server?

The Python modules (`mcp-scan`, `agent-scan`, `AIG-PromptSecurity`) operate as standalone CLI tools but can integrate with the broader infrastructure through the agent profile. Specifically, [`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py) accepts an `--agent_provider` parameter linking to the YAML configuration used by the Go agent, while the Go server orchestrates results through the WebSocket protocol defined in [`AGENTS.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AGENTS.md).

### Which deployment profile is recommended for production environments?

The pre-built Docker profile using [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) is recommended for production due to its built-in Redis clustering support, TLS configuration options, and standardized environment variable management. However, organizations requiring custom rule modifications may prefer the local build profile or a hybrid approach combining containerized servers with customized Python scanners.