AI-Infra-Guard Deployment Profiles: Docker, Standalone Binary, and Python Module Options
AI-Infra-Guard supports six distinct deployment profiles ranging from containerized pre-built images to standalone Go binaries and Python scanning modules, enabling flexible installation strategies for development, testing, and production environments.
Tencent/AI-Infra-Guard is a hybrid-stack AI security scanning platform that offers multiple deployment configurations to accommodate different infrastructure requirements. Understanding the available deployment profiles for AI-Infra-Guard allows operators to choose between containerized orchestration, native binary execution, or modular Python-based scanning depending on their specific security assessment needs.
Overview of AI-Infra-Guard Deployment Profiles
The repository structure supports six primary deployment configurations defined across docker-compose.images.yml, cmd/cli/main.go, and various Python module directories. Each profile serves distinct operational contexts, from rapid containerized deployment to customized source-based installation.
Docker-Based Deployment Profiles
The Docker configurations provide the fastest path to production deployment using the zhuquelab/aig-server and zhuquelab/aig-agent images.
Pre-Built Image Profile (docker-compose.images.yml)
The pre-built profile utilizes published container images without requiring local compilation. According to readme/README_ZH.md, this profile deploys both the server and agent components with a single command.
docker-compose -f docker-compose.images.yml up -d
The docker-compose.images.yml file defines two services:
- server: Uses
zhuquelab/aig-server:latestwith environment variables includingAIG_SERVER=0.0.0.0:8088,AIG_API_KEY=default_api_key, and extensive Redis configuration options - agent: Uses
zhuquelab/aig-agent:latestconnecting toserver:8088via theAIG_SERVERenvironment variable and sharing logging parameters likeAIG_LOG_MAXSIZE=10MandAIG_LOG_ROTATE_DAILY=true
This profile includes comprehensive Redis sentinel, cluster mode, and TLS configuration options (lines 61-84 of the compose file), making it suitable for production environments requiring high availability.
Local Build Profile (docker-compose.yml)
For development or customization, the local build profile compiles images from the repository's Dockerfile rather than pulling pre-built images. As documented in the Chinese README, operators execute:
docker-compose up -d
This profile builds the server binary from cmd/cli/main.go and agent components from local source, enabling modifications to the Go codebase before deployment.
Standalone Binary Deployment Profiles
When containerization is unnecessary or prohibited, AI-Infra-Guard supports direct compilation and execution of Go binaries.
Go Server Profile (cmd/cli/main.go)
The standalone server profile compiles the main CLI application responsible for Web services, task management, and rule engine execution. Build and launch using:
go build -o ai-infra-guard ./cmd/cli/main.go
./ai-infra-guard webserver --server 127.0.0.1:8088
This profile exposes the Web interface on the specified address (default 127.0.0.1:8088) and requires the AIG_AGENT_PROVIDER configuration for agent connectivity. Note that readme/README_ZH.md explicitly warns against binding to non-localhost addresses in production without proper network isolation.
Go Agent Profile (cmd/agent)
The agent profile establishes WebSocket connections to an existing server instance for distributed scanning operations. Compilation and execution follow this pattern:
go build -o agent ./cmd/agent
AIG_SERVER=127.0.0.1:8088 ./agent
The agent binary requires the AIG_SERVER environment variable pointing to the server address and shares configuration parameters like AIG_GUARDIAN_ENABLED=true and AIG_MAX_PARALLEL=4 with the server component.
Python Module Deployment Profiles
AI-Infra-Guard includes three specialized Python subsystems for MCP (Model/Code/Product/Network) scanning, agent-based workflows, and prompt security evaluation.
MCP Scanner Profile (mcp-scan/main.py)
The MCP scanner performs repository-level analysis for model and code vulnerabilities. Deployment requires:
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project
This profile operates independently of the Go server and requires only local Python dependencies.
Agent Scanner Profile (agent-scan/main.py)
For agent-assisted scanning workflows, deploy the agent scanner using:
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/project --agent_provider /path/to/provider.yaml
This profile connects to the provider configuration specified in the YAML file, integrating with the broader AI-Infra-Guard architecture described in AGENTS.md.
Prompt Security Profile (AIG-PromptSecurity/main.py)
The prompt security module evaluates AI model inputs for injection vulnerabilities:
pip install -r AIG-PromptSecurity/requirements.txt
This profile functions as a standalone security tool or integrates with the main scanning pipeline.
Hybrid Deployment Architecture
Production deployments typically combine multiple profiles according to AGENTS.md and the Docker compose specifications. A common hybrid configuration runs the Docker-based server (docker-compose.images.yml), connects native Go agents for specific network segments, and invokes Python scanners (mcp-scan/main.py or agent-scan/main.py) for targeted repository analysis. This architecture leverages the containerized infrastructure for core services while maintaining flexibility for specialized scanning tasks.
Summary
- Pre-built Docker Profile: Fastest deployment using
zhuquelab/aig-server:latestandzhuquelab/aig-agent:latestimages viadocker-compose.images.yml - Local Docker Build Profile: Source-based containerization for development and customization using the default
docker-compose.yml - Standalone Go Server: Native binary compiled from
cmd/cli/main.gofor Web service and rule engine execution - Standalone Go Agent: WebSocket-connected scanner compiled from
cmd/agentfor distributed operations - Python MCP Scanner: Repository analysis tool in
mcp-scan/for model/code/product/network scanning - Python Agent Scanner: Workflow-integrated scanner in
agent-scan/requiring provider YAML configuration - Hybrid Architecture: Combines Docker services with standalone binaries and Python modules for comprehensive coverage
Frequently Asked Questions
What is the difference between the pre-built and local build Docker profiles?
The pre-built profile pulls published images from zhuquelab/aig-server and zhuquelab/aig-agent, enabling immediate deployment without compilation. The local build profile compiles the Go source code from cmd/cli/main.go and cmd/agent during the Docker build process, allowing custom modifications and development testing before image creation.
Can I run the AI-Infra-Guard server without Docker?
Yes. Compile the standalone binary using go build -o ai-infra-guard ./cmd/cli/main.go and execute ./ai-infra-guard webserver --server 127.0.0.1:8088. This deployment profile requires manual configuration of Redis and environment variables otherwise managed by Docker Compose.
How do the Python scanning modules integrate with the Go server?
The Python modules (mcp-scan, agent-scan, AIG-PromptSecurity) operate as standalone CLI tools but can integrate with the broader infrastructure through the agent profile. Specifically, agent-scan/main.py accepts an --agent_provider parameter linking to the YAML configuration used by the Go agent, while the Go server orchestrates results through the WebSocket protocol defined in AGENTS.md.
Which deployment profile is recommended for production environments?
The pre-built Docker profile using docker-compose.images.yml is recommended for production due to its built-in Redis clustering support, TLS configuration options, and standardized environment variable management. However, organizations requiring custom rule modifications may prefer the local build profile or a hybrid approach combining containerized servers with customized Python scanners.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →