AI-Infra-Guard Deployment Profiles: Docker, Standalone Binary, and Python Module Options

AI-Infra-Guard supports six distinct deployment profiles ranging from containerized pre-built images to standalone Go binaries and Python scanning modules, enabling flexible installation strategies for development, testing, and production environments.

Tencent/AI-Infra-Guard is a hybrid-stack AI security scanning platform that offers multiple deployment configurations to accommodate different infrastructure requirements. Understanding the available deployment profiles for AI-Infra-Guard allows operators to choose between containerized orchestration, native binary execution, or modular Python-based scanning depending on their specific security assessment needs.

Overview of AI-Infra-Guard Deployment Profiles

The repository structure supports six primary deployment configurations defined across docker-compose.images.yml, cmd/cli/main.go, and various Python module directories. Each profile serves distinct operational contexts, from rapid containerized deployment to customized source-based installation.

Docker-Based Deployment Profiles

The Docker configurations provide the fastest path to production deployment using the zhuquelab/aig-server and zhuquelab/aig-agent images.

Pre-Built Image Profile (docker-compose.images.yml)

The pre-built profile utilizes published container images without requiring local compilation. According to readme/README_ZH.md, this profile deploys both the server and agent components with a single command.

docker-compose -f docker-compose.images.yml up -d

The docker-compose.images.yml file defines two services:

  • server: Uses zhuquelab/aig-server:latest with environment variables including AIG_SERVER=0.0.0.0:8088, AIG_API_KEY=default_api_key, and extensive Redis configuration options
  • agent: Uses zhuquelab/aig-agent:latest connecting to server:8088 via the AIG_SERVER environment variable and sharing logging parameters like AIG_LOG_MAXSIZE=10M and AIG_LOG_ROTATE_DAILY=true

This profile includes comprehensive Redis sentinel, cluster mode, and TLS configuration options (lines 61-84 of the compose file), making it suitable for production environments requiring high availability.

Local Build Profile (docker-compose.yml)

For development or customization, the local build profile compiles images from the repository's Dockerfile rather than pulling pre-built images. As documented in the Chinese README, operators execute:

docker-compose up -d

This profile builds the server binary from cmd/cli/main.go and agent components from local source, enabling modifications to the Go codebase before deployment.

Standalone Binary Deployment Profiles

When containerization is unnecessary or prohibited, AI-Infra-Guard supports direct compilation and execution of Go binaries.

Go Server Profile (cmd/cli/main.go)

The standalone server profile compiles the main CLI application responsible for Web services, task management, and rule engine execution. Build and launch using:

go build -o ai-infra-guard ./cmd/cli/main.go
./ai-infra-guard webserver --server 127.0.0.1:8088

This profile exposes the Web interface on the specified address (default 127.0.0.1:8088) and requires the AIG_AGENT_PROVIDER configuration for agent connectivity. Note that readme/README_ZH.md explicitly warns against binding to non-localhost addresses in production without proper network isolation.

Go Agent Profile (cmd/agent)

The agent profile establishes WebSocket connections to an existing server instance for distributed scanning operations. Compilation and execution follow this pattern:

go build -o agent ./cmd/agent
AIG_SERVER=127.0.0.1:8088 ./agent

The agent binary requires the AIG_SERVER environment variable pointing to the server address and shares configuration parameters like AIG_GUARDIAN_ENABLED=true and AIG_MAX_PARALLEL=4 with the server component.

Python Module Deployment Profiles

AI-Infra-Guard includes three specialized Python subsystems for MCP (Model/Code/Product/Network) scanning, agent-based workflows, and prompt security evaluation.

MCP Scanner Profile (mcp-scan/main.py)

The MCP scanner performs repository-level analysis for model and code vulnerabilities. Deployment requires:

pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

This profile operates independently of the Go server and requires only local Python dependencies.

Agent Scanner Profile (agent-scan/main.py)

For agent-assisted scanning workflows, deploy the agent scanner using:

pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/project --agent_provider /path/to/provider.yaml

This profile connects to the provider configuration specified in the YAML file, integrating with the broader AI-Infra-Guard architecture described in AGENTS.md.

Prompt Security Profile (AIG-PromptSecurity/main.py)

The prompt security module evaluates AI model inputs for injection vulnerabilities:

pip install -r AIG-PromptSecurity/requirements.txt

This profile functions as a standalone security tool or integrates with the main scanning pipeline.

Hybrid Deployment Architecture

Production deployments typically combine multiple profiles according to AGENTS.md and the Docker compose specifications. A common hybrid configuration runs the Docker-based server (docker-compose.images.yml), connects native Go agents for specific network segments, and invokes Python scanners (mcp-scan/main.py or agent-scan/main.py) for targeted repository analysis. This architecture leverages the containerized infrastructure for core services while maintaining flexibility for specialized scanning tasks.

Summary

  • Pre-built Docker Profile: Fastest deployment using zhuquelab/aig-server:latest and zhuquelab/aig-agent:latest images via docker-compose.images.yml
  • Local Docker Build Profile: Source-based containerization for development and customization using the default docker-compose.yml
  • Standalone Go Server: Native binary compiled from cmd/cli/main.go for Web service and rule engine execution
  • Standalone Go Agent: WebSocket-connected scanner compiled from cmd/agent for distributed operations
  • Python MCP Scanner: Repository analysis tool in mcp-scan/ for model/code/product/network scanning
  • Python Agent Scanner: Workflow-integrated scanner in agent-scan/ requiring provider YAML configuration
  • Hybrid Architecture: Combines Docker services with standalone binaries and Python modules for comprehensive coverage

Frequently Asked Questions

What is the difference between the pre-built and local build Docker profiles?

The pre-built profile pulls published images from zhuquelab/aig-server and zhuquelab/aig-agent, enabling immediate deployment without compilation. The local build profile compiles the Go source code from cmd/cli/main.go and cmd/agent during the Docker build process, allowing custom modifications and development testing before image creation.

Can I run the AI-Infra-Guard server without Docker?

Yes. Compile the standalone binary using go build -o ai-infra-guard ./cmd/cli/main.go and execute ./ai-infra-guard webserver --server 127.0.0.1:8088. This deployment profile requires manual configuration of Redis and environment variables otherwise managed by Docker Compose.

How do the Python scanning modules integrate with the Go server?

The Python modules (mcp-scan, agent-scan, AIG-PromptSecurity) operate as standalone CLI tools but can integrate with the broader infrastructure through the agent profile. Specifically, agent-scan/main.py accepts an --agent_provider parameter linking to the YAML configuration used by the Go agent, while the Go server orchestrates results through the WebSocket protocol defined in AGENTS.md.

The pre-built Docker profile using docker-compose.images.yml is recommended for production due to its built-in Redis clustering support, TLS configuration options, and standardized environment variable management. However, organizations requiring custom rule modifications may prefer the local build profile or a hybrid approach combining containerized servers with customized Python scanners.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →