# AI-Infra-Guard System Requirements: Complete Setup Guide for Linux and Docker

> Discover the system requirements for AI-Infra-Guard. Learn how to set up this powerful AI security tool on Linux and Docker with our comprehensive guide. Get started today.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: how-to-guide
- Published: 2026-08-25

---

**AI-Infra-Guard requires a Linux host with Docker 20.10 or newer, Docker Compose v2, Go 1.20, Node.js 18 LTS, and Python 3.8, with each scanning module maintaining its own [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) for dependency management.**

Tencent/AI-Infra-Guard is a multi-language security scanning platform that combines a Go-based core service, Python scanning modules, and a TypeScript frontend. Meeting the system requirements ensures reliable deployment whether you run the platform via Docker containers or build directly from the source code.

## Core Infrastructure Prerequisites

### Operating System and Container Runtime

The platform targets **Linux environments** exclusively. According to the `Dockerfile` in the repository root, all official images build on Debian or Ubuntu base images. While Windows and macOS can host the platform through Docker, native execution is only supported on Linux distributions.

- **Docker** 20.10 or any compatible OCI runtime
- **Docker Compose** v2.x (the [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) uses version 2 syntax)
- **Linux kernel** (any recent distribution)

### Hardware Specifications

The Go-based core service is lightweight, but Python scanners require additional resources when analyzing large codebases.

- **CPU**: 2 cores minimum for the core service
- **RAM**: 4 GB minimum for the core service, plus additional memory for UI and scanning workers

## Language Runtime Requirements

### Go 1.20 or Newer

The core server, CLI binaries, and agent implementations are written in Go. The `go.mod` file explicitly requires Go 1.20, binding all modules to this version or newer.

```bash
go version  # Verify Go 1.20+

go build -o ai-infra-guard ./cmd/cli/main.go

```

### Node.js 18 LTS for Frontend

The web interface located in `frontend/` uses Vite and TypeScript. The [`frontend/vite.config.ts`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/vite.config.ts) configuration targets Node.js 18 LTS for building production assets.

```bash
cd frontend
npm ci
npm run build

```

### Python 3.8 and Module-Specific Dependencies

Python powers the scanning modules including MCP-scan, Agent-scan, and AIG-PromptSecurity. Each module maintains isolated dependency files in its respective directory:

- [`mcp-scan/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/requirements.txt) - MCP scanning dependencies
- [`agent-scan/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/requirements.txt) - Agent scanning dependencies
- [`AIG-PromptSecurity/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AIG-PromptSecurity/requirements.txt) - Prompt security dependencies
- `services/api_checker/Dockerfile` - API checker service dependencies

Install each dependency set independently:

```bash
pip install -r mcp-scan/requirements.txt
pip install -r agent-scan/requirements.txt
pip install -r AIG-PromptSecurity/requirements.txt

```

Optionally install **uv** for faster Python package management, as recommended in [`mcp-scan/README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/README.md).

## Docker-Based Deployment Workflow

The recommended production deployment uses Docker Compose to orchestrate all services. The [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) defines the main service, API-checker service, and optional UI containers.

Pull pre-built images and start the stack:

```bash
docker pull tencent/ai-infra-guard:latest
docker compose up -d

```

This exposes the web UI on `127.0.0.1:8088` by default.

## Source Build Installation Steps

For development or customization, build from source after installing prerequisites:

1. Clone the repository:
   ```bash
   git clone https://github.com/Tencent/AI-Infra-Guard.git
   cd AI-Infra-Guard
   ```

2. Compile the Go binary:
   ```bash
   go build -o ai-infra-guard ./cmd/cli/main.go
   ```

3. Build frontend assets:
   ```bash
   cd frontend && npm ci && npm run build
   ```

4. Install Python dependencies for all scanners:
   ```bash
   pip install -r mcp-scan/requirements.txt
   pip install -r agent-scan/requirements.txt
   pip install -r AIG-PromptSecurity/requirements.txt
   ```

5. Start the server:
   ```bash
   ./ai-infra-guard webserver --server 0.0.0.0:8088
   ```

## Key Configuration Files

The following source files define the system requirements and build processes:

- `go.mod` - Declares Go 1.20 requirement and module dependencies
- `Dockerfile` - Defines base image and binary compilation steps
- [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) - Orchestrates multi-container deployment
- [`frontend/vite.config.ts`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/vite.config.ts) - Frontend build configuration requiring Node.js 18
- [`mcp-scan/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/requirements.txt) - Python dependencies for MCP scanning
- [`agent-scan/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/requirements.txt) - Python dependencies for agent scanning
- [`AIG-PromptSecurity/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AIG-PromptSecurity/requirements.txt) - Prompt security Python dependencies
- `services/api_checker/Dockerfile` - API checker microservice container definition

## Summary

- **Linux host** is required for native deployment; Docker supports other platforms
- **Docker 20.10+ and Docker Compose v2** orchestrate the containerized stack according to [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml)
- **Go 1.20** builds the core service and CLI tools per `go.mod`
- **Node.js 18 LTS** compiles the TypeScript frontend assets configured in [`frontend/vite.config.ts`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/vite.config.ts)
- **Python 3.8+** runs the scanning modules with isolated [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) files per component
- **2 CPU cores and 4 GB RAM** minimum for the core service, with additional resources for scanning workers

## Frequently Asked Questions

### Can AI-Infra-Guard run on Windows or macOS?

Windows and macOS are only supported through Docker containers. The `Dockerfile` and [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) target Linux base images (Debian/Ubuntu), and all CI/CD pipelines build for Linux architectures. Native compilation on non-Linux platforms is not officially supported.

### What Python package manager should I use for the scanning modules?

Standard `pip` works for all modules using their respective [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) files. However, the `mcp-scan` module documentation recommends `uv` for faster dependency installation and version locking. Both approaches install identical package versions defined in the requirements files.

### How do I verify all system requirements are met before installation?

Check Go version with `go version` (requires 1.20+), Node.js with `node --version` (requires 18.x), and Python with `python3 --version` (requires 3.8+). For Docker, run `docker compose version` to confirm v2.x is installed. The build will fail with explicit errors if any version requirements are not satisfied according to `go.mod` or [`package.json`](https://github.com/Tencent/AI-Infra-Guard/blob/main/package.json) constraints.

### Are the hardware requirements listed per-container or for the entire stack?

The 2 CPU core and 4 GB RAM minimum applies specifically to the core Go service. The complete stack including Python scanning workers and the database requires additional resources proportional to the scanning workload. Production deployments should allocate 8 GB RAM or more for concurrent scanning operations.