AI-Infra-Guard System Requirements: Complete Setup Guide for Linux and Docker

AI-Infra-Guard requires a Linux host with Docker 20.10 or newer, Docker Compose v2, Go 1.20, Node.js 18 LTS, and Python 3.8, with each scanning module maintaining its own requirements.txt for dependency management.

Tencent/AI-Infra-Guard is a multi-language security scanning platform that combines a Go-based core service, Python scanning modules, and a TypeScript frontend. Meeting the system requirements ensures reliable deployment whether you run the platform via Docker containers or build directly from the source code.

Core Infrastructure Prerequisites

Operating System and Container Runtime

The platform targets Linux environments exclusively. According to the Dockerfile in the repository root, all official images build on Debian or Ubuntu base images. While Windows and macOS can host the platform through Docker, native execution is only supported on Linux distributions.

  • Docker 20.10 or any compatible OCI runtime
  • Docker Compose v2.x (the docker-compose.yml uses version 2 syntax)
  • Linux kernel (any recent distribution)

Hardware Specifications

The Go-based core service is lightweight, but Python scanners require additional resources when analyzing large codebases.

  • CPU: 2 cores minimum for the core service
  • RAM: 4 GB minimum for the core service, plus additional memory for UI and scanning workers

Language Runtime Requirements

Go 1.20 or Newer

The core server, CLI binaries, and agent implementations are written in Go. The go.mod file explicitly requires Go 1.20, binding all modules to this version or newer.

go version  # Verify Go 1.20+

go build -o ai-infra-guard ./cmd/cli/main.go

Node.js 18 LTS for Frontend

The web interface located in frontend/ uses Vite and TypeScript. The frontend/vite.config.ts configuration targets Node.js 18 LTS for building production assets.

cd frontend
npm ci
npm run build

Python 3.8 and Module-Specific Dependencies

Python powers the scanning modules including MCP-scan, Agent-scan, and AIG-PromptSecurity. Each module maintains isolated dependency files in its respective directory:

Install each dependency set independently:

pip install -r mcp-scan/requirements.txt
pip install -r agent-scan/requirements.txt
pip install -r AIG-PromptSecurity/requirements.txt

Optionally install uv for faster Python package management, as recommended in mcp-scan/README.md.

Docker-Based Deployment Workflow

The recommended production deployment uses Docker Compose to orchestrate all services. The docker-compose.yml defines the main service, API-checker service, and optional UI containers.

Pull pre-built images and start the stack:

docker pull tencent/ai-infra-guard:latest
docker compose up -d

This exposes the web UI on 127.0.0.1:8088 by default.

Source Build Installation Steps

For development or customization, build from source after installing prerequisites:

  1. Clone the repository:

    git clone https://github.com/Tencent/AI-Infra-Guard.git
    cd AI-Infra-Guard
  2. Compile the Go binary:

    go build -o ai-infra-guard ./cmd/cli/main.go
  3. Build frontend assets:

    cd frontend && npm ci && npm run build
  4. Install Python dependencies for all scanners:

    pip install -r mcp-scan/requirements.txt
    pip install -r agent-scan/requirements.txt
    pip install -r AIG-PromptSecurity/requirements.txt
  5. Start the server:

    ./ai-infra-guard webserver --server 0.0.0.0:8088

Key Configuration Files

The following source files define the system requirements and build processes:

Summary

  • Linux host is required for native deployment; Docker supports other platforms
  • Docker 20.10+ and Docker Compose v2 orchestrate the containerized stack according to docker-compose.yml
  • Go 1.20 builds the core service and CLI tools per go.mod
  • Node.js 18 LTS compiles the TypeScript frontend assets configured in frontend/vite.config.ts
  • Python 3.8+ runs the scanning modules with isolated requirements.txt files per component
  • 2 CPU cores and 4 GB RAM minimum for the core service, with additional resources for scanning workers

Frequently Asked Questions

Can AI-Infra-Guard run on Windows or macOS?

Windows and macOS are only supported through Docker containers. The Dockerfile and docker-compose.yml target Linux base images (Debian/Ubuntu), and all CI/CD pipelines build for Linux architectures. Native compilation on non-Linux platforms is not officially supported.

What Python package manager should I use for the scanning modules?

Standard pip works for all modules using their respective requirements.txt files. However, the mcp-scan module documentation recommends uv for faster dependency installation and version locking. Both approaches install identical package versions defined in the requirements files.

How do I verify all system requirements are met before installation?

Check Go version with go version (requires 1.20+), Node.js with node --version (requires 18.x), and Python with python3 --version (requires 3.8+). For Docker, run docker compose version to confirm v2.x is installed. The build will fail with explicit errors if any version requirements are not satisfied according to go.mod or package.json constraints.

Are the hardware requirements listed per-container or for the entire stack?

The 2 CPU core and 4 GB RAM minimum applies specifically to the core Go service. The complete stack including Python scanning workers and the database requires additional resources proportional to the scanning workload. Production deployments should allocate 8 GB RAM or more for concurrent scanning operations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →