# How to Build the AI-Infra-Guard Binary from Source

> Learn to build the AI-Infra-Guard binary from source using Go 1.22 or later. Follow our clear instructions to compile the CLI entry point and get your AI-Infra-Guard running.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: how-to-guide
- Published: 2026-08-25

---

**To build the AI-Infra-Guard binary, compile the [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) entry point using Go 1.22 or later with the command `go build -o ai-infra-guard ./cmd/cli/main.go`.**

Tencent/AI-Infra-Guard is an open-source security scanner designed for AI infrastructure. The project distributes its core functionality as a command-line binary written in Go, with build instructions distributed throughout the `cmd/cli` package and documented in the repository root. Learning how to build the AI-Infra-Guard binary from source enables custom modifications and deployments in restricted environments.

## Prerequisites for Building AI-Infra-Guard

Before compiling the binary, ensure your environment meets the following requirements:

- **Go 1.22 or later**: The project uses Go modules to manage dependencies, requiring a recent Go toolchain as declared in `go.mod`.
- **Git**: Required only if cloning the repository from GitHub to access the `cmd/cli` source files.

## Source Code Structure

Understanding the repository layout clarifies the build process. The executable logic resides in specific files within the `cmd/cli` directory:

- **[`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go)**: The primary entry point that initializes the command-line interface, web server, and scanning engine.
- **[`cmd/cli/cmd/scan.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/scan.go)**: Implements the `scan` subcommand, orchestrating target analysis when the binary executes scanning operations.
- **[`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go)**: Implements the `webserver` subcommand, launching the HTTP API server.
- **`go.mod`**: Declares the module path and required third-party dependencies.

## Step-by-Step Build Process

### Compile the Binary

To build the AI-Infra-Guard binary for your current operating system and architecture, execute the following from the repository root:

```bash
go build -o ai-infra-guard ./cmd/cli/main.go

```

This command produces an executable named `ai-infra-guard` in the current directory. The `-o` flag specifies the output filename, while [`./cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/./cmd/cli/main.go) points to the entry point that wires together all application components according to the Tencent/AI-Infra-Guard source code.

### Cross-Compile for Different Platforms

Go supports building the AI-Infra-Guard binary for alternate operating systems through environment variables. To compile for Linux AMD64 from macOS or Windows:

```bash
GOOS=linux GOARCH=amd64 go build -o ai-infra-guard-linux-amd64 ./cmd/cli/main.go

```

Replace `linux` and `amd64` with your target platform and architecture (for example, `windows`/`amd64` or `darwin`/`arm64`) to generate platform-specific executables without switching machines.

## Running the Compiled Binary

After building the AI-Infra-Guard binary, verify functionality by launching the web server or running a scan against a target.

Start the web server on localhost port 8088:

```bash
./ai-infra-guard webserver --server 127.0.0.1:8088

```

Execute a basic scan against a local target:

```bash
./ai-infra-guard scan -t http://127.0.0.1:8088

```

These commands leverage the subcommand implementations found in [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go) and [`cmd/cli/cmd/scan.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/scan.go), respectively.

## Summary

- The **AI-Infra-Guard binary** is built from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), which serves as the application entry point wiring together the CLI, web server, and scanning engine.
- **Go 1.22 or later** is required to handle the module dependencies declared in `go.mod`.
- Use **`go build -o ai-infra-guard ./cmd/cli/main.go`** for standard compilation, or set `GOOS` and `GOARCH` for cross-platform builds.
- The resulting executable supports multiple subcommands including `webserver` and `scan` as implemented in the `cmd/cli/cmd/` directory.

## Frequently Asked Questions

### What is the entry point for building the AI-Infra-Guard binary?

The entry point is **[`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go)**. This file initializes the command-line interface and wires together the web server and scanning engine components before delegating to specific subcommand handlers in [`cmd/cli/cmd/scan.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/scan.go) and [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go).

### Can I build the AI-Infra-Guard binary on Windows?

Yes. The Go toolchain supports Windows natively. Run `go build -o ai-infra-guard.exe ./cmd/cli/main.go` from the repository root on Windows to produce an executable. For Linux targets, use cross-compilation with `GOOS=linux` and `GOARCH=amd64`.

### What Go version is required to compile AI-Infra-Guard?

You need **Go 1.22 or later**. The project utilizes Go modules defined in `go.mod`, and the codebase assumes a modern Go runtime. Earlier versions may fail to compile due to dependency requirements or language features used in [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go).

### How do I run the binary after building it?

Execute `./ai-infra-guard` (or `ai-infra-guard.exe` on Windows) followed by a subcommand. For example, `./ai-infra-guard webserver --server 127.0.0.1:8088` starts the API server, while `./ai-infra-guard scan -t <target>` runs a security scan against the specified target URL.