# How to Configure AI-Infra-Guard for Your AI Environment: A Complete Setup Guide

> Configure AI-Infra-Guard easily for your AI environment. Follow our complete setup guide to secure your infrastructure with essential environment variables for seamless operation.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: how-to-guide
- Published: 2026-08-26

---

**Configure AI-Infra-Guard by setting the `AIG_BASE_URL` environment variable to your server address (default `http://localhost:8088`), optionally disable external lookups with `AIG_CLOUD_LOOKUP=off` for air-gapped operation, and point the optional Agent to the control plane via `AIG_SERVER` for distributed scanning.**

AI-Infra-Guard (A.I.G) from Tencent is a security scanning platform composed of a Go-based backend web service, an optional Agent process, and Python-based scanning tools. To integrate the platform with your own AI services—whether local LLM endpoints, MCP servers, or custom skill repositories—you must configure three critical environment variables that control connectivity, outbound policy, and agent registration.

## Core Configuration Variables

AI-Infra-Guard relies on environment variables to define how components communicate. These settings determine where scans are sent, whether external lookups are permitted, and how distributed agents connect to the control plane.

### Web Service URL (AIG_BASE_URL)

The **AIG_BASE_URL** variable specifies the base URL of the running A.I.G server, typically `http://127.0.0.1:8088` when running locally. All skills and external tools read this variable to send task-creation requests to the server.

If omitted, skills will fail with the error *"configure the A.I.G service address first"* as documented in [`skills/aig-scanner/SKILL.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/skills/aig-scanner/SKILL.md). Set this in your shell or within the Docker Compose environment section according to the Tencent/AI-Infra-Guard source code.

### Outbound Policy (AIG_CLOUD_LOOKUP)

The **AIG_CLOUD_LOOKUP** variable controls whether the server contacts Tencent's cloud APIs for CVE and supply-chain lookups. Set to `off` (or `0`/`false`) to perform a **purely local scan** that sends no metadata outside the host. This is mandatory for air-gapped or high-security environments.

As implemented in [`skills/edgeone-clawscan/SKILL.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/skills/edgeone-clawscan/SKILL.md) (lines 70-102), this flag disables all calls to external lookup endpoints.

### Agent Configuration (AIG_SERVER)

The optional **AIG_SERVER** variable points the Agent binary to the web service, typically `webserver:8088` when using Docker networking. The Agent registers itself with the server and executes distributed scans including MCP and skill-based assessments. This is pre-configured in the `agent` service of [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml).

## Step-by-Step Configuration

Follow this deployment flow to configure AI-Infra-Guard for your specific AI environment.

### 1. Start the Platform

Launch the services using either pre-built images or local builds. The server listens on port **8088** by default.

```bash

# Using pre-built images

docker compose -f docker-compose.images.yml up -d

# Or build locally

docker compose up -d

```

### 2. Configure Client Environment

Export the base URL and optional offline settings for all client tools:

```bash
export AIG_BASE_URL=http://localhost:8088
export AIG_CLOUD_LOOKUP=off  # Optional: disables external lookups

```

Reference the Quick Start section in [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) (lines 125-132) for additional context.

### 3. Run Security Scans

Execute scans against your AI infrastructure using the CLI or Python wrappers. Both tools automatically pull the base URL from `AIG_BASE_URL`.

**AI Infrastructure Scan:**

```bash
./ai-infra-guard scan -t http://127.0.0.1:8000

```

**Skill Scan (Python):**

```bash
pip install aig-skill-scan
export LLM_API_KEY="your-key"
aig-skill-scan --repo /path/to/skill -m deepseek-v4-flash -o result.json

```

### 4. Verify Connectivity

Open the Swagger UI at `http://localhost:8088/docs/index.html` to inspect exposed APIs and confirm the server is reachable.

## Configuration Examples

### Docker Compose Environment

Inject configuration directly into containers via [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml):

```yaml
services:
  webserver:
    build:
      context: .
      dockerfile: Dockerfile
    ports:
      - "8088:8088"
    environment:
      - APP_ENV=production
      - AIG_BASE_URL=http://localhost:8088
      - AIG_CLOUD_LOOKUP=off

```

### Go Client SDK

For programmatic access using the generated SDK in `pkg/client/`:

```go
package main

import (
    "context"
    "log"
    aig "github.com/Tencent/AI-Infra-Guard/pkg/client"
)

func main() {
    cfg := aig.NewConfiguration()
    cfg.BasePath = "http://localhost:8088"
    client := aig.NewAPIClient(cfg)

    req := client.TaskApi.CreateInfraTask(context.Background())
    req = req.Body(aig.InfraTaskRequest{
        Target: "http://127.0.0.1:8000",
    })
    resp, _, err := req.Execute()
    if err != nil {
        log.Fatalf("task creation failed: %v", err)
    }
    log.Printf("task ID: %s", resp.TaskId)
}

```

## Summary

- **AIG_BASE_URL** is required for all client operations, pointing to the server at `http://localhost:8088` by default.
- **AIG_CLOUD_LOOKUP=off** enables air-gapped operation by disabling external CVE and supply-chain lookups as implemented in the Tencent/AI-Infra-Guard source code.
- **AIG_SERVER** connects the optional Agent to the control plane for distributed scanning.
- Configuration can be set via shell exports, Docker Compose environment blocks, or programmatically in Go clients.
- Verify setup using the Swagger UI at [`/docs/index.html`](https://github.com/Tencent/AI-Infra-Guard/blob/main//docs/index.html) or by running test scans against your AI endpoints.

## Frequently Asked Questions

### How do I run AI-Infra-Guard in an air-gapped environment?

Set `AIG_CLOUD_LOOKUP=off` before starting any scans. This disables all calls to Tencent's cloud lookup endpoints as detailed in [`skills/edgeone-clawscan/SKILL.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/skills/edgeone-clawscan/SKILL.md), ensuring the platform performs purely local scans without transmitting metadata outside the host.

### What happens if I don't set AIG_BASE_URL?

Skills and scan tools will fail with the error *"configure the A.I.G service address first"*. The [`skills/aig-scanner/SKILL.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/skills/aig-scanner/SKILL.md) file explicitly documents this requirement, as all Python-based scanning tools and CLI commands use this variable to locate the task creation API.

### Can I configure AI-Infra-Guard without using environment variables?

While environment variables are the primary configuration method, you can also set values directly in [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) under the `environment:` blocks of the `webserver` and `agent` services. For programmatic use, configure the Go SDK client directly by setting `cfg.BasePath` as shown in the client examples in `pkg/client/`.

### Where is the main entry point for the CLI commands?

The Go-based CLI entry point is located in [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go). This file handles commands such as `scan` and `webserver`, and respects the `AIG_BASE_URL` and `AIG_CLOUD_LOOKUP` environment variables when executing operations.