How to Configure AI-Infra-Guard for Your AI Environment: A Complete Setup Guide
Configure AI-Infra-Guard by setting the AIG_BASE_URL environment variable to your server address (default http://localhost:8088), optionally disable external lookups with AIG_CLOUD_LOOKUP=off for air-gapped operation, and point the optional Agent to the control plane via AIG_SERVER for distributed scanning.
AI-Infra-Guard (A.I.G) from Tencent is a security scanning platform composed of a Go-based backend web service, an optional Agent process, and Python-based scanning tools. To integrate the platform with your own AI services—whether local LLM endpoints, MCP servers, or custom skill repositories—you must configure three critical environment variables that control connectivity, outbound policy, and agent registration.
Core Configuration Variables
AI-Infra-Guard relies on environment variables to define how components communicate. These settings determine where scans are sent, whether external lookups are permitted, and how distributed agents connect to the control plane.
Web Service URL (AIG_BASE_URL)
The AIG_BASE_URL variable specifies the base URL of the running A.I.G server, typically http://127.0.0.1:8088 when running locally. All skills and external tools read this variable to send task-creation requests to the server.
If omitted, skills will fail with the error "configure the A.I.G service address first" as documented in skills/aig-scanner/SKILL.md. Set this in your shell or within the Docker Compose environment section according to the Tencent/AI-Infra-Guard source code.
Outbound Policy (AIG_CLOUD_LOOKUP)
The AIG_CLOUD_LOOKUP variable controls whether the server contacts Tencent's cloud APIs for CVE and supply-chain lookups. Set to off (or 0/false) to perform a purely local scan that sends no metadata outside the host. This is mandatory for air-gapped or high-security environments.
As implemented in skills/edgeone-clawscan/SKILL.md (lines 70-102), this flag disables all calls to external lookup endpoints.
Agent Configuration (AIG_SERVER)
The optional AIG_SERVER variable points the Agent binary to the web service, typically webserver:8088 when using Docker networking. The Agent registers itself with the server and executes distributed scans including MCP and skill-based assessments. This is pre-configured in the agent service of docker-compose.yml.
Step-by-Step Configuration
Follow this deployment flow to configure AI-Infra-Guard for your specific AI environment.
1. Start the Platform
Launch the services using either pre-built images or local builds. The server listens on port 8088 by default.
# Using pre-built images
docker compose -f docker-compose.images.yml up -d
# Or build locally
docker compose up -d
2. Configure Client Environment
Export the base URL and optional offline settings for all client tools:
export AIG_BASE_URL=http://localhost:8088
export AIG_CLOUD_LOOKUP=off # Optional: disables external lookups
Reference the Quick Start section in README.md (lines 125-132) for additional context.
3. Run Security Scans
Execute scans against your AI infrastructure using the CLI or Python wrappers. Both tools automatically pull the base URL from AIG_BASE_URL.
AI Infrastructure Scan:
./ai-infra-guard scan -t http://127.0.0.1:8000
Skill Scan (Python):
pip install aig-skill-scan
export LLM_API_KEY="your-key"
aig-skill-scan --repo /path/to/skill -m deepseek-v4-flash -o result.json
4. Verify Connectivity
Open the Swagger UI at http://localhost:8088/docs/index.html to inspect exposed APIs and confirm the server is reachable.
Configuration Examples
Docker Compose Environment
Inject configuration directly into containers via docker-compose.yml:
services:
webserver:
build:
context: .
dockerfile: Dockerfile
ports:
- "8088:8088"
environment:
- APP_ENV=production
- AIG_BASE_URL=http://localhost:8088
- AIG_CLOUD_LOOKUP=off
Go Client SDK
For programmatic access using the generated SDK in pkg/client/:
package main
import (
"context"
"log"
aig "github.com/Tencent/AI-Infra-Guard/pkg/client"
)
func main() {
cfg := aig.NewConfiguration()
cfg.BasePath = "http://localhost:8088"
client := aig.NewAPIClient(cfg)
req := client.TaskApi.CreateInfraTask(context.Background())
req = req.Body(aig.InfraTaskRequest{
Target: "http://127.0.0.1:8000",
})
resp, _, err := req.Execute()
if err != nil {
log.Fatalf("task creation failed: %v", err)
}
log.Printf("task ID: %s", resp.TaskId)
}
Summary
- AIG_BASE_URL is required for all client operations, pointing to the server at
http://localhost:8088by default. - AIG_CLOUD_LOOKUP=off enables air-gapped operation by disabling external CVE and supply-chain lookups as implemented in the Tencent/AI-Infra-Guard source code.
- AIG_SERVER connects the optional Agent to the control plane for distributed scanning.
- Configuration can be set via shell exports, Docker Compose environment blocks, or programmatically in Go clients.
- Verify setup using the Swagger UI at
/docs/index.htmlor by running test scans against your AI endpoints.
Frequently Asked Questions
How do I run AI-Infra-Guard in an air-gapped environment?
Set AIG_CLOUD_LOOKUP=off before starting any scans. This disables all calls to Tencent's cloud lookup endpoints as detailed in skills/edgeone-clawscan/SKILL.md, ensuring the platform performs purely local scans without transmitting metadata outside the host.
What happens if I don't set AIG_BASE_URL?
Skills and scan tools will fail with the error "configure the A.I.G service address first". The skills/aig-scanner/SKILL.md file explicitly documents this requirement, as all Python-based scanning tools and CLI commands use this variable to locate the task creation API.
Can I configure AI-Infra-Guard without using environment variables?
While environment variables are the primary configuration method, you can also set values directly in docker-compose.yml under the environment: blocks of the webserver and agent services. For programmatic use, configure the Go SDK client directly by setting cfg.BasePath as shown in the client examples in pkg/client/.
Where is the main entry point for the CLI commands?
The Go-based CLI entry point is located in cmd/cli/main.go. This file handles commands such as scan and webserver, and respects the AIG_BASE_URL and AIG_CLOUD_LOOKUP environment variables when executing operations.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →