How to Start the AI-Infra-Guard Web Server: Build, Run, and Deploy

TLDR: Compile the Go binary from cmd/cli/main.go and execute the webserver sub‑command with the --server flag (default 127.0.0.1:8088) to launch the HTTP service, or use docker-compose -f docker-compose.images.yml up -d for a containerized deployment.

Tencent/AI-Infra-Guard (A.I.G) is an open‑source security scanner for AI infrastructure that exposes its detection capabilities through a modern web interface and REST API. To start the AI-Infra-Guard web server, you must either build the Go application locally or run the pre‑built Docker images. This guide details the exact source files, command flags, and deployment options based on the repository’s architecture.

Build the Binary from Source

The application entry point is located at cmd/cli/main.go, which initializes the Cobra command framework and registers all sub‑commands. Before you can start the web server, you need to compile this entry point into an executable binary.

Prerequisites

  • Go 1.21 or newer installed on your system
  • Git to clone the repository

Compilation Steps

Run the following commands from your terminal:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
go build -o ai-infra-guard ./cmd/cli/main.go

This produces a single binary named ai-infra-guard in the current directory. The build process parses dependencies from go.mod and compiles the command router defined in cmd/cli/main.go.

Launch the Web Server

The server logic is implemented in cmd/cli/cmd/webserver.go. This file defines the webserver sub‑command, parses the --server flag, and initializes the WebSocket‑driven HTTP handlers.

Basic Startup

To start the server on the default address 127.0.0.1:8088:

./ai-infra-guard webserver --server 127.0.0.1:8088

The service will bind to localhost port 8088 and serve both the React‑based UI and the REST API endpoints.

Custom Binding

To expose the service on all network interfaces or use a different port, override the flag:

./ai-infra-guard webserver --server 0.0.0.0:9090

This configuration is useful when running inside Docker containers or on remote hosts where you need external access.

Docker Deployment Methods

For production environments or isolated testing, the repository provides two Docker Compose configurations that eliminate the need for a local Go toolchain.

Pre‑built Images (Fastest)

Use docker-compose.images.yml to pull the latest official images from the registry and start the stack immediately:

docker-compose -f docker-compose.images.yml up -d

This command downloads the backend and optional frontend containers, maps port 8088, and runs the web server in detached mode.

Build from Source

To compile the binary inside a container using the repository’s Dockerfile, run the default compose file:

docker-compose up -d

This reads docker-compose.yml, builds the image locally from the current source tree, and starts the service. Any local changes to cmd/cli/cmd/webserver.go or other source files will be reflected in the container.

Verify the Running Service

Once the process starts, open http://localhost:8088 (or your custom address) in a browser to access the scanning dashboard. The interactive API documentation is served at http://localhost:8088/docs/index.html, which renders the specification defined in docs/api.md.

Summary

  • The AI-Infra-Guard web server is started via the webserver sub‑command implemented in cmd/cli/cmd/webserver.go
  • The default listening address is 127.0.0.1:8088, configurable with the --server flag
  • Build the binary from cmd/cli/main.go using go build -o ai-infra-guard ./cmd/cli/main.go
  • Docker deployments can use pre‑built images via docker-compose.images.yml or build from source with docker-compose.yml
  • The service hosts a WebSocket‑enabled HTTP server that powers both the web UI and REST API

Frequently Asked Questions

What port does AI-Infra-Guard use by default?

The default listening address is 127.0.0.1:8088. You can override this by passing the --server flag when executing the webserver command, or by modifying the port mappings in your Docker Compose file.

Can I run AI-Infra-Guard without installing Go?

Yes. Use the Docker Compose workflow with docker-compose.images.yml to download and run pre‑built containers. This approach requires only Docker and Docker Compose, eliminating the need for a local Go toolchain or compilation steps.

Where is the webserver command defined in the source code?

The webserver sub‑command is registered in cmd/cli/main.go as part of the Cobra command tree, and the implementation logic resides in cmd/cli/cmd/webserver.go. This file handles flag parsing, address binding, and HTTP server initialization.

How do I access the API documentation once the server is running?

Navigate to http://localhost:8088/docs/index.html (replace the host and port with your custom --server value if applicable). This endpoint serves the Swagger UI, which documents all endpoints specified in docs/api.md at the repository root.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →