How to Update AI-Infra-Guard to the Latest Version: Step-by-Step Upgrade Guide
Update AI-Infra-Guard by pulling the latest source code from the Tencent repository, rebuilding Docker images via docker-compose.images.yml, and restarting the web-server and agent containers to deploy the newest security definitions.
AI-Infra-Guard is distributed as open-source code and pre-built Docker images, requiring periodic updates to maintain detection accuracy for AI infrastructure vulnerabilities. The upgrade process is documented in the project's Getting Started guides and follows a Docker-centric workflow. Whether you are upgrading an existing installation or deploying a fresh instance, the same commands apply to synchronize your environment with the latest upstream changes.
Prerequisites for Updating AI-Infra-Guard
Before initiating the update, ensure your environment meets the following requirements:
- Docker Engine and Docker Compose installed on your host system
- Network access to GitHub and Docker Hub to fetch the latest artifacts
- Administrative privileges to execute Docker commands and restart services
Step-by-Step Guide to Update AI-Infra-Guard
The official upgrade workflow consists of three phases: synchronizing source code, rebuilding container images, and optionally pruning obsolete resources.
1. Pull the Latest Repository
First, synchronize your local copy with the upstream Tencent/AI-Infra-Guard repository. For new installations, clone the repository. For existing deployments, fetch the latest commits.
# Fresh installation
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
# OR update existing installation
git pull origin main
2. Rebuild Docker Images and Restart Services
Execute the Docker Compose command specified in the project documentation to build and launch the updated containers. According to the source code documentation in frontend/public/aigdocs/docs/getting-started_en.md (lines 89-96), use the docker-compose.images.yml file specifically for production deployments.
# Rebuild and restart all services
docker-compose -f docker-compose.images.yml up -d --build
This command pulls the newest base images from Docker Hub, rebuilds local layers if the Dockerfile has changed, and restarts both the web-server and agent containers with zero-downtime deployment via the -d (detached) flag.
3. Clean Up Obsolete Resources (Optional)
After successfully updating, remove dangling images to reclaim disk space.
# Remove unused Docker images
docker image prune -f
Where Upgrade Instructions Are Documented
The update procedures are formally specified in multiple locations within the repository:
frontend/public/aigdocs/docs/getting-started_en.md(lines 89-96): Contains the canonical upgrade steps for web-facing documentationcommon/websocket/static/aigdocs/docs/getting-started_en.md: Mirrors the Getting Started guide for websocket static assetsREADME.md: Provides repository overview and quick-start referencesdocker-compose.images.yml: Defines the production-grade container orchestration used during updatesdocker-compose.yml: Primary compose file intended for local development and testing environments
Understanding the Docker Compose Files
When updating AI-Infra-Guard, it is critical to use the correct compose file for your use case:
docker-compose.images.yml: Use this file for production updates. It references pre-built images from Docker Hub and handles the web-server and agent container orchestration.
docker-compose.yml: Reserved for local development workflows. This file typically mounts source volumes and builds from local Dockerfiles rather than pulling remote images.
Verifying the Update
After running the upgrade commands, verify the deployment by checking container status:
docker-compose -f docker-compose.images.yml ps
Look for containers in the "Up" state and review the web interface to confirm the version reflects the latest commit hash or release tag.
Summary
- Fetch latest code: Use
git pullinside your existing AI-Infra-Guard directory or clone fresh fromhttps://github.com/Tencent/AI-Infra-Guard.git - Rebuild services: Execute
docker-compose -f docker-compose.images.yml up -d --buildto compile and deploy the newest Docker images - Documentation reference: Official upgrade steps are located at lines 89-96 of
frontend/public/aigdocs/docs/getting-started_en.md - Resource cleanup: Run
docker image prune -fto eliminate outdated image layers after successful deployment
Frequently Asked Questions
What is the difference between docker-compose.yml and docker-compose.images.yml?
The docker-compose.yml file configures the environment for local development, mounting source directories and building containers from local Dockerfiles. The docker-compose.images.yml file is optimized for production updates, referencing pre-built images from Docker Hub and orchestrating the web-server and agent services. Always use docker-compose.images.yml when updating AI-Infra-Guard in production environments.
Do I need to stop running containers before updating?
No. The docker-compose -f docker-compose.images.yml up -d --build command automatically recreates containers with updated images while maintaining service continuity. The --build flag ensures any Dockerfile changes are compiled, and the -d flag runs containers in detached mode.
How can I verify that AI-Infra-Guard updated successfully?
Check running container status using docker-compose -f docker-compose.images.yml ps to confirm all services are active. Additionally, examine the web interface footer or about page, which typically displays the current build version or Git commit hash corresponding to the latest pull.
Is it necessary to prune Docker images after every update?
While not mandatory, running docker image prune -f is recommended housekeeping. Each update may leave behind outdated image layers consuming disk space. This command removes dangling images (those untagged and unreferenced by running containers) without affecting active AI-Infra-Guard services.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →