# Best Practices for Deploying AI-Infra-Guard: A Complete Production Guide

> Deploy AI-Infra-Guard with Docker Compose. Secure its UI with a reverse proxy and authentication. Update rules easily by mounting the data volume separately for a robust production setup.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: best-practices
- Published: 2026-08-26

---

**Deploy AI-Infra-Guard using the official Docker Compose configuration with pre-built images, secure the web UI behind a reverse proxy with authentication, and mount the `data/` volume separately to enable rule updates without rebuilding containers.**

AI-Infra-Guard (A.I.G) is a hybrid Go-Python platform developed by Tencent for securing AI infrastructure through automated scanning and vulnerability detection. The system runs as a set of Docker containers exposing both a web interface and a REST API, making deployment straightforward but requiring attention to architecture, security, and operational hygiene. Following these best practices ensures a reliable, scalable, and secure production deployment.

## Understand the AI-Infra-Guard Architecture

Before deploying, understand the three-tier architecture to make informed decisions about resource allocation and networking.

### Core Components

The platform consists of distinct modules that communicate via **WebSocket** connections between containers:

- **Go Core** (`cmd/cli`, `cmd/agent`, `internal/...`): Handles the web service, task scheduling, and CLI entry-points. This is the control plane of the application.
- **Python Modules** (`agent-scan`, `mcp-scan`, `AIG-PromptSecurity`): Specialized scan engines that perform the actual security analysis on AI agents, MCP servers, and prompt security validation.
- **Data Directory** (`data/*`): Contains fingerprint and vulnerability rule sets. According to the source code in [`CODEBUDDY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/CODEBUDDY.md) lines 84-86, all containers share this volume, allowing rule updates without image rebuilds.

The platform is deliberately **stateless** except for the `data/` volume, which simplifies scaling and backup strategies.

## Choose Your Deployment Mode

AI-Infra-Guard supports three deployment methods depending on your environment constraints and customization needs.

### One-Click Installation Script

For fresh environments requiring minimal manual steps, use the official installation script referenced in [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) lines 134-138:

```bash
curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bash

```

This script handles Docker installation, image pulling, and initial configuration automatically.

### Docker Compose with Pre-Built Images

For production or CI environments where Docker is already installed, use the pre-built images configuration as documented in [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) lines 99-110:

```bash
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker compose -f docker-compose.images.yml up -d

```

This method deploys two images: the **A.I.G server** and the **agent runtime**, without requiring local builds.

### Build from Source

When you need custom image tweaks or offline builds, build locally as shown in [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) lines 140-146:

```bash
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker compose up -d   # Builds local images from Dockerfile

```

Ensure you have **Docker 20.10+** and at least **4 GiB RAM** available before building.

## Secure the Deployment

Security misconfigurations are the primary risk in production deployments. The following measures are derived from [`SECURITY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/SECURITY.md) recommendations.

### Network Isolation and Access Control

Run AI-Infra-Guard on a dedicated host or isolated network segment. By default, the UI binds to `127.0.0.1:8088` only, as implemented in [`SECURITY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/SECURITY.md) lines 60-66. Exposing this port publicly without additional protection constitutes an operator misconfiguration.

### Authentication and Transport Security

If you must expose the UI beyond localhost, place it behind a reverse proxy with TLS termination and basic authentication:

```nginx

# /etc/nginx/conf.d/aig.conf

server {
    listen 443 ssl;
    server_name aig.mycorp.local;
    ssl_certificate /etc/ssl/certs/aig.crt;
    ssl_certificate_key /etc/ssl/private/aig.key;

    location / {
        proxy_pass http://127.0.0.1:8088;
        auth_basic "A.I.G Access";
        auth_basic_user_file /etc/nginx/.htpasswd;
    }
}

```

### Runtime Security

Never mount the host Docker socket into containers unless absolutely necessary. Run containers with the least privileges using the `--user` flag. Additionally, verify that logs do not contain API keys—while A.I.G masks secrets automatically, audit your logging configuration as noted in [`SECURITY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/SECURITY.md) lines 100-102.

## Maintain Rule Sets and Data

The `data/` directory contains versioned fingerprint databases that require regular updates.

### Updating Fingerprints

Within the web UI, click **"Update data"** to fetch the latest vulnerability rules without container redeployment, as documented in [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) lines 194-205. This works because the `data/` directory is mounted as a shared volume across all containers.

### Air-Gapped Environments

For offline deployments, manually synchronize the data directory:

```bash

# On a machine with internet access

git clone https://github.com/Tencent/AI-Infra-Guard.git
scp -r AI-Infra-Guard/data <offline-host>:/opt/aig/data

# On the offline host

docker compose restart

```

## Integrate into CI/CD Pipelines

AI-Infra-Guard functions as a security gate when integrated into build pipelines. The REST API is documented at `http://localhost:8088/docs/index.html` per [`api.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/api.md) lines 40-42.

Example GitHub Actions integration:

```yaml
- name: Run A.I.G scan
  run: |
    curl -X POST http://localhost:8088/api/v1/tasks \
         -H 'Content-Type: application/json' \
         -d '{"type":"mcp_scan","target":"http://localhost:8088"}'

```

Use this endpoint to abort releases when scans detect critical vulnerabilities in MCP servers or AI agents.

## Resource Planning and Monitoring

Proper resource allocation prevents scan failures and system instability.

### Minimum Requirements

Allocate at least **4 GiB RAM** and **10 GiB disk space** per the resource table in [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) lines 101-104. Python-based scan engines are memory-intensive when processing large AI models or extensive codebases.

### Health Checks and Logging

Implement Docker health checks or simple HTTP probes:

```bash
curl http://localhost:8088/health

```

Forward container logs to a central logging system (such as ELK or Loki) to maintain audit trails of all security scans and API access. Configure automatic container restarts for unhealthy states.

## Summary

- **Use the pre-built Docker Compose** ([`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml)) for production deployments to avoid build complexity.
- **Secure the default localhost binding** (`127.0.0.1:8088`) with reverse proxy authentication and TLS if exposing externally.
- **Mount the `data/` volume separately** to update vulnerability fingerprints without rebuilding images or restarting services.
- **Allocate sufficient resources**: minimum 4 GiB RAM and Docker 20.10+ to support the hybrid Go-Python runtime.
- **Integrate via REST API** into CI/CD pipelines to automate security scanning of AI infrastructure components.

## Frequently Asked Questions

### What are the minimum system requirements for AI-Infra-Guard?

AI-Infra-Guard requires Docker version 20.10 or higher, at least 4 GiB of RAM, and approximately 10 GiB of available disk space. These specifications accommodate both the Go-based web service and the Python scan engines that perform intensive security analysis.

### How do I update vulnerability rules without redeploying?

Because all containers share the `data/` volume mount, you can update fingerprints by clicking **"Update data"** in the web UI or by replacing the contents of the mounted `data/` directory on the host filesystem. This design, referenced in [`CODEBUDDY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/CODEBUDDY.md), allows rule updates without container restarts or image rebuilds.

### Is it safe to expose the AI-Infra-Guard UI to the internet?

No, exposing the default UI directly is considered a misconfiguration per [`SECURITY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/SECURITY.md) lines 60-66. The service binds to `127.0.0.1:8088` by default specifically to prevent unauthorized access. If remote access is required, always place the service behind a reverse proxy (such as Nginx) with TLS encryption and strong authentication.

### How do I integrate AI-Infra-Guard into my CI/CD pipeline?

Use the REST API endpoint `POST /api/v1/tasks` documented in [`api.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/api.md) lines 40-42. Your pipeline can trigger scans immediately after building AI agents or MCP servers, using the API response to determine whether to proceed with deployment or fail the build based on detected vulnerabilities.