Best Practices for Deploying AI-Infra-Guard: A Complete Production Guide

Deploy AI-Infra-Guard using the official Docker Compose configuration with pre-built images, secure the web UI behind a reverse proxy with authentication, and mount the data/ volume separately to enable rule updates without rebuilding containers.

AI-Infra-Guard (A.I.G) is a hybrid Go-Python platform developed by Tencent for securing AI infrastructure through automated scanning and vulnerability detection. The system runs as a set of Docker containers exposing both a web interface and a REST API, making deployment straightforward but requiring attention to architecture, security, and operational hygiene. Following these best practices ensures a reliable, scalable, and secure production deployment.

Understand the AI-Infra-Guard Architecture

Before deploying, understand the three-tier architecture to make informed decisions about resource allocation and networking.

Core Components

The platform consists of distinct modules that communicate via WebSocket connections between containers:

  • Go Core (cmd/cli, cmd/agent, internal/...): Handles the web service, task scheduling, and CLI entry-points. This is the control plane of the application.
  • Python Modules (agent-scan, mcp-scan, AIG-PromptSecurity): Specialized scan engines that perform the actual security analysis on AI agents, MCP servers, and prompt security validation.
  • Data Directory (data/*): Contains fingerprint and vulnerability rule sets. According to the source code in CODEBUDDY.md lines 84-86, all containers share this volume, allowing rule updates without image rebuilds.

The platform is deliberately stateless except for the data/ volume, which simplifies scaling and backup strategies.

Choose Your Deployment Mode

AI-Infra-Guard supports three deployment methods depending on your environment constraints and customization needs.

One-Click Installation Script

For fresh environments requiring minimal manual steps, use the official installation script referenced in README.md lines 134-138:

curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bash

This script handles Docker installation, image pulling, and initial configuration automatically.

Docker Compose with Pre-Built Images

For production or CI environments where Docker is already installed, use the pre-built images configuration as documented in README.md lines 99-110:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker compose -f docker-compose.images.yml up -d

This method deploys two images: the A.I.G server and the agent runtime, without requiring local builds.

Build from Source

When you need custom image tweaks or offline builds, build locally as shown in README.md lines 140-146:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker compose up -d   # Builds local images from Dockerfile

Ensure you have Docker 20.10+ and at least 4 GiB RAM available before building.

Secure the Deployment

Security misconfigurations are the primary risk in production deployments. The following measures are derived from SECURITY.md recommendations.

Network Isolation and Access Control

Run AI-Infra-Guard on a dedicated host or isolated network segment. By default, the UI binds to 127.0.0.1:8088 only, as implemented in SECURITY.md lines 60-66. Exposing this port publicly without additional protection constitutes an operator misconfiguration.

Authentication and Transport Security

If you must expose the UI beyond localhost, place it behind a reverse proxy with TLS termination and basic authentication:


# /etc/nginx/conf.d/aig.conf

server {
    listen 443 ssl;
    server_name aig.mycorp.local;
    ssl_certificate /etc/ssl/certs/aig.crt;
    ssl_certificate_key /etc/ssl/private/aig.key;

    location / {
        proxy_pass http://127.0.0.1:8088;
        auth_basic "A.I.G Access";
        auth_basic_user_file /etc/nginx/.htpasswd;
    }
}

Runtime Security

Never mount the host Docker socket into containers unless absolutely necessary. Run containers with the least privileges using the --user flag. Additionally, verify that logs do not contain API keys—while A.I.G masks secrets automatically, audit your logging configuration as noted in SECURITY.md lines 100-102.

Maintain Rule Sets and Data

The data/ directory contains versioned fingerprint databases that require regular updates.

Updating Fingerprints

Within the web UI, click "Update data" to fetch the latest vulnerability rules without container redeployment, as documented in README.md lines 194-205. This works because the data/ directory is mounted as a shared volume across all containers.

Air-Gapped Environments

For offline deployments, manually synchronize the data directory:


# On a machine with internet access

git clone https://github.com/Tencent/AI-Infra-Guard.git
scp -r AI-Infra-Guard/data <offline-host>:/opt/aig/data

# On the offline host

docker compose restart

Integrate into CI/CD Pipelines

AI-Infra-Guard functions as a security gate when integrated into build pipelines. The REST API is documented at http://localhost:8088/docs/index.html per api.md lines 40-42.

Example GitHub Actions integration:

- name: Run A.I.G scan
  run: |
    curl -X POST http://localhost:8088/api/v1/tasks \
         -H 'Content-Type: application/json' \
         -d '{"type":"mcp_scan","target":"http://localhost:8088"}'

Use this endpoint to abort releases when scans detect critical vulnerabilities in MCP servers or AI agents.

Resource Planning and Monitoring

Proper resource allocation prevents scan failures and system instability.

Minimum Requirements

Allocate at least 4 GiB RAM and 10 GiB disk space per the resource table in README.md lines 101-104. Python-based scan engines are memory-intensive when processing large AI models or extensive codebases.

Health Checks and Logging

Implement Docker health checks or simple HTTP probes:

curl http://localhost:8088/health

Forward container logs to a central logging system (such as ELK or Loki) to maintain audit trails of all security scans and API access. Configure automatic container restarts for unhealthy states.

Summary

  • Use the pre-built Docker Compose (docker-compose.images.yml) for production deployments to avoid build complexity.
  • Secure the default localhost binding (127.0.0.1:8088) with reverse proxy authentication and TLS if exposing externally.
  • Mount the data/ volume separately to update vulnerability fingerprints without rebuilding images or restarting services.
  • Allocate sufficient resources: minimum 4 GiB RAM and Docker 20.10+ to support the hybrid Go-Python runtime.
  • Integrate via REST API into CI/CD pipelines to automate security scanning of AI infrastructure components.

Frequently Asked Questions

What are the minimum system requirements for AI-Infra-Guard?

AI-Infra-Guard requires Docker version 20.10 or higher, at least 4 GiB of RAM, and approximately 10 GiB of available disk space. These specifications accommodate both the Go-based web service and the Python scan engines that perform intensive security analysis.

How do I update vulnerability rules without redeploying?

Because all containers share the data/ volume mount, you can update fingerprints by clicking "Update data" in the web UI or by replacing the contents of the mounted data/ directory on the host filesystem. This design, referenced in CODEBUDDY.md, allows rule updates without container restarts or image rebuilds.

Is it safe to expose the AI-Infra-Guard UI to the internet?

No, exposing the default UI directly is considered a misconfiguration per SECURITY.md lines 60-66. The service binds to 127.0.0.1:8088 by default specifically to prevent unauthorized access. If remote access is required, always place the service behind a reverse proxy (such as Nginx) with TLS encryption and strong authentication.

How do I integrate AI-Infra-Guard into my CI/CD pipeline?

Use the REST API endpoint POST /api/v1/tasks documented in api.md lines 40-42. Your pipeline can trigger scans immediately after building AI agents or MCP servers, using the API response to determine whether to proceed with deployment or fail the build based on detected vulnerabilities.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →