# Supported Deployment Environments for AI-Infra-Guard: Docker, Binary, and Air-Gapped Options

> Explore AI-Infra-Guard deployment environments: Docker Compose for portability, native binaries for direct execution, and air-gapped options for offline networks. Deploy with flexibility.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: how-to-guide
- Published: 2026-08-23

---

**AI-Infra-Guard supports three primary deployment environments: containerized Docker-Compose stacks for cross-platform portability, native Go binaries for direct host execution, and offline/air-gapped configurations for isolated networks.**

AI-Infra-Guard, Tencent's open-source AI infrastructure security scanner, offers flexible deployment options to accommodate diverse operational constraints. Whether you require rapid containerized testing, bare-metal performance, or completely offline operation, the project provides documented pathways for each scenario.

## Docker-Compose Deployment (One-Click)

### Cross-Platform Container Support

The project distributes pre-built images `zhuquelab/aig-server` and `zhuquelab/aig-agent` via Docker Hub. According to the [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md), these containers abstract the underlying operating system, enabling deployment on **Linux, macOS, and Windows** without environment-specific configuration. The [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) and [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) files orchestrate both services with a single command, making this the fastest path to a running instance.

### Automated Setup with docker.sh

For rapid initialization, the repository includes a convenience script at [`docker.sh`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker.sh). This script automates image retrieval and container startup as referenced in the repository documentation:

```bash
curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bash
docker-compose -f docker-compose.images.yml up -d

```

This approach is ideal for **CI/CD pipelines** and environments where you want isolated container runtimes without installing Go tooling.

## Native Binary Deployment

### Building the Server and Agent

When container runtimes are unavailable or restricted, compile the Go source directly. The entry point for the web server resides in [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), while the agent executable compiles from [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go). This method produces native binaries that execute directly on the host OS without virtualization overhead.

### Direct Execution on Host

As noted in [`SECURITY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/SECURITY.md), you can deploy the compiled binaries to a dedicated scan host. This mode eliminates Docker overhead and provides tighter control over execution parameters:

```bash

# Build server binary

go build -o ai-infra-guard ./cmd/cli/main.go

# Launch web service

./ai-infra-guard webserver --server 127.0.0.1:8088

# Build and run agent

go build -o agent ./cmd/agent
AIG_SERVER=127.0.0.1:8088 ./agent

```

This deployment mode is preferred for **on-premises installations** where container runtimes are prohibited or when you require direct hardware access for scanning operations.

## Air-Gapped and On-Premises Deployment

### Offline Data Updates

For environments without internet access, the FAQ documentation in [`frontend/public/aigdocs/docs/faq_en.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/public/aigdocs/docs/faq_en.md) describes an offline update workflow. Pre-pull images or clone the repository on an internet-connected machine, then transfer the `data` directory containing rules and fingerprints to the isolated host:

```bash

# On internet-connected machine

git clone https://github.com/Tencent/AI-Infra-Guard.git
cp -r AI-Infra-Guard/data /tmp/aig-data

# Transfer to air-gapped host

scp -r /tmp/aig-data user@offline-host:/path/to/aig-deployment/data

```

This approach allows security signature updates without redeploying the entire service stack, enabling fully offline operation in highly secure environments.

## Summary

- **Docker-Compose**: Best for quick starts and CI/CD; uses [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) and [`docker.sh`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker.sh) for one-click deployment across Linux, macOS, and Windows.
- **Native Binaries**: Compile from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) and [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go) for bare-metal performance without containerization dependencies.
- **Air-Gapped**: Supports fully offline operation by manually syncing the `data` directory, as documented in the FAQ and README.

## Frequently Asked Questions

### Can AI-Infra-Guard run on Windows?

Yes. Through Docker-Compose deployment, the containerized architecture abstracts the host operating system, enabling execution on Windows, Linux, and macOS. For native execution, compile the Go binaries for Windows targets using `GOOS=windows` during the build process.

### How do I update detection rules in an offline environment?

Clone the repository on an internet-connected system, copy the `data` directory containing the latest rules and fingerprints, and transfer it to your air-gapped deployment. Replace the existing `data` folder on the isolated host to update detection capabilities without requiring network access from the secure environment.

### What is the difference between docker-compose.yml and docker-compose.images.yml?

The [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) file typically builds images from source, while [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) references the pre-built `zhuquelab/aig-server` and `zhuquelab/aig-agent` images from Docker Hub. The latter enables faster, one-click deployment without compiling locally.

### Is it safe to run the agent and server on the same host?

According to [`SECURITY.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/SECURITY.md), you can run both components on a dedicated scan host. For production environments, consider network segmentation between the agent (which performs active scanning) and the server (which hosts the web interface) based on your organization's security posture and compliance requirements.