# How to Set Up Pentagi Locally: Complete Installation Guide

> Set up Pentagi locally easily with our complete installation guide. Run the interactive installer or Docker Compose. Get started with just Docker and 4GB RAM.

- Repository: [VXControl/pentagi](https://github.com/vxcontrol/pentagi)
- Tags: how-to-guide
- Published: 2026-03-21

---

**You can set up Pentagi locally by running the interactive installer or manually launching Docker Compose stacks, requiring only Docker, 4 GB RAM, and a configured `.env` file with LLM credentials.**

Pentagi is a modular, container-native penetration testing platform developed by **vxcontrol/pentagi**. It combines a **React/TypeScript frontend**, a **Go-based API server**, **PostgreSQL with pgvector**, and an **asynchronous task queue**, all orchestrated via Docker Compose. This guide covers both the automated installer and manual deployment methods to get Pentagi running on your local machine.

## Prerequisites

Before starting, ensure your system meets the following requirements:

| Requirement | Purpose | Verification |
|-------------|---------|------------|
| **Docker & Docker Compose** | Runs isolated containers for each service | `docker compose version` |
| **2 vCPU, 4 GB RAM, 20 GB disk** | Minimum for API, DB, and security tools | Check Docker Desktop resources |
| **Internet access** | Pulls images and downloads installer | Required for first run only |
| **(Optional) GPU & vLLM** | Accelerates local LLM inference | See the vLLM setup guide for driver requirements |

## Installation Methods

Pentagi offers two deployment paths: an **interactive installer** that automates configuration, or a **manual setup** for full control over the environment.

### Option 1: Interactive Installer (Recommended)

The installer binary performs system validation, generates a secure `.env` file, and launches the Docker stack. According to the source code in [`backend/cmd/installer/wizard/controller.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/wizard/controller.go), the wizard executes six distinct phases: Docker verification, environment creation, LLM provider selection, search engine configuration, credential generation, and stack initialization.

Execute the following commands to run the installer:

```bash

# Create a working directory

mkdir -p pentagi && cd pentagi

# Download the latest Linux installer (amd64)

wget -O installer.zip https://pentagi.com/downloads/linux/amd64/installer-latest.zip
unzip installer.zip

# Run the installer (requires Docker socket access)

sudo ./installer

```

During the wizard, you will:

1. **Verify Docker** is running and check system resources.
2. **Create a `.env` file** pre-populated with secure defaults.
3. **Select LLM providers** (OpenAI, Anthropic, Ollama, AWS Bedrock, etc.).
4. **Configure search engines** (DuckDuckGo, Google, Tavily).
5. **Generate cryptographic salts** for cookie signing and JWT secrets.
6. **Start the stack** via `docker compose up -d`.

### Option 2: Manual Docker Compose Setup

For custom deployments or development environments, manually configure the containers using the repository's compose files.

**Step 1:** Clone the repository and prepare the environment file:

```bash
git clone https://github.com/vxcontrol/pentagi.git
cd pentagi

# Copy the example environment file

cp .env.example .env

# Edit .env to add at least one LLM API key (OPEN_AI_KEY, ANTHROPIC_API_KEY, etc.)

```

**Step 2:** (Optional) Download provider configurations for local LLMs:

```bash
mkdir -p examples/configs
curl -o examples/configs/ollama-llama318b.provider.yml \
  https://raw.githubusercontent.com/vxcontrol/pentagi/master/examples/configs/ollama-llama318b.provider.yml

```

**Step 3:** Launch the core stack defined in [`docker-compose.yml`](https://github.com/vxcontrol/pentagi/blob/main/docker-compose.yml):

```bash
docker compose up -d

```

This creates the `pentagi-network` Docker network and starts the UI, API server, PostgreSQL with pgvector, Redis, and the scraper service.

**Step 4:** Add optional stacks by merging compose files:

```bash

# LLM observability with Langfuse

docker compose -f docker-compose.yml -f docker-compose-langfuse.yml up -d

# Knowledge graph with Graphiti/Neo4j

docker compose -f docker-compose.yml -f docker-compose-graphiti.yml up -d

# Full observability (Grafana, VictoriaMetrics, Jaeger, Loki)

docker compose -f docker-compose.yml -f docker-compose-observability.yml up -d

```

Separate networks (`langfuse-network`, `observability-network`) isolate traffic between optional stacks while permitting controlled inter-service communication.

## Network Configuration and External Access

By default, Pentagi binds to `127.0.0.1` (localhost) only. To expose the UI to your local network or access it from a remote machine:

**Step 1:** Modify `.env`:

```bash
PENTAGI_LISTEN_IP=0.0.0.0
PUBLIC_URL=https://<YOUR_HOST_IP>:8443
CORS_ORIGINS=https://localhost:8443,https://<YOUR_HOST_IP>:8443

```

**Step 2:** Recreate containers to apply network changes:

```bash
docker compose down
docker compose up -d --force-recreate

```

**Step 3:** Open port `8443` on your host firewall:

```bash

# Ubuntu/Debian

sudo ufw allow 8443/tcp

# RHEL/CentOS/Fedora

sudo firewall-cmd --add-port=8443/tcp --permanent
sudo firewall-cmd --reload

```

### Podman Compatibility

For rootless Podman deployments, modify the scraper service port to avoid privileged binding. In [`docker-compose.yml`](https://github.com/vxcontrol/pentagi/blob/main/docker-compose.yml) (or a [`podman-compose.yml`](https://github.com/vxcontrol/pentagi/blob/main/podman-compose.yml) override), change the scraper port from `443` to `3000` and update `SCRAPER_PRIVATE_URL` to use HTTP on port `3000`.

## Verifying Your Installation

Once containers are running, verify the API is responsive:

```bash

# Obtain an API token from the UI (Settings → API Tokens)

API_TOKEN=your_token_here

curl -s https://localhost:8443/api/v1/flows \
  -H "Authorization: Bearer $API_TOKEN" | jq .

```

Access the web UI at `https://localhost:8443` (accept the self-signed certificate). Default credentials are `admin@pentagi.com` / `admin` — change these immediately after first login.

## Summary

- **Pentagi** is a containerized penetration testing platform using React, Go, PostgreSQL/pgvector, and Redis.
- **Two installation methods** exist: the **interactive installer** (recommended) automates configuration via `backend/cmd/installer/`, or **manual Docker Compose** for custom deployments.
- **Core stack** requires only [`docker-compose.yml`](https://github.com/vxcontrol/pentagi/blob/main/docker-compose.yml) and a configured `.env` file with at least one LLM provider key.
- **Optional stacks** extend functionality via separate compose files: **Langfuse** (observability), **Graphiti** (knowledge graph), and **Observability** (metrics/logging).
- **Network access** defaults to localhost; bind to `0.0.0.0` via `PENTAGI_LISTEN_IP` and update `PUBLIC_URL` and `CORS_ORIGINS` for LAN/internet access.

## Frequently Asked Questions

### What hardware specifications are required to run Pentagi locally?

Pentagi requires a minimum of **2 vCPU, 4 GB RAM, and 20 GB disk space** to run the core API, database, and security tools. If you plan to run local LLM inference via vLLM, you will need a compatible GPU and additional VRAM (e.g., 24 GB+ for models like Qwen 3.5-27B-FP8).

### Can I use Pentagi without an internet connection?

Yes, after the **initial installation**. The first run requires internet access to pull Docker images and download the installer binary. Once all images are cached locally and you have configured local LLM providers (such as Ollama or vLLM), Pentagi can operate fully offline.

### How do I switch between different LLM providers after installation?

Modify the `.env` file in your Pentagi working directory to add or change provider API keys (e.g., `OPEN_AI_KEY`, `ANTHROPIC_API_KEY`, `OLLAMA_SERVER_URL`). For advanced configurations, place provider-specific YAML files in `examples/configs/` and reference them via environment variables. Restart the containers with `docker compose restart` to apply changes.

### Is it possible to run Pentagi on Podman instead of Docker?

Yes, Pentagi supports **rootless Podman** with minor configuration changes. You must modify the scraper service in [`docker-compose.yml`](https://github.com/vxcontrol/pentagi/blob/main/docker-compose.yml) to use a non-privileged port (change `443` to `3000`) and update the `SCRAPER_PRIVATE_URL` environment variable to use HTTP on port `3000`. This avoids the permission issues associated with binding to privileged ports in rootless containers.