How to Set Up Pentagi Locally: Complete Installation Guide
You can set up Pentagi locally by running the interactive installer or manually launching Docker Compose stacks, requiring only Docker, 4 GB RAM, and a configured .env file with LLM credentials.
Pentagi is a modular, container-native penetration testing platform developed by vxcontrol/pentagi. It combines a React/TypeScript frontend, a Go-based API server, PostgreSQL with pgvector, and an asynchronous task queue, all orchestrated via Docker Compose. This guide covers both the automated installer and manual deployment methods to get Pentagi running on your local machine.
Prerequisites
Before starting, ensure your system meets the following requirements:
| Requirement | Purpose | Verification |
|---|---|---|
| Docker & Docker Compose | Runs isolated containers for each service | docker compose version |
| 2 vCPU, 4 GB RAM, 20 GB disk | Minimum for API, DB, and security tools | Check Docker Desktop resources |
| Internet access | Pulls images and downloads installer | Required for first run only |
| (Optional) GPU & vLLM | Accelerates local LLM inference | See the vLLM setup guide for driver requirements |
Installation Methods
Pentagi offers two deployment paths: an interactive installer that automates configuration, or a manual setup for full control over the environment.
Option 1: Interactive Installer (Recommended)
The installer binary performs system validation, generates a secure .env file, and launches the Docker stack. According to the source code in backend/cmd/installer/wizard/controller.go, the wizard executes six distinct phases: Docker verification, environment creation, LLM provider selection, search engine configuration, credential generation, and stack initialization.
Execute the following commands to run the installer:
# Create a working directory
mkdir -p pentagi && cd pentagi
# Download the latest Linux installer (amd64)
wget -O installer.zip https://pentagi.com/downloads/linux/amd64/installer-latest.zip
unzip installer.zip
# Run the installer (requires Docker socket access)
sudo ./installer
During the wizard, you will:
- Verify Docker is running and check system resources.
- Create a
.envfile pre-populated with secure defaults. - Select LLM providers (OpenAI, Anthropic, Ollama, AWS Bedrock, etc.).
- Configure search engines (DuckDuckGo, Google, Tavily).
- Generate cryptographic salts for cookie signing and JWT secrets.
- Start the stack via
docker compose up -d.
Option 2: Manual Docker Compose Setup
For custom deployments or development environments, manually configure the containers using the repository's compose files.
Step 1: Clone the repository and prepare the environment file:
git clone https://github.com/vxcontrol/pentagi.git
cd pentagi
# Copy the example environment file
cp .env.example .env
# Edit .env to add at least one LLM API key (OPEN_AI_KEY, ANTHROPIC_API_KEY, etc.)
Step 2: (Optional) Download provider configurations for local LLMs:
mkdir -p examples/configs
curl -o examples/configs/ollama-llama318b.provider.yml \
https://raw.githubusercontent.com/vxcontrol/pentagi/master/examples/configs/ollama-llama318b.provider.yml
Step 3: Launch the core stack defined in docker-compose.yml:
docker compose up -d
This creates the pentagi-network Docker network and starts the UI, API server, PostgreSQL with pgvector, Redis, and the scraper service.
Step 4: Add optional stacks by merging compose files:
# LLM observability with Langfuse
docker compose -f docker-compose.yml -f docker-compose-langfuse.yml up -d
# Knowledge graph with Graphiti/Neo4j
docker compose -f docker-compose.yml -f docker-compose-graphiti.yml up -d
# Full observability (Grafana, VictoriaMetrics, Jaeger, Loki)
docker compose -f docker-compose.yml -f docker-compose-observability.yml up -d
Separate networks (langfuse-network, observability-network) isolate traffic between optional stacks while permitting controlled inter-service communication.
Network Configuration and External Access
By default, Pentagi binds to 127.0.0.1 (localhost) only. To expose the UI to your local network or access it from a remote machine:
Step 1: Modify .env:
PENTAGI_LISTEN_IP=0.0.0.0
PUBLIC_URL=https://<YOUR_HOST_IP>:8443
CORS_ORIGINS=https://localhost:8443,https://<YOUR_HOST_IP>:8443
Step 2: Recreate containers to apply network changes:
docker compose down
docker compose up -d --force-recreate
Step 3: Open port 8443 on your host firewall:
# Ubuntu/Debian
sudo ufw allow 8443/tcp
# RHEL/CentOS/Fedora
sudo firewall-cmd --add-port=8443/tcp --permanent
sudo firewall-cmd --reload
Podman Compatibility
For rootless Podman deployments, modify the scraper service port to avoid privileged binding. In docker-compose.yml (or a podman-compose.yml override), change the scraper port from 443 to 3000 and update SCRAPER_PRIVATE_URL to use HTTP on port 3000.
Verifying Your Installation
Once containers are running, verify the API is responsive:
# Obtain an API token from the UI (Settings → API Tokens)
API_TOKEN=your_token_here
curl -s https://localhost:8443/api/v1/flows \
-H "Authorization: Bearer $API_TOKEN" | jq .
Access the web UI at https://localhost:8443 (accept the self-signed certificate). Default credentials are admin@pentagi.com / admin — change these immediately after first login.
Summary
- Pentagi is a containerized penetration testing platform using React, Go, PostgreSQL/pgvector, and Redis.
- Two installation methods exist: the interactive installer (recommended) automates configuration via
backend/cmd/installer/, or manual Docker Compose for custom deployments. - Core stack requires only
docker-compose.ymland a configured.envfile with at least one LLM provider key. - Optional stacks extend functionality via separate compose files: Langfuse (observability), Graphiti (knowledge graph), and Observability (metrics/logging).
- Network access defaults to localhost; bind to
0.0.0.0viaPENTAGI_LISTEN_IPand updatePUBLIC_URLandCORS_ORIGINSfor LAN/internet access.
Frequently Asked Questions
What hardware specifications are required to run Pentagi locally?
Pentagi requires a minimum of 2 vCPU, 4 GB RAM, and 20 GB disk space to run the core API, database, and security tools. If you plan to run local LLM inference via vLLM, you will need a compatible GPU and additional VRAM (e.g., 24 GB+ for models like Qwen 3.5-27B-FP8).
Can I use Pentagi without an internet connection?
Yes, after the initial installation. The first run requires internet access to pull Docker images and download the installer binary. Once all images are cached locally and you have configured local LLM providers (such as Ollama or vLLM), Pentagi can operate fully offline.
How do I switch between different LLM providers after installation?
Modify the .env file in your Pentagi working directory to add or change provider API keys (e.g., OPEN_AI_KEY, ANTHROPIC_API_KEY, OLLAMA_SERVER_URL). For advanced configurations, place provider-specific YAML files in examples/configs/ and reference them via environment variables. Restart the containers with docker compose restart to apply changes.
Is it possible to run Pentagi on Podman instead of Docker?
Yes, Pentagi supports rootless Podman with minor configuration changes. You must modify the scraper service in docker-compose.yml to use a non-privileged port (change 443 to 3000) and update the SCRAPER_PRIVATE_URL environment variable to use HTTP on port 3000. This avoids the permission issues associated with binding to privileged ports in rootless containers.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →