Core Components of the Pentagi Architecture: A Technical Deep Dive
Pentagi's architecture consists of five core components—a React frontend, Go backend API, PostgreSQL vector store, Redis task queue, and multi-agent AI system—that together enable autonomous, AI-driven penetration testing workflows.
The Pentagi platform, developed by vxcontrol/pentagi, implements a modular, scalable, and secure architecture designed specifically for autonomous security assessments. Understanding the core components of the Pentagi architecture is essential for security engineers deploying self-hosted instances or integrating the platform into existing DevSecOps pipelines.
The Five Core Components of Pentagi
Frontend UI: React-Based Security Interface
The Frontend UI serves as the primary interaction layer for security engineers. Built with React and TypeScript, this component provides the web interface where users create testing flows, monitor real-time progress, and review generated security reports. The frontend communicates with the backend via GraphQL subscriptions for live updates, making it critical for real-time penetration testing visibility.
Backend API: Go-Powered Orchestration Layer
The Backend API functions as the central nervous system of Pentagi. Implemented in Go, it exposes both REST and GraphQL endpoints protected by bearer-token authentication. This component orchestrates flows, exposes data to the frontend, and drives the multi-agent system. In backend/pkg/server/router.go, the API router sets up Gin handlers, CORS policies, and authentication middleware that secure all communications.
Vector Store: PostgreSQL with pgvector for Semantic Memory
The Vector Store provides long-term memory and semantic search capabilities essential for autonomous testing. This component utilizes PostgreSQL with the pgvector extension to store embeddings, historical actions, and discovered vulnerabilities. The system queries this store to retrieve context from previous testing steps, enabling the AI agents to learn from prior actions. Typed Go queries in backend/pkg/database/queries.go handle all vector operations.
Task Queue: Redis-Backed Asynchronous Processing
The Task Queue manages asynchronous job processing for long-running operations. Backed by Redis, this component guarantees reliable execution of parallel tasks including tool runs, LLM reasoning cycles, and external API calls. When users initiate a flow, the Backend API enqueues jobs that the AI Agent workers pick up asynchronously, preventing blocking operations and enabling scalable concurrent testing.
AI Agent: Multi-Agent System for Autonomous Testing
The AI Agent represents the intelligent core that executes penetration testing workflows. This multi-agent system implements specialized roles including the Researcher, Developer, Executor, and Adviser agents. These agents plan testing steps, execute security tools, analyze results, and iterate on findings. The component leverages LLM providers implemented in backend/pkg/providers/ to interface with OpenAI, Anthropic, Gemini, Bedrock, and Ollama models.
How the Pentagi Components Interact
The core components of the Pentagi architecture communicate through well-defined APIs and shared data stores to form a cohesive autonomous testing workflow:
- User initiates flow via the Frontend UI (or directly through the Backend API).
- Backend API stores the flow definition in the Vector Store and enqueues a job on the Task Queue.
- AI Agent picks up the job, queries the Vector Store for prior knowledge, and may call external LLM providers or search engines.
- Results and discovered knowledge are persisted back into the Vector Store and knowledge graph.
- Frontend UI continuously polls the API or receives GraphQL subscriptions to present live progress and final reports.
Key Implementation Files
The following source files implement the core components of the Pentagi architecture:
backend/pkg/server/router.go— Sets up the Gin router, CORS, auth middleware, and registers all REST/GraphQL endpoints for the Backend API.backend/pkg/graph/schema.graphqls— Defines the GraphQL schema exposing flows, tasks, agents, and analytics.backend/pkg/config/config.go— Parses environment variables and configures services including the Vector Store, Task Queue, and provider URLs.backend/pkg/providers/— Implements theprovider.Providerinterface for OpenAI, Anthropic, Gemini, Bedrock, and Ollama, powering the AI Agent LLM interactions.frontend/src/app.tsx— Entry point for the React SPA implementing the Frontend UI.backend/pkg/database/queries.go— Generated SQLC queries for the Vector Store (PostgreSQL + pgvector).backend/pkg/services/flow_service.go— Business logic for managing flows and interfacing with the Task Queue.
Practical Integration Examples
Creating a New Penetration Testing Flow
Use the GraphQL mutation to create a flow through the Backend API:
mutation CreateFlow {
createFlow(
modelProvider: "openai"
input: "Run a full security assessment on https://example.com"
) {
id
title
status
createdAt
}
}
Execute via curl:
curl -X POST https://your-pentagi-instance:8443/api/v1/graphql \
-H "Authorization: Bearer $API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"query":"mutation CreateFlow { createFlow(modelProvider:\"openai\",input:\"Run a full security assessment on https://example.com\") { id title status createdAt } }"}'
Configuring an LLM Provider
Configure the AI Agent to use OpenRouter via YAML:
# examples/configs/openrouter.provider.yml
provider: openrouter
model: meta-llama/Meta-Llama-3.1-70B-Instruct
api_key: ${OPENROUTER_API_KEY}
The Providers package in backend/pkg/providers/providers.go registers this configuration for the multi-agent system.
Monitoring Real-Time Progress
Subscribe to flow updates via GraphQL subscription:
subscription FlowProgress($flowID: ID!) {
flowProgress(flowId: $flowID) {
subtaskId
status
logs
}
}
The Backend API delivers these updates through pkg/graph/subscriptions to the Frontend UI via WebSocket connections.
Summary
The core components of the Pentagi architecture work together to deliver autonomous penetration testing capabilities:
- Frontend UI provides the React-based interface for security engineers to manage testing workflows.
- Backend API serves as the Go-powered orchestration layer securing all communications with bearer-token authentication.
- Vector Store implements PostgreSQL with pgvector for semantic search and long-term memory of testing history.
- Task Queue utilizes Redis for reliable asynchronous processing of long-running security tasks.
- AI Agent operates as a multi-agent system leveraging specialized roles and multiple LLM providers to execute autonomous testing.
Frequently Asked Questions
What programming languages power the Pentagi architecture?
Pentagi utilizes a polyglot architecture: the Frontend UI is built with TypeScript and React, while the Backend API, AI Agent, and data services are implemented in Go. The Vector Store relies on PostgreSQL with the pgvector extension.
How does Pentagi handle authentication between components?
The Backend API implements bearer-token authentication for all REST and GraphQL endpoints, configured in backend/pkg/server/router.go. The Frontend UI passes these tokens with each request, while internal services communicate through secured channels with environment-based credentials.
Can Pentagi integrate with custom LLM providers?
Yes, the AI Agent supports custom LLM providers through the Providers package in backend/pkg/providers/. The system implements the provider.Provider interface for OpenAI, Anthropic, Gemini, AWS Bedrock, and Ollama, with configuration handled via YAML files or environment variables.
What database does Pentagi use for storing embeddings?
Pentagi uses PostgreSQL with the pgvector extension as its Vector Store. This configuration stores embeddings and semantic data for long-term memory, enabling the AI Agent to retrieve context from previous testing steps. Typed queries are generated via sqlc in backend/pkg/database/queries.go.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →