# What Programming Languages and Frameworks Power Pentagi?

> Discover the Go backend with Gin and GraphQL and the React TypeScript frontend compiled by Vite that power Pentagi. Learn about its tech stack.

- Repository: [VXControl/pentagi](https://github.com/vxcontrol/pentagi)
- Tags: internals
- Published: 2026-03-21

---

**Pentagi is built with a Go-based backend using Gin and GraphQL, paired with a React and TypeScript frontend compiled by Vite, alongside Docker-based observability stacks.**

Pentagi is an open-source, full-stack multi-agent security testing platform developed by vxcontrol. Understanding the programming languages and frameworks used in Pentagi reveals how it orchestrates complex penetration testing workflows through modern web technologies and containerized architectures.

## Backend Architecture: Go and the Gin Ecosystem

The backend services are implemented in **Go** and expose both REST and GraphQL APIs. According to the `backend/go.mod` file, the project relies on a curated ecosystem of Go libraries for high-performance networking and data persistence.

**Core Go frameworks include:**

- **Gin (Gin-Gonic)** – HTTP router and middleware framework that handles API requests and JWT/OAuth2/API token authentication
- **GORM** – Object-Relational Mapper for PostgreSQL interactions
- **gqlgen** – Schema-first GraphQL server generation (defined in `backend/pkg/graph/schema.graphqls`)
- **swag** – Swagger/OpenAPI documentation generation
- **go-vector / pgvector** – Semantic vector storage for AI embeddings
- **OpenTelemetry** – Distributed tracing and metrics collection

The HTTP routing layer is implemented in [`backend/pkg/server/router.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/server/router.go), where Gin handlers manage endpoints for flow creation, job queuing, and Docker sandbox orchestration:

```go
// src: backend/pkg/server/router.go
func registerRoutes(r *gin.Engine) {
    r.GET("/api/v1/version", func(c *gin.Context) {
        c.JSON(http.StatusOK, gin.H{
            "version": "v1.0.0",
        })
    })
}

```

## Frontend Stack: React with TypeScript and Vite

The web interface is built with **TypeScript** and **React**, bundled using **Vite** as shown in [`frontend/vite.config.ts`](https://github.com/vxcontrol/pentagi/blob/main/frontend/vite.config.ts). This modern frontend stack provides type safety and fast development cycles for the complex UI interactions required to visualize penetration testing flows.

**Key frontend libraries include:**

- **React** – Component-based UI library for building the interface
- **Apollo Client** – GraphQL client for queries and subscriptions (configured in [`frontend/src/lib/apollo.ts`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/lib/apollo.ts))
- **Radix UI** – Accessible, unstyled component primitives (used in components like [`frontend/src/components/ui/Button.tsx`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/components/ui/Button.tsx))
- **Zod** – Schema validation for form inputs and API responses
- **Vitest** – Unit testing framework

The frontend communicates with the Go backend via GraphQL, as demonstrated in components similar to [`frontend/src/pages/settings/Version.tsx`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/pages/settings/Version.tsx):

```tsx
import { gql, useQuery } from '@apollo/client';
import { Spinner } from '@/components/ui/Spinner';

const VERSION_QUERY = gql`
  query GetVersion {
    version
  }
`;

export const Version = () => {
  const { data, loading, error } = useQuery(VERSION_QUERY);

  if (loading) return <Spinner />;
  if (error) return <p>Error loading version</p>;

  return <p>PentAGI version: {data.version}</p>;
};

```

## LLM Provider Layer: Custom Go Adapters

Pentagi integrates with multiple Large Language Model providers through a custom abstraction layer written in **Go**. The [`backend/pkg/providers/provider/provider.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/providers/provider/provider.go) file defines a `provider.Provider` interface that standardizes interactions with various AI services.

**Supported LLM platforms include:**

- OpenAI
- Anthropic
- Google Gemini
- AWS Bedrock
- Ollama
- DeepSeek
- GLM
- Kimi
- Qwen

These adapters enable the multi-agent system to route penetration testing tasks to different models based on capability and availability, all implemented within the Go backend runtime.

## Tool Execution: Docker SDK Integration

Security tools like Nmap and Dirb execute within isolated containers managed by the **Docker SDK for Go**. This architecture ensures that offensive security tools run in sandboxed environments without compromising the host system.

The Go backend uses the Docker SDK to orchestrate container lifecycle management, volume mounting for scan results, and network isolation during tool execution workflows.

## Observability Infrastructure: YAML and Docker Compose

The observability stack is configured through **YAML** files and orchestrated using **Docker Compose**. This layer provides optional monitoring capabilities that can be spun up alongside the core application.

**Components defined in [`observability/otel/config.yml`](https://github.com/vxcontrol/pentagi/blob/main/observability/otel/config.yml) and [`docker-compose.yml`](https://github.com/vxcontrol/pentagi/blob/main/docker-compose.yml) include:**

- **OpenTelemetry Collector** – Metrics and trace aggregation
- **Jaeger** – Distributed tracing backend
- **Loki** – Log aggregation system
- **VictoriaMetrics** – Time-series metrics storage

These services integrate with the Go backend's OpenTelemetry instrumentation to provide full visibility into API performance and agent execution flows.

## Summary

- **Pentagi** combines a **Go** backend with **React** and **TypeScript** frontend to deliver a multi-agent security testing platform.
- The backend uses **Gin**, **GORM**, **gqlgen**, and the **Docker SDK** to handle APIs, databases, and sandboxed tool execution.
- The frontend leverages **Vite**, **Apollo Client**, and **Radix UI** for a modern, type-safe user experience.
- **OpenTelemetry**, **Jaeger**, and **Loki** provide observability through YAML-configured Docker services.
- LLM integrations are abstracted through a custom Go interface supporting providers from OpenAI to Ollama.

## Frequently Asked Questions

### What backend framework does Pentagi use for its REST API?

Pentagi uses **Gin (Gin-Gonic)** as its primary HTTP router and middleware framework. The router configuration in [`backend/pkg/server/router.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/server/router.go) defines REST endpoints alongside GraphQL handlers, implementing authentication via JWT and API tokens within the Gin middleware chain.

### Is Pentagi's frontend built with TypeScript?

Yes, the frontend is built with **TypeScript** and compiled using **Vite**. The configuration in [`frontend/vite.config.ts`](https://github.com/vxcontrol/pentagi/blob/main/frontend/vite.config.ts) enables fast hot-module replacement and optimized production builds, while **Zod** provides runtime schema validation and **Vitest** handles unit testing.

### How does Pentagi support multiple LLM providers?

Pentagi implements a custom **Go** interface defined in [`backend/pkg/providers/provider/provider.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/providers/provider/provider.go) that abstracts provider-specific implementations. This allows the backend to support OpenAI, Anthropic, Gemini, Bedrock, Ollama, and other models through a unified adapter pattern without modifying core workflow logic.

### What observability tools are included in Pentagi's deployment?

Pentagi includes an optional observability stack configured via **YAML** and **Docker Compose**, featuring **OpenTelemetry** for instrumentation, **Jaeger** for distributed tracing, **Loki** for log aggregation, and **VictoriaMetrics** for metrics storage. These services are defined in [`observability/otel/config.yml`](https://github.com/vxcontrol/pentagi/blob/main/observability/otel/config.yml) and integrated with the Go backend's telemetry exporters.