What Programming Languages and Frameworks Power Pentagi?

Pentagi is built with a Go-based backend using Gin and GraphQL, paired with a React and TypeScript frontend compiled by Vite, alongside Docker-based observability stacks.

Pentagi is an open-source, full-stack multi-agent security testing platform developed by vxcontrol. Understanding the programming languages and frameworks used in Pentagi reveals how it orchestrates complex penetration testing workflows through modern web technologies and containerized architectures.

Backend Architecture: Go and the Gin Ecosystem

The backend services are implemented in Go and expose both REST and GraphQL APIs. According to the backend/go.mod file, the project relies on a curated ecosystem of Go libraries for high-performance networking and data persistence.

Core Go frameworks include:

  • Gin (Gin-Gonic) – HTTP router and middleware framework that handles API requests and JWT/OAuth2/API token authentication
  • GORM – Object-Relational Mapper for PostgreSQL interactions
  • gqlgen – Schema-first GraphQL server generation (defined in backend/pkg/graph/schema.graphqls)
  • swag – Swagger/OpenAPI documentation generation
  • go-vector / pgvector – Semantic vector storage for AI embeddings
  • OpenTelemetry – Distributed tracing and metrics collection

The HTTP routing layer is implemented in backend/pkg/server/router.go, where Gin handlers manage endpoints for flow creation, job queuing, and Docker sandbox orchestration:

// src: backend/pkg/server/router.go
func registerRoutes(r *gin.Engine) {
    r.GET("/api/v1/version", func(c *gin.Context) {
        c.JSON(http.StatusOK, gin.H{
            "version": "v1.0.0",
        })
    })
}

Frontend Stack: React with TypeScript and Vite

The web interface is built with TypeScript and React, bundled using Vite as shown in frontend/vite.config.ts. This modern frontend stack provides type safety and fast development cycles for the complex UI interactions required to visualize penetration testing flows.

Key frontend libraries include:

  • React – Component-based UI library for building the interface
  • Apollo Client – GraphQL client for queries and subscriptions (configured in frontend/src/lib/apollo.ts)
  • Radix UI – Accessible, unstyled component primitives (used in components like frontend/src/components/ui/Button.tsx)
  • Zod – Schema validation for form inputs and API responses
  • Vitest – Unit testing framework

The frontend communicates with the Go backend via GraphQL, as demonstrated in components similar to frontend/src/pages/settings/Version.tsx:

import { gql, useQuery } from '@apollo/client';
import { Spinner } from '@/components/ui/Spinner';

const VERSION_QUERY = gql`
  query GetVersion {
    version
  }
`;

export const Version = () => {
  const { data, loading, error } = useQuery(VERSION_QUERY);

  if (loading) return <Spinner />;
  if (error) return <p>Error loading version</p>;

  return <p>PentAGI version: {data.version}</p>;
};

LLM Provider Layer: Custom Go Adapters

Pentagi integrates with multiple Large Language Model providers through a custom abstraction layer written in Go. The backend/pkg/providers/provider/provider.go file defines a provider.Provider interface that standardizes interactions with various AI services.

Supported LLM platforms include:

  • OpenAI
  • Anthropic
  • Google Gemini
  • AWS Bedrock
  • Ollama
  • DeepSeek
  • GLM
  • Kimi
  • Qwen

These adapters enable the multi-agent system to route penetration testing tasks to different models based on capability and availability, all implemented within the Go backend runtime.

Tool Execution: Docker SDK Integration

Security tools like Nmap and Dirb execute within isolated containers managed by the Docker SDK for Go. This architecture ensures that offensive security tools run in sandboxed environments without compromising the host system.

The Go backend uses the Docker SDK to orchestrate container lifecycle management, volume mounting for scan results, and network isolation during tool execution workflows.

Observability Infrastructure: YAML and Docker Compose

The observability stack is configured through YAML files and orchestrated using Docker Compose. This layer provides optional monitoring capabilities that can be spun up alongside the core application.

Components defined in observability/otel/config.yml and docker-compose.yml include:

  • OpenTelemetry Collector – Metrics and trace aggregation
  • Jaeger – Distributed tracing backend
  • Loki – Log aggregation system
  • VictoriaMetrics – Time-series metrics storage

These services integrate with the Go backend's OpenTelemetry instrumentation to provide full visibility into API performance and agent execution flows.

Summary

  • Pentagi combines a Go backend with React and TypeScript frontend to deliver a multi-agent security testing platform.
  • The backend uses Gin, GORM, gqlgen, and the Docker SDK to handle APIs, databases, and sandboxed tool execution.
  • The frontend leverages Vite, Apollo Client, and Radix UI for a modern, type-safe user experience.
  • OpenTelemetry, Jaeger, and Loki provide observability through YAML-configured Docker services.
  • LLM integrations are abstracted through a custom Go interface supporting providers from OpenAI to Ollama.

Frequently Asked Questions

What backend framework does Pentagi use for its REST API?

Pentagi uses Gin (Gin-Gonic) as its primary HTTP router and middleware framework. The router configuration in backend/pkg/server/router.go defines REST endpoints alongside GraphQL handlers, implementing authentication via JWT and API tokens within the Gin middleware chain.

Is Pentagi's frontend built with TypeScript?

Yes, the frontend is built with TypeScript and compiled using Vite. The configuration in frontend/vite.config.ts enables fast hot-module replacement and optimized production builds, while Zod provides runtime schema validation and Vitest handles unit testing.

How does Pentagi support multiple LLM providers?

Pentagi implements a custom Go interface defined in backend/pkg/providers/provider/provider.go that abstracts provider-specific implementations. This allows the backend to support OpenAI, Anthropic, Gemini, Bedrock, Ollama, and other models through a unified adapter pattern without modifying core workflow logic.

What observability tools are included in Pentagi's deployment?

Pentagi includes an optional observability stack configured via YAML and Docker Compose, featuring OpenTelemetry for instrumentation, Jaeger for distributed tracing, Loki for log aggregation, and VictoriaMetrics for metrics storage. These services are defined in observability/otel/config.yml and integrated with the Go backend's telemetry exporters.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →