Preferred deployment for privacy-sensitive teams: run the AXGuard GitHub adapter + Core in your network. Prefer this over a SaaS dashboard.
Related: install.md · privacy.md · docs/research/github-security-bot.md.
Customer VPC / GHES
├── HTTPS webhook receiver (Adapter)
├── Queue + worker (async; ack webhooks in <10s)
├── AXGuard Core (engines/*)
└── Optional local AI endpoint
There is no large hosted UI in this repo. Operational status is:
axguard github status .
axguard github validate .If/when a process exposes a bind address (github.webhook_host /
github.webhook_port in .axguard.yml), treat it as a webhook endpoint — not
a product dashboard.
- Register a GitHub App with permissions.md.
- Store PEM + webhook secret in your secret manager; export env vars from config.md.
axguard github setup .and edit.axguard.ymlbind host/port if needed.- Terminate TLS in front of the adapter (reverse proxy / load balancer).
- Allowlist GitHub webhook IPs from
GET /metawhen practical. - Keep
privacy.retain_source: falseunless debugging with an explicit TTL. - On uninstall, stop the process and delete local credentials (uninstall.md).
Point the adapter’s API base at your GHES hostname. Keep the same permission matrix and signature verification. Confirm API version headers against your GHES release notes.
If you cannot run a receiver:
# .github/workflows/axguard.yml (illustrative)
on: pull_request
jobs:
axguard:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: pip install -e .
- run: axguard audit . --fail-on high --no-bannerThis runs Core in CI; it does not create App Check Runs unless you add further Checks API wiring.