Skip to main content

Install

Face Matcher is installed with Docker Compose on a Linux host. The package starts the dependencies (PostgreSQL, RabbitMQ, SeaweedFS), migrates the database, creates the S3 bucket, then starts the engine services and Station, all from one script. The whole run takes a few minutes, most of it pulling images. Complete the hardware check and get a license first.

1. Install Docker​

Install Docker Engine and the Docker Compose plugin following the Docker documentation. Add your user to the docker group so you do not need sudo for every command:

sudo usermod -aG docker $USER
newgrp docker

2. Get the package and log in to the registry​

Clone or download the face-matcher repository into a directory you own. Then log in to the Innovatrics container registry with the credentials from the Customer Portal:

git clone https://github.com/innovatrics/face-matcher.git
cd face-matcher
docker login registry.dot.innovatrics.com -u <username> -p <password>

The images live under registry.dot.innovatrics.com/vpp/, a path inherited from the platform Face Matcher is built on; .env already points there.

3. Add the license​

Read the hardware ID and generate the license as described in Get a license, then copy the file:

docker run --rm registry.dot.innovatrics.com/vpp/license-manager:3.2.7
cp /path/to/iengine.lic secrets/

4. Start​

./start.sh

start.sh checks for secrets/iengine.lic, creates the face-matcher-network Docker network, starts the dependencies, runs the database migration for the configured number of camera services, creates the S3 bucket and starts all services. It ends by printing the URLs of Station and the APIs. The services restart automatically after a host reboot.

Most engine services run as root inside their containers. The licensing library derives the hardware ID from identifiers that only root can read; with the image's default unprivileged user the ID differs and the license is rejected. This is a known constraint of the current images, documented in docker-compose.override.yml.

5. Verify​

Open http://localhost:8000 in a browser (or replace localhost with the host's address). Station's Security page appears with empty camera previews. Check that every container is up:

docker ps --format '{{.Names}}\t{{.Status}}'

Continue with First identification.

Endpoints​

ServiceURLDefault credentials
Stationhttp://localhost:8000none (authentication off)
REST APIhttp://localhost:8098none (authentication off)
GraphQL APIhttp://localhost:8097/graphqlnone (authentication off)
RabbitMQ managementhttp://localhost:15672guest / guest
SeaweedFS S3http://localhost:8333admin / admin
pgAdminhttp://localhost:7070admin@admin.com / Test1234
PostgreSQLlocalhost:5432postgres / Test1234

All ports are published on all interfaces with development credentials. Do not expose the host to an untrusted network in this state: change the credentials in .env and .env.station, restrict the published ports and enable authentication and HTTPS before production. The full port list, including the internal container addresses, is in Network and ports.

Stop and reset​

  • ./stop.sh stops all containers and keeps the data volumes; ./start.sh brings everything back.
  • ./factory-reset.sh stops everything and deletes the containers, images and data volumes. The license in secrets/ is kept. Use it to start over from scratch, never on a system whose data you need.