Skip to main content

Network and ports

All containers join the Docker network face-matcher-network, created by run.sh. Inside that network services address each other by container name; on the host, a subset of ports is published so that Station, API clients and cameras can reach the deployment. The release package publishes these ports on all host interfaces with default credentials, so restrict them with a firewall or a reverse proxy before you expose the host to an untrusted network.

Dependencies​

ServiceHost portIn-network addressProtocolPurpose
RabbitMQ5672rmq:5672AMQPIntra-service messaging and notification delivery.
RabbitMQ15672rmq:15672HTTPManagement UI (guest/guest by default).
RabbitMQ1883rmq:1883MQTTEdge devices publish FrameData and receive watchlist updates here.
RabbitMQ5552rmq:5552RabbitMQ StreamsWatchlist update-log stream read by the synchronization services.
PostgreSQL5432pgsql:5432TCPRelational database.
SeaweedFS8333seaweedfs:8333HTTP (S3 API)Object storage for images.
pgAdmin7070—HTTPOptional database administration UI.

RabbitMQ can additionally serve MQTT and Streams over TLS (conventionally 8883 and 5551). The shipped broker configuration does not enable TLS; configure it yourself if you need encrypted transport to edge devices, see the HTTPS and TLS guide.

Engine services and Station​

ServiceHost portIn-network addressProtocolPurpose
REST API (api)8098api:8080HTTPREST API and Swagger UI.
GraphQL API (graphql-api)8097graphql-api:8080HTTP / WebSocket/graphql endpoint, queries and subscriptions.
Station (fm-station)8000fm-station:8000HTTPWeb UI.
Camera services (cam-1 … cam-5)30001 – 30005same portsTCPLive camera preview streams, one port per camera slot (30000 + camera sequence).
Synchronization Leader (db-synchronization-leader)8100—gRPC (HTTP/2)Endpoint that Follower sites connect to. Only needed on a Leader site.
Every engine servicenot published<container>:6060HTTPHealth checks (/healthz/ready, /healthz/live). Publish per service if your monitoring needs them.
Every engine servicenot published<container>:4318HTTPPrometheus metrics exporter (OpenTelemetry).

The preview port of a camera is assigned automatically as 30000 plus the camera's sequence number. Leave CameraDefaults__PreviewPort empty in .env to keep that behaviour; set it only if you need one fixed port for every camera. Each cam-* service publishes its own port in docker-compose.yml, so add a mapping if you add camera slots.

Cameras and edge devices​

DirectionPortProtocolNotes
Face Matcher → IP camera, VMS or NVR554RTSPDefault RTSP port; the camera service pulls the stream.
Edge device → Face Matcher1883MQTTThe Embedded Stream Processor on the device connects to the RabbitMQ MQTT endpoint.

Both port numbers are conventions and can be changed on the camera or in the device settings. Make sure the network and the firewalls allow this traffic between the cameras and the server, and keep the round trip short: server-side processing needs a steady stream at 15 fps or better, see Choosing a camera.

Stacks built on Face Matcher​

A stack that runs next to Face Matcher joins face-matcher-network with external: true and uses the in-network addresses above (api:8080, graphql-api:8080, rmq:5672, seaweedfs:8333, pgsql:5432, fm-station:8000). Everything else is internal and may change between releases. Credentials are in .env.