Network and ports
All containers join the Docker network face-matcher-network, created by run.sh. Inside that network services address each other by container name; on the host, a subset of ports is published so that Station, API clients and cameras can reach the deployment. The release package publishes these ports on all host interfaces with default credentials, so restrict them with a firewall or a reverse proxy before you expose the host to an untrusted network.
Dependencies
| Service | Host port | In-network address | Protocol | Purpose |
|---|---|---|---|---|
| RabbitMQ | 5672 | rmq:5672 | AMQP | Intra-service messaging and notification delivery. |
| RabbitMQ | 15672 | rmq:15672 | HTTP | Management UI (guest/guest by default). |
| RabbitMQ | 1883 | rmq:1883 | MQTT | Edge devices publish FrameData and receive watchlist updates here. |
| RabbitMQ | 5552 | rmq:5552 | RabbitMQ Streams | Watchlist update-log stream read by the synchronization services. |
| PostgreSQL | 5432 | pgsql:5432 | TCP | Relational database. |
| SeaweedFS | 8333 | seaweedfs:8333 | HTTP (S3 API) | Object storage for images. |
| pgAdmin | 7070 | — | HTTP | Optional database administration UI. |
RabbitMQ can additionally serve MQTT and Streams over TLS (conventionally 8883 and 5551). The shipped broker configuration does not enable TLS; configure it yourself if you need encrypted transport to edge devices, see the HTTPS and TLS guide.
Engine services and Station
| Service | Host port | In-network address | Protocol | Purpose |
|---|---|---|---|---|
REST API (api) | 8098 | api:8080 | HTTP | REST API and Swagger UI. |
GraphQL API (graphql-api) | 8097 | graphql-api:8080 | HTTP / WebSocket | /graphql endpoint, queries and subscriptions. |
Station (fm-station) | 8000 | fm-station:8000 | HTTP | Web UI. |
Camera services (cam-1 … cam-5) | 30001 – 30005 | same ports | TCP | Live camera preview streams, one port per camera slot (30000 + camera sequence). |
Synchronization Leader (db-synchronization-leader) | 8100 | — | gRPC (HTTP/2) | Endpoint that Follower sites connect to. Only needed on a Leader site. |
| Every engine service | not published | <container>:6060 | HTTP | Health checks (/healthz/ready, /healthz/live). Publish per service if your monitoring needs them. |
| Every engine service | not published | <container>:4318 | HTTP | Prometheus metrics exporter (OpenTelemetry). |
The preview port of a camera is assigned automatically as 30000 plus the camera's sequence number. Leave CameraDefaults__PreviewPort empty in .env to keep that behaviour; set it only if you need one fixed port for every camera. Each cam-* service publishes its own port in docker-compose.yml, so add a mapping if you add camera slots.
Cameras and edge devices
| Direction | Port | Protocol | Notes |
|---|---|---|---|
| Face Matcher → IP camera, VMS or NVR | 554 | RTSP | Default RTSP port; the camera service pulls the stream. |
| Edge device → Face Matcher | 1883 | MQTT | The Embedded Stream Processor on the device connects to the RabbitMQ MQTT endpoint. |
Both port numbers are conventions and can be changed on the camera or in the device settings. Make sure the network and the firewalls allow this traffic between the cameras and the server, and keep the round trip short: server-side processing needs a steady stream at 15 fps or better, see Choosing a camera.
Stacks built on Face Matcher
A stack that runs next to Face Matcher joins face-matcher-network with external: true and uses the in-network addresses above (api:8080, graphql-api:8080, rmq:5672, seaweedfs:8333, pgsql:5432, fm-station:8000). Everything else is internal and may change between releases. Credentials are in .env.