Configuration
Station is configured through environment variables in .env.station, loaded by the station service in docker-compose.override.yml. Two values are not taken from that file: IDENTIFICATION_ENABLED comes from STATION_IDENTIFICATION in .env, and S3_PUBLIC_ENDPOINT is built from STATION_PUBLIC_HOST, which start.sh exports (defaulting to the host name). After any change to .env.station run:
docker compose up -d station
Compose recreates the Station container with the new environment; the platform services are not touched.
Connection to the platform
| Setting | Default | Meaning |
|---|---|---|
HOST, PORT | 0.0.0.0, 8000 | Address and port Station binds to inside the container. The host port is STATION_PORT in .env. |
CORE_API_ROOT | http://api:8080/api/v1 | REST API of the platform on the Compose network. |
GRAPHQL_ROOT | http://graphql-api:8080/graphql | GraphQL API, used for queries and subscriptions. |
CAM_PREVIEW_HOST_SFCAM1 to ..._SFCAM5 | cam-1 to cam-5 | Container hosting each camera slot, used to reach the preview stream (see Cameras). |
LICENSE_FILE_PATH | /etc/innovatrics/iengine.lic | Licence file mounted from ./iengine.lic, which start.sh links to secrets/iengine.lic. |
Feature toggles
| Setting | Default | Meaning |
|---|---|---|
STATION_IDENTIFICATION (in .env) | true | Shows the Identification page. Passed to the container as IDENTIFICATION_ENABLED. |
DOT_FACE_CAMERA_ENABLED | false | Allows taking photos with the device camera on the identification page, in the history face filter and in member registration. Needs HTTPS. |
DOT_FACE_CAMERA_FACE_CENTER_LIMIT | 0.2 | How far from the centre of the frame a face may be for the camera component to accept it. |
DOT_FACE_CAMERA_FACE_CONFIDENCE | 0.06 | Minimum face confidence for the camera component. |
SCORE_CONVERSION_LOWER_LIMIT / ..._PERCENTAGE | 20 / 30 | Biometric score shown as this percentage when the linear score type is selected. |
SCORE_CONVERSION_UPPER_LIMIT / ..._PERCENTAGE | 40 / 90 | Upper anchor of the same conversion (see Settings). |
BLACKLIST_WATCHLIST_IDS | placeholder | Comma-separated IDs of watchlists to show as restricted (see Manage watchlists). |
BULK_MEMBER_REGISTER_PARALLELISM | 4 | Parallel registration calls during bulk enrollment. |
FACE_VALIDATION_MODE | predefined | predefined validates enrolment images against the platform's face validation rules; none skips the validation. |
Watchlist member labels
Labels are extra key-value fields on a watchlist member, shown in the member profile and in event details and settable in the profile, through the REST API (labels array of the member) or from file names in bulk enrollment. Each label is a pair of settings: the key is what the API stores, the label is the caption Station shows. The package ships ten of them for border-control style data:
WATCHLIST_MEMBER_KEY_0=country
WATCHLIST_MEMBER_LABEL_0=Nationality
WATCHLIST_MEMBER_KEY_1=dob
WATCHLIST_MEMBER_LABEL_1=Date of Birth
...
WATCHLIST_MEMBER_KEY_9=docExpiry
WATCHLIST_MEMBER_LABEL_9=Expires
Change, remove or add pairs (_10, _11, ...) to fit your data. Labels set through the API with a key that is not configured here are stored but not displayed.
Logging
Station writes its log to the container output, so docker compose logs -f station is the normal way to read it and the monitoring and logs guide shows how to ship it with the other services' logs.
| Setting | Default | Meaning |
|---|---|---|
ENABLE_LOGGING | true | Logging on or off. |
LOG_LEVEL | info | debug, info or error. |
LOG_FORMAT_JSON | false | JSON lines instead of plain text. |
LOG_TO_FILE | false | Also write a rotating log file inside the container. If you enable it, set LOG_FILE_PATH to a path inside the container and mount a volume there; the value shipped in the file is a placeholder. |
LOG_FILE_DATE_PATTERN, LOG_FILE_MAX_SIZE, LOG_FILE_MAX_FILES | YYYY-MM-DD, 20m, 1d | Rotation of the log file: date pattern in the name, size per file, retention. |
S3 storage
Station shows images by handing the browser presigned URLs to the S3 storage, so the storage has to be reachable under two names: from the Station container and from the operator's browser.
| Setting | Default | Meaning |
|---|---|---|
S3_ENDPOINT | http://seaweedfs:8333 | Storage address on the Compose network. |
S3_PUBLIC_ENDPOINT | http://<STATION_PUBLIC_HOST>:8333 | Storage address as seen by the browser. Set by docker-compose.override.yml from STATION_PUBLIC_HOST; start.sh defaults that to the host name. If images do not load in the browser, export STATION_PUBLIC_HOST with an address the browser can reach before running start.sh. |
S3_ACCESS_KEY, S3_SECRET_KEY | admin / admin | Credentials; must match the storage credentials in .env. Change both before production. |
S3_BUCKET | face-matcher | Bucket used by the platform. |
S3_REGION | us-east-1 | Region name expected by the S3 client. |
S3_URL_EXPIRATION | 300 | Lifetime of a presigned URL in seconds. |
S3_SKIP_SSL | false | Skip certificate validation when the storage uses HTTPS. |
S3_PRECREATE_BUCKET | true | Create the bucket if it does not exist. |
How the platform itself writes to the storage is described in S3 storage.
HTTPS and authentication
HTTPS_ENABLED, HTTPS_HOST_NAME, HTTPS_KEY_FILE and HTTPS_CERT_FILE make Station serve HTTPS with your certificate, which is required for the device camera features; the HTTPS guide covers certificates and the local-testing alternative.
AUTH0_* and KEYCLOAK_* (each with an _AUTHENTICATION_ENABLED switch), AUTH_HEADER, UNAUTHORIZE_ACCESS_REDIRECTION_URL and KEYCLOAK_ADMIN_URL put Station behind an OpenID Connect provider; ROLES_CLAIM_NAME, ROLE_KEY_* and FORCED_ROLE_NAME_0 map users to roles. See the authentication guide and Roles and presets. Authentication is off by default.
Settings to leave as shipped
ACCESS_CONTROLLER_ADDRESS (empty) and PALMS_ENABLED (false) refer to components that are not part of Face Matcher. Leave them at their shipped values; enabling them exposes controls in Station that have no service behind them.