Skip to main content

Network Topology

A Smart Corridor stack sits between three network concerns: the camera network feeding it video, the client network consuming its endpoints, and — in multi-stack deployments — the inter-site link to the Face Matcher Leader. Internal traffic between the Hub, Face Matcher, CIGS, CBS, MCT and the message broker stays inside the face-matcher-network Docker network and never needs to be exposed.

Camera network​

Cameras belong on a dedicated VLAN or physically separate segment reachable only by the stack host. For server-side RTSP, budget roughly 4 Mbps of stable bandwidth per camera and keep latency low enough to hold 15+ fps end to end; PoE switches simplify cabling and power. Edge devices send only metadata and selected frames over MQTT to the broker, so their bandwidth needs are a fraction of RTSP — a practical relief on sites where pulling new cabling is expensive. Details in Cameras.

Client and integration network​

Corridor consumers — the dashboard, integrator systems, gate controllers — need exactly one thing: HTTP(S) access to the Hub's /graphql endpoint on port 8090 (WebSocket or SSE for subscriptions). Operators additionally use Station on port 8000, and the officer's browser needs to reach the S3 image store on port 8333 for thumbnails. No client needs the broker or the databases.

Host portService
8095Corridor dashboard
8090Hub GraphQL API (/corridor-foundation/graphql)
8096CIGS health endpoint
8000Face Matcher Station
8098Face Matcher REST API
8097Face Matcher GraphQL API
8333SeaweedFS S3 (face crops)
15672RabbitMQ management UI
7070pgAdmin
8004MCT Visualizer (only with MCT)

Face Matcher's full port list, including camera previews, is in Network Ports. Terminate TLS in front of the endpoints you expose and restrict access to the operational network; see Security Hardening.

Inter-site and outbound​

Multi-stack deployments need connectivity between each stack's Face Matcher Follower and the Leader (see Deployment Layouts); matching runs locally, so this link tolerates latency and interruptions without stopping lanes. Outbound access is needed at install and upgrade time to registry.dot.innovatrics.com only (see First Deployment); air-gapped operation between upgrades is otherwise viable.