Network Topology
A Smart Corridor stack sits between three network concerns: the camera network feeding it video, the client network consuming its endpoints, and — in multi-stack deployments — the inter-site link to the Face Matcher Leader. Internal traffic between the Hub, Face Matcher, CIGS, CBS, MCT and the message broker stays inside the face-matcher-network Docker network and never needs to be exposed.
Camera network
Cameras belong on a dedicated VLAN or physically separate segment reachable only by the stack host. For server-side RTSP, budget roughly 4 Mbps of stable bandwidth per camera and keep latency low enough to hold 15+ fps end to end; PoE switches simplify cabling and power. Edge devices send only metadata and selected frames over MQTT to the broker, so their bandwidth needs are a fraction of RTSP — a practical relief on sites where pulling new cabling is expensive. Details in Cameras.
Client and integration network
Corridor consumers — the dashboard, integrator systems, gate controllers — need exactly one thing: HTTP(S) access to the Hub's /graphql endpoint on port 8090 (WebSocket or SSE for subscriptions). Operators additionally use Station on port 8000, and the officer's browser needs to reach the S3 image store on port 8333 for thumbnails. No client needs the broker or the databases.
| Host port | Service |
|---|---|
8095 | Corridor dashboard |
8090 | Hub GraphQL API (/corridor-foundation/graphql) |
8096 | CIGS health endpoint |
8000 | Face Matcher Station |
8098 | Face Matcher REST API |
8097 | Face Matcher GraphQL API |
8333 | SeaweedFS S3 (face crops) |
15672 | RabbitMQ management UI |
7070 | pgAdmin |
8004 | MCT Visualizer (only with MCT) |
Face Matcher's full port list, including camera previews, is in Network Ports. Terminate TLS in front of the endpoints you expose and restrict access to the operational network; see Security Hardening.
Inter-site and outbound
Multi-stack deployments need connectivity between each stack's Face Matcher Follower and the Leader (see Deployment Layouts); matching runs locally, so this link tolerates latency and interruptions without stopping lanes. Outbound access is needed at install and upgrade time to registry.dot.innovatrics.com only (see First Deployment); air-gapped operation between upgrades is otherwise viable.