Skip to main content

Security Hardening

The corridor's attack surface is deliberately small: one integration endpoint (the Hub's /graphql), a handful of operator-facing ports (the dashboard, Station, the S3 image store), internal services on a private Docker network, and cameras on their own segment. Hardening is mostly about preserving that shape in production — do not expose the message broker, the databases, pgAdmin or the Face Matcher APIs beyond the operational network, and put TLS and authentication in front of what is exposed.

Network and access​

Terminate TLS at a reverse proxy in front of the Hub's /graphql endpoint and the dashboard, and restrict reachability to the operational network where officers, displays, and integrator systems live. Face Matcher's Station and APIs bind to host ports too: put them behind the same proxy, enable Face Matcher's optional OAuth2/OIDC authentication (Authentication, HTTPS), and firewall the RabbitMQ, pgAdmin and PostgreSQL ports. Keep cameras on a dedicated VLAN with no route to anything but the stack host; camera credentials and RTSP URLs are configuration secrets. In multi-stack deployments, treat the Follower-to-Leader Face Matcher link as trusted infrastructure traffic — private link or VPN, never the public internet.

Secrets and supply chain​

Registry credentials are per-client robot accounts scoped to your entitled products — store them in your secret management, not in shell history or committed .env files. The same applies to the license file in secrets/ and any watchlist provisioning credentials. Change the development-default credentials of RabbitMQ, the S3 store and pgAdmin before go-live. Pull images only from registry.dot.innovatrics.com (see First Deployment) and pin versions rather than tracking latest in production. Never patch files inside the vendored face-matcher/ folder — apply Face Matcher upgrades as whole release checkouts so the copy stays verifiable.

Data protection​

The strongest control is not storing data at all: with STORAGE_ENABLED=false, the corridor persists no event data at rest — the recommended mode for GDPR-sensitive deployments. Where storage is on, retention TTLs for events and images are enforced by a scheduled job and should be set to the minimum your operation needs; face crops and frames are personal data and belong in your records-of-processing documentation. Apply the matching policy on the Face Matcher side, which keeps its own detection history (Data and Privacy, Data Retention and Cleanup). Details in Event Storage & Retention.