First Deployment
This guide runs the Smart Corridor stack for the first time using the official Docker Compose package. By the end, the dashboard, the Hub's GraphQL API and Face Matcher's Station are reachable.
1. Clone the deployment repository
The deployment package — Compose files, environment files, the vendored Face Matcher release and the helper scripts — lives in the smart-corridor repository:
git clone https://github.com/innovatrics/smart-corridor.git
cd smart-corridor
Do not edit anything under face-matcher/: it is a byte-identical copy of the Face Matcher release and is replaced as a whole on upgrade.
2. Registry access
All images are pulled from the Innovatrics registry registry.dot.innovatrics.com — Face Matcher images from the vpp/ project, corridor images (corridor-foundation-service, corridor-identity-grouping-service, biometriccorridor, the MCT services) from the border-control/ project. Access is granted through a robot account — one dedicated account per client, scoped to the products you are entitled to, with no expiration — provided from the Innovatrics Customer Portal:
docker login registry.dot.innovatrics.com -u '<robot-account-name>' -p '<token>'
Use the robot account name and token exactly as provided in the Customer Portal. The login persists in ~/.docker/config.json.
3. Obtain a license
The stack requires one iengine.lic file tied to the hardware of the host. Get the hardware ID by running the license-manager image:
docker run --rm registry.dot.innovatrics.com/vpp/license-manager:3.2.7
Provide the printed hardware ID when requesting a license from the Customer Portal. The same file licenses Face Matcher and — through its smart_corridor block — the corridor services, so make sure the request covers both. Place it at:
./secrets/iengine.lic
For the details of Face Matcher licensing, see Get a License.
4. Configure the environment
Two files drive the corridor configuration (Face Matcher keeps its own .env inside face-matcher/):
.env— corridor image versions and the dashboard port (default8095). Use the version values from your release notes..env.hub— Hub wiring:VPP_ADAPTER_ALLOWED_WATCHLISTS(watchlist IDs that grant GREEN clearance), theFOUNDATION_UNITS_0_*unit/camera definitions, and the storage settings for face crops.
Face-crop images are kept in the shared S3 store (SeaweedFS, host port 8333). If thumbnails do not load in the browser, check that the S3 address configured in .env.hub is reachable from the officer's workstation, not only from inside the Docker network.
5. Run the stack
start.sh starts Face Matcher from face-matcher/ first, then the corridor services:
bash start.sh
6. Verify
When the script finishes, these endpoints are available on the host:
| Service | URL |
|---|---|
| Corridor dashboard | http://localhost:8095 |
| Hub GraphQL | http://localhost:8090/corridor-foundation/graphql |
| Hub GraphiQL explorer | http://localhost:8090/corridor-foundation/graphiql |
| CIGS health | http://localhost:8096/actuator/health |
| Face Matcher Station | http://localhost:8000 |
| Face Matcher REST API | http://localhost:8098 |
| Face Matcher GraphQL | http://localhost:8097/graphql |
| MCT Visualizer (only with MCT) | http://localhost:8004 |
Supporting services with development-default credentials (change them before production): RabbitMQ http://localhost:15672 (guest / guest), SeaweedFS S3 http://localhost:8333 (admin / admin), pgAdmin http://localhost:7070 (admin@admin.com / Test1234). The full port list is in Network Ports and Network Topology.
Open the GraphiQL explorer, or check container status:
docker compose ps
docker compose logs <service-name>
Stopping and resetting
bash stop.sh # stop all services, keep data
bash factory-reset.sh # stop and wipe all containers, images, and volumes
Next steps
- Add Cameras — register your first camera in Face Matcher and assign it to a unit
- Add People to Watchlists — enroll subjects and mark which watchlists grant clearance