Skip to main content

First Deployment

This guide runs the Smart Corridor stack for the first time using the official Docker Compose package. By the end, the dashboard, the Hub's GraphQL API and Face Matcher's Station are reachable.

1. Clone the deployment repository​

The deployment package — Compose files, environment files, the vendored Face Matcher release and the helper scripts — lives in the smart-corridor repository:

git clone https://github.com/innovatrics/smart-corridor.git
cd smart-corridor

Do not edit anything under face-matcher/: it is a byte-identical copy of the Face Matcher release and is replaced as a whole on upgrade.

2. Registry access​

All images are pulled from the Innovatrics registry registry.dot.innovatrics.com — Face Matcher images from the vpp/ project, corridor images (corridor-foundation-service, corridor-identity-grouping-service, biometriccorridor, the MCT services) from the border-control/ project. Access is granted through a robot account — one dedicated account per client, scoped to the products you are entitled to, with no expiration — provided from the Innovatrics Customer Portal:

docker login registry.dot.innovatrics.com -u '<robot-account-name>' -p '<token>'

Use the robot account name and token exactly as provided in the Customer Portal. The login persists in ~/.docker/config.json.

3. Obtain a license​

The stack requires one iengine.lic file tied to the hardware of the host. Get the hardware ID by running the license-manager image:

docker run --rm registry.dot.innovatrics.com/vpp/license-manager:3.2.7

Provide the printed hardware ID when requesting a license from the Customer Portal. The same file licenses Face Matcher and — through its smart_corridor block — the corridor services, so make sure the request covers both. Place it at:

./secrets/iengine.lic

For the details of Face Matcher licensing, see Get a License.

4. Configure the environment​

Two files drive the corridor configuration (Face Matcher keeps its own .env inside face-matcher/):

  • .env — corridor image versions and the dashboard port (default 8095). Use the version values from your release notes.
  • .env.hub — Hub wiring: VPP_ADAPTER_ALLOWED_WATCHLISTS (watchlist IDs that grant GREEN clearance), the FOUNDATION_UNITS_0_* unit/camera definitions, and the storage settings for face crops.

Face-crop images are kept in the shared S3 store (SeaweedFS, host port 8333). If thumbnails do not load in the browser, check that the S3 address configured in .env.hub is reachable from the officer's workstation, not only from inside the Docker network.

5. Run the stack​

start.sh starts Face Matcher from face-matcher/ first, then the corridor services:

bash start.sh

6. Verify​

When the script finishes, these endpoints are available on the host:

ServiceURL
Corridor dashboardhttp://localhost:8095
Hub GraphQLhttp://localhost:8090/corridor-foundation/graphql
Hub GraphiQL explorerhttp://localhost:8090/corridor-foundation/graphiql
CIGS healthhttp://localhost:8096/actuator/health
Face Matcher Stationhttp://localhost:8000
Face Matcher REST APIhttp://localhost:8098
Face Matcher GraphQLhttp://localhost:8097/graphql
MCT Visualizer (only with MCT)http://localhost:8004

Supporting services with development-default credentials (change them before production): RabbitMQ http://localhost:15672 (guest / guest), SeaweedFS S3 http://localhost:8333 (admin / admin), pgAdmin http://localhost:7070 (admin@admin.com / Test1234). The full port list is in Network Ports and Network Topology.

Open the GraphiQL explorer, or check container status:

docker compose ps
docker compose logs <service-name>

Stopping and resetting​

bash stop.sh # stop all services, keep data
bash factory-reset.sh # stop and wipe all containers, images, and volumes

Next steps​