Troubleshooting
Debug along the pipeline, upstream to downstream: camera → Face Matcher → VPP Adapter and CIGS → Hub → consumer. At each stage there is one question — does data come out of it? — and docker compose logs <service> answers most of them (run it in face-matcher/ for the Face Matcher services, in the package root for the corridor services). Station at http://localhost:8000 is the fastest way to see whether Face Matcher itself is healthy; the classes below cover the common first-deployment failures.
Nothing deploys or images won't pull
Registry authentication is the usual cause: the Innovatrics registry registry.dot.innovatrics.com needs a successful docker login with your robot account before the first start.sh — re-check registry access. A stack that starts but has Face Matcher services crash-looping typically has a missing or host-mismatched iengine.lic in secrets/; corridor services that start but refuse to work with a valid Face Matcher usually miss the smart_corridor block in that same license.
Camera connected, no detections
Confirm Face Matcher actually consumes the stream: the camera must be registered in Station with a reachable RTSP URL, from inside the containers — a URL that works from your laptop can be unroutable from the Docker network (RTSP URLs and masking). If Face Matcher sees video but detects nothing, faces are probably too small or the frame rate dropped below usable levels in low light; re-check the numbers in Camera Selection & Placement.
Detections in Face Matcher, no events at the Hub
Check the wiring between the layers: the camera's Face Matcher ID must be listed on a unit in FOUNDATION_UNITS_0_CAMERAS, and the Hub (with its VPP Adapter), CIGS and the RabbitMQ broker must be healthy — CIGS reports at http://localhost:8096/actuator/health. Events for a camera not assigned to any unit go nowhere by design. The RabbitMQ biometric_events exchange is the internal seam — adapter logs on one side, Hub logs on the other localize the break.
Events flow, but clearance looks wrong
Green/red clearance depends on watchlist wiring: an allowed watchlist not listed in VPP_ADAPTER_ALLOWED_WATCHLISTS produces plain identification.match instead of identification.clearance.green — revisit Add People to Watchlists. Frequent condition_violation events point at obscured faces or capture conditions, and matching-quality issues belong to Tuning Identification.
Thumbnails missing on the dashboard
Face crops are served from the shared S3 store (SeaweedFS on port 8333). If events show but images do not, the officer's browser cannot reach the S3 address configured in .env.hub — see First Deployment.