Five components that ship as one product:
- behavision/ the recognition engine. RTSP ingest, YuNet detection, IoU
tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
FastAPI dashboard. Identity is decided once per TRACK from an
average of at least three embeddings, never per frame.
- agent/ the Go edge agent: supervises the engine, holds a durable
spool, and drains it to MQTT. Nothing is acked before the
broker confirms.
- desktop/ the shop PC application (Wails + React + tray).
- server/ the cloud API, MQTT consumer, reports and assistant.
- web/ platform.loyaly.ai, the head-office app, embedded in the
server binary.
The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.
CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
27 lines
1.1 KiB
Docker
27 lines
1.1 KiB
Docker
# Two stages: the runtime image carries the binary and nothing else.
|
|
# Must match the `go` directive in go.mod. A lower builder fails with
|
|
# "go.mod requires go >= X" because GOTOOLCHAIN=local inside the image - the
|
|
# local build hid this by silently downloading a newer toolchain.
|
|
FROM golang:1.25-alpine AS build
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
ARG VERSION=dev
|
|
# CGO off gives a static binary, which is what makes the scratch-like runtime
|
|
# below possible and removes the whole class of glibc/musl surprises.
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath \
|
|
-ldflags "-s -w -X main.version=${VERSION}" \
|
|
-o /out/behavision-server ./cmd/behavision-server
|
|
|
|
FROM alpine:3.20
|
|
# ca-certificates for outbound TLS (object storage, webhooks). tzdata because
|
|
# footfall is reported in each site's local time and the container's default
|
|
# UTC-only image would make every report an hour or more wrong.
|
|
RUN apk add --no-cache ca-certificates tzdata && \
|
|
adduser -D -u 10001 behavision
|
|
COPY --from=build /out/behavision-server /usr/local/bin/behavision-server
|
|
USER behavision
|
|
EXPOSE 8080
|
|
ENTRYPOINT ["/usr/local/bin/behavision-server"]
|