Files
Behavision/server/Dockerfile
Suriyakumarvijayanayagam dad04e8cda Behavision: face recognition for retail, edge to head office
Five components that ship as one product:

- behavision/  the recognition engine. RTSP ingest, YuNet detection, IoU
               tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
               FastAPI dashboard. Identity is decided once per TRACK from an
               average of at least three embeddings, never per frame.
- agent/       the Go edge agent: supervises the engine, holds a durable
               spool, and drains it to MQTT. Nothing is acked before the
               broker confirms.
- desktop/     the shop PC application (Wails + React + tray).
- server/      the cloud API, MQTT consumer, reports and assistant.
- web/         platform.loyaly.ai, the head-office app, embedded in the
               server binary.

The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.

CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
2026-09-04 11:14:18 +05:30

27 lines
1.1 KiB
Docker

# Two stages: the runtime image carries the binary and nothing else.
# Must match the `go` directive in go.mod. A lower builder fails with
# "go.mod requires go >= X" because GOTOOLCHAIN=local inside the image - the
# local build hid this by silently downloading a newer toolchain.
FROM golang:1.25-alpine AS build
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
ARG VERSION=dev
# CGO off gives a static binary, which is what makes the scratch-like runtime
# below possible and removes the whole class of glibc/musl surprises.
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath \
-ldflags "-s -w -X main.version=${VERSION}" \
-o /out/behavision-server ./cmd/behavision-server
FROM alpine:3.20
# ca-certificates for outbound TLS (object storage, webhooks). tzdata because
# footfall is reported in each site's local time and the container's default
# UTC-only image would make every report an hour or more wrong.
RUN apk add --no-cache ca-certificates tzdata && \
adduser -D -u 10001 behavision
COPY --from=build /out/behavision-server /usr/local/bin/behavision-server
USER behavision
EXPOSE 8080
ENTRYPOINT ["/usr/local/bin/behavision-server"]