Building an Automated Video Analytics System: Deploying Kerberos.io on VPS for RTSP Security Cameras
Introduction to Smart Video Surveillance
In the era of digital transformation, traditional video surveillance is undergoing a massive shift. Passive recording is no longer sufficient for modern security and operational needs. Businesses today require automated video analytics—systems that can detect anomalies, track objects, and trigger real-time alerts without human intervention. However, commercial enterprise solutions often come with prohibitive licensing fees and restrictive vendor lock-ins.
Fortunately, open-source ecosystems offer a powerful, cost-effective alternative. By deploying Kerberos.io on a Virtual Private Server (VPS), you can construct a centralized, highly scalable video analytics pipeline using your existing RTSP (Real-Time Streaming Protocol) IP cameras. This guide provides a comprehensive, step-by-step blueprint to architecture, deploy, and optimize this system for business-grade reliability.
Understanding the Architecture: Kerberos.io and RTSP
Before diving into the deployment phase, it is crucial to understand how the components interact within this architecture. The system relies on three primary layers:
- The Edge Layer (IP Cameras): Your on-premise security cameras capture video and broadcast it over the network using the standardized RTSP protocol.
- The Processing Layer (VPS & Kerberos.io): A cloud-based VPS hosts the Kerberos.io ecosystem, which continuously pulls the RTSP streams, processes the frames, and executes motion detection algorithms.
- The Storage & Notification Layer: Validated events, images, and video clips are saved to cloud storage or local directories, while webhooks trigger immediate notifications to external business communication tools.
Architectural Advantage: By offloading the video processing to a cloud VPS, you eliminate the need for expensive, high-maintenance on-site hardware, ensuring high availability and secure off-site backup.
Prerequisites and System Requirements
To ensure a smooth installation and stable performance, your VPS environment should meet or exceed the following specifications, depending on the number of concurrent camera streams:
- Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS (Clean installation recommended).
- Hardware Specs (for 2-4 HD Streams): Minimum 2 vCPUs, 4GB RAM, and 40GB SSD storage. High-frequency CPUs are preferred as video decoding is CPU-intensive.
- Network: A static IPv4 address with a minimum of 100 Mbps bandwidth to handle inbound RTSP traffic smoothly.
- Software: Docker and Docker Compose installed on the host system to simplify container management.
Step 1: Preparing Your VPS and Network
First, access your VPS via SSH and update the system packages to their latest versions. Run the following commands in your terminal:
sudo apt update && sudo apt upgrade -y
Next, ensure your firewall is configured to allow access to the Kerberos.io web interface (typically port 80 or 443 via a reverse proxy) while keeping your RTSP ingress secure. If you use UFW, configure it as follows:
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
Step 2: Installing Docker and Docker Compose
Kerberos.io is highly containerized, making Docker the optimal deployment vector. Install Docker using the official repository script:
curl -fsSL [https://get.docker.com](https://get.docker.com) -o get-docker.sh
sudo sh get-docker.sh
Verify that Docker is active and running smoothly:
sudo systemctl status docker
Step 3: Deploying Kerberos.io Open Source (Agent)
Kerberos.io operates primarily through two variants: the standalone Kerberos Agent and the enterprise-level Kerberos Factory/Hub. For a standard business infrastructure, deploying the Kerberos Agent per camera or utilizing Docker Compose for multi-camera management is the most effective approach.
Create a dedicated directory for your deployment and navigate into it:
mkdir -p ~/kerberos-analytics && cd ~/kerberos-analytics
Create a docker-compose.yml file to define the Kerberos environment:
nano docker-compose.yml
Paste the following structural configuration into the file:
version: '3.8'
services:
kerberos-camera1:
image: kerberos/agent:latest
container_name: kerberos_agent_cam1
ports:
- "8080:80"
volumes:
- ./config/cam1:/etc/kerberosio/config
- ./capture/cam1:/etc/kerberosio/capture
environment:
- TZ=Asia/Ho_Chi_Minh
restart: always
Save and close the file, then initiate the container in detached mode:
docker-compose up -d
Step 4: Configuring the RTSP Stream & Motion Analytics
Once the container is initialized, open your web browser and navigate to http://your_vps_ip:8080. You will be greeted by the initial Kerberos.io setup wizard.
Connecting the RTSP Source
In the configuration panel, select IP Camera (RTSP) as your stream type. You will need to input the exact RTSP URL format provided by your camera manufacturer. A standard format typically resembles:
rtsp://username:password@camera_ip_address:554/stream1
Note: Ensure your on-premise router has port forwarding or a secure VPN tunnel (like WireGuard) configured so your cloud VPS can safely reach the camera's internal IP address.
Optimizing Motion Detection and Regions of Interest (ROI)
To eliminate false positives caused by passing clouds, wind, or small animals, utilize the Region of Interest (ROI) matrix within the Kerberos dashboard. This feature allows you to draw a specific mask over critical zones—such as entryways, cash registers, or perimeter fences. Only pixel changes within these specified boundaries will trigger a recording or analytical alert.
Step 5: Scaling with Advanced Automation and Webhooks
The true power of an automated analytics system lies in its ability to communicate with other business applications. Within the Kerberos.io configuration settings, navigate to the Notifications tab.
You can configure Webhooks to send a JSON payload to a custom API endpoint, a Node-RED workflow, or automation platforms like Make/Zapier whenever motion is verified. For instance, an alert can instantly push a snapshot of the event directly to a corporate Slack or Telegram channel, enabling real-time security monitoring.
Security Best Practices for Cloud Video Deployment
Exposing video feeds to the cloud requires stringent security protocols. Protect your infrastructure by adhering to these essential security measures:
- Implement SSL/TLS: Never access your dashboard over unencrypted HTTP. Use a reverse proxy like Nginx Proxy Manager or Caddy along with Let's Encrypt to enforce HTTPS.
- Strong Authentication: Change all default credentials immediately upon setup and use complex, non-repeating passwords for both your cameras and your Kerberos dashboard.
- Isolate Traffic via VPN: Instead of opening your camera's RTSP ports to the public internet, establish a secure Site-to-Site VPN between your local network and the VPS.
Conclusion
Deploying an automated video analytics system by leveraging Kerberos.io on a VPS offers an enterprise-level solution without the enterprise price tag. It grants businesses full sovereignty over their data, eliminates recurring subscription model traps, and converts standard security infrastructure into proactive analytical tools. By following this deployment framework, your organization will gain actionable insights and enhanced situational awareness, driving both security and operational efficiency forward.
