Back to articles
Technology Insight

Building an Automated Video Analytics System from RTSP Security Cameras: A Guide to Deploying Kerberos.io on a VPS Server

May 29, 2026

Introduction to Enterprise Video Analytics

In the contemporary security landscape, standard video surveillance is no longer sufficient. Traditional Closed-Circuit Television (CCTV) systems act as passive recorders, generating massive volumes of footage that require manual, retroactive review. For modern enterprises, the real value lies in proactive, real-time intelligence. An automated video analytics system transforms these passive streams into actionable data insights, enabling immediate threat detection, operational monitoring, and automated event triggering.

Implementing an enterprise-grade surveillance system historically required expensive proprietary hardware and restrictive licensing agreements. However, open-source technology combined with cloud infrastructure has democratized this domain. By deploying Kerberos.io—a powerful, low-latency open-source video analytics solution—on a robust Virtual Private Server (VPS), organizations can build a centralized, highly scalable, and cost-effective monitoring hub. This architecture allows companies to leverage their existing Real-Time Streaming Protocol (RTSP) IP cameras while unlocking advanced intelligence features without vendor lock-in.

Architectural Overview: RTSP, Kerberos.io, and VPS

Before diving into the technical implementation, it is critical to understand how the components interact within this automated analytics ecosystem:

  • The Edge Layer (RTSP Cameras): Local IP security cameras compress live video feeds and broadcast them over the local network using the Real-Time Streaming Protocol (RTSP). These cameras handle the primary optics and hardware encoding (typically H.264 or H.265).
  • The Network Layer (Secure Tunneling): Because the analytics engine resides on a remote cloud VPS, the local RTSP streams must be securely routed over the internet. This is achieved via a secure Virtual Private Network (VPN), an encrypted reverse proxy, or firewall port forwarding.
  • The Analytics and Processing Hub (Kerberos.io on VPS): The VPS acts as the cloud engine. Kerberos.io ingests the secure RTSP streams, executes continuous video processing algorithms, handles motion and heuristic analysis, and structures the metadata for long-term storage or immediate alerting.

By shifting processing from local hardware to a cloud-hosted VPS, enterprises achieve centralization. Multiple geographic sites can stream back to a singular dashboard, simplifying administration and data aggregation.

Prerequisites and System Requirements

To ensure optimal performance, low latency, and high reliability, the destination VPS and network infrastructure must meet specific baseline requirements. Video decoding and analytics are compute-intensive tasks, heavily relying on CPU capabilities and fast disk I/O.

1. VPS Hardware Recommendations (Per 3-4 Camera Streams)

  • CPU: Minimum 2 vCPUs (Compute-optimized instances are highly recommended).
  • RAM: At least 4 GB of dedicated RAM to handle concurrent stream caching.
  • Storage: 40 GB to 100 GB NVMe SSD storage. Storage scale depends heavily on retention policies for video clips and analytical metadata.
  • Network Bandwidth: Unmetered or high-capacity network plans (minimum 100 Mbps port speed) to prevent ingress bottlenecks from multiple high-definition streams.

2. Software and Environment Prerequisites

The host server should ideally run a clean installation of a stable Linux distribution, such as Ubuntu Server 22.04 LTS or Debian 12. Additionally, the system requires a working installation of Docker and Docker Compose, as containerization is the preferred and most reliable deployment method for modern cloud applications.

Step-by-Step Deployment Guide

Follow this structured, sequential technical process to provision your environment, deploy the Kerberos.io engine, and link your first RTSP asset.

Step 1: Preparing and Securing the VPS

Initial server setup must prioritize security, especially since the server will be exposed to incoming video traffic. Connect to your VPS via SSH and perform standard baseline maintenance:

sudo apt update && sudo apt upgrade -y

Next, configure the Uncomplicated Firewall (UFW) to permit secure shell access, standard web traffic, and the dedicated streaming ports needed by Kerberos.io:

sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 8080/tcp
sudo ufw enable

Step 2: Installing Docker and Docker Compose

Kerberos.io utilizes a microservices architecture best managed via containerization. Install the official Docker engine with the following command sequence:

sudo apt install apt-transport-https ca-certificates curl software-properties-common -y
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.p/docker.list > /dev/null
sudo apt update && sudo apt install docker-ce docker-ce-cli containerd.io -y

Verify that the Docker service is running actively on the system initialization layer:

sudo systemctl status docker

Step 3: Orchestrating Kerberos.io Open Source (Agent)

Create a dedicated directory structure for the Kerberos agent configuration and recording artifacts to ensure persistent storage mappings survive container restarts:

mkdir -p ~/kerberos-analytics/config
mkdir -p ~/kerberos-analytics/recordings
cd ~/kerberos-analytics

Construct a docker-compose.yml deployment blueprint using a text editor such as Nano. This layout explicitly maps the networking ports, configures self-healing restart policies, and anchors the physical recording paths onto your VPS file system:

version: '3.8'
services:
  kerberos-agent:
    image: kerberos/agent:latest
    container_name: kerberos_analytics_agent
    restart: unless-stopped
    ports:
      - "8080:80"
    volumes:
      - ./config:/etc/kerberosio/config
      - ./recordings:/etc/kerberosio/capture
    environment:
      - TZ=Etc/UTC

Execute the stack orchestration in detached mode to launch the processing server background tasks:

sudo docker-compose up -d

Step 4: Connecting the RTSP Stream Assets

Open a web browser and navigate to your server IP address on the designated port (e.g., http://your_vps_ip:8080). Follow the initial on-screen wizard to create your master administrator credentials. Once authenticated, access the configuration console to establish connection with your camera:

  1. Navigate to the Configuration panel and select Stream Source.
  2. Choose RTSP IP Camera from the source dropdown selector.
  3. Input your absolute RTSP stream URI. The structure typically conforms to the standard authentication format: rtsp://username:password@camera_ip_address:554/stream_path.
  4. Adjust the target frame rate and resolution metrics to match the performance profile of your VPS. Click Save Changes to initialize the live media pipeline.

Configuring Advanced Analytics and Enterprise Alerts

With the primary video connection verified, you can configure the system's core value driver: automated processing. Within the configuration interface, access the Heuristics and Conditions matrix. Here, administrators can define a distinct visual Region of Interest (ROI). By utilizing an overlay grid, you can mask high-traffic peripheral areas—such as moving trees or public roadways—ensuring the analytics engine only evaluates specific critical boundaries, such as shipping docks, secure entryways, or sensitive facility perimeters.

Furthermore, Kerberos.io excels at downstream webhook orchestration. Within the Notifications hub, you can wire processing triggers directly to company communications infrastructure. When the engine detects unauthorized boundary entries, it can fire JSON payloads to remote endpoints, instantly generating critical notifications inside corporate messaging spaces like Slack or Microsoft Teams, opening critical IT support tickets, or logging events into an enterprise Security Information and Event Management (SIEM) dashboard.

Strategic Evaluation: Cost and Operational Benefits

Implementing an open-source analytics platform hosted on virtual cloud infrastructure presents clear financial and operational advantages when compared to traditional on-premise hardware paradigms:

  • Elimination of Capital Expenditures (CapEx): Instead of procuring specialized on-site physical servers, high-end network video recorders (NVRs), and expensive proprietary analytics cards, organizations shift their monitoring expenses entirely to a predictable, highly scalable Operating Expense (OpEx) framework.
  • Unbounded Scalability: Physical setups are constrained by fixed hardware ports and localized processing limits. Conversely, if your facility expands or introduces additional RTSP assets, scaling up merely requires a few clicks within the cloud management portal to allocate extra vCPUs and NVMe storage allocations to the VPS instantly.
  • Data Sovereignty and Control: Unlike turnkey commercial cloud cameras that lock security data behind opaque proprietary networks, this VPS implementation gives your IT department complete, uninhibited custody over all historical footage, log archives, and analytical metadata.

Conclusion

Building an automated video analytics system by deploying Kerberos.io on a cloud-based VPS is a highly efficient way to unlock enterprise-grade intelligence from standard security cameras. By leveraging open-source processing layers alongside flexible virtualized infrastructure, businesses can maximize their security investments, achieve deep situational awareness, and build a scalable framework ready to handle future operational requirements.

Building an Automated Video Analytics System from RTSP Security Cameras: A Guide to Deploying Kerberos.io on a VPS Server | DPTCloud