Mô hình triển khai

Mỗi địa điểm có một máy luôn bật cùng LAN với camera. go2rtc và AI chỉ nghe trên localhost; Cloudflare Tunnel chỉ đưa relay đã xác thực ra ngoài. Khách đăng nhập SaaS và nhận URL WebRTC ký ngắn hạn, không dùng Google Cloudflare Access.

Free
1 viewer/camera
Pro
5 viewers/camera
Clip
R2; live qua WebRTC

1. Chuẩn bị máy tại site

  • macOS hoặc Linux 64-bit, chạy 24/7, ưu tiên Ethernet.
  • Node.js 20+, Git, Python 3.10+ với venv, curl; Linux cần sudo.
  • Camera đã bật RTSP + ONVIF, có IP cố định/DHCP reservation và tài khoản riêng.
  • Outbound HTTPS/WSS tới Cloudflare, GitHub và dashboard; không mở port router.
  • MVP yêu cầu nhập IP camera, chưa tự động quét camera trong LAN.
Repo private: tạo GitHub deploy key chỉ-đọc cho từng máy site. Không chép PAT cá nhân lên máy khách.

2. Cài đặt

Đăng ký public key của máy trong GitHub Repository → Settings → Deploy keys, không bật quyền write.

ssh-keygen -t ed25519 -C cameraai-site -f "$HOME/.ssh/cameraai_deploy" -N ''
cat "$HOME/.ssh/cameraai_deploy.pub"

git clone --depth 1 [email protected]:nhannguyenalien/cameraaiwork.git
cd cameraaiwork
[email protected]:nhannguyenalien/cameraaiwork.git \
CAMERAAIWORK_API=https://cameraaiwork.pages.dev \
./apps/relay/install.sh

Installer hỏi API key account, tên site, IP/ONVIF camera; sau đó đăng ký site, tạo Named Tunnel và cài go2rtc, relay, AI thành service.

3. Kiểm tra

macOS
launchctl list | grep cameraaiwork
tail -n 100 /tmp/cameraaiwork-relay.log
curl -fsS http://127.0.0.1:1984/api/streams
curl -fsS http://127.0.0.1:4000/health
Linux
systemctl --no-pager --full status cameraaiwork-go2rtc cameraaiwork-relay cameraaiwork-ai
journalctl -u cameraaiwork-relay -n 100 --no-pager
curl -fsS http://127.0.0.1:1984/api/streams
curl -fsS http://127.0.0.1:4000/health

Trên dashboard, test theo chuỗi: camera xuất hiện → live → PTZ rồi stop → motion event → AI → clip R2 → Telegram.

API cho AI agent

Nạp /openapi.yaml làm tool schema. Token phải nằm trong secret store và gửi qua Authorization: Bearer.

export CAMERAAI_API='https://cameraaiwork.pages.dev'
export CAMERAAI_TOKEN='account-session-key'
curl -fsS "$CAMERAAI_API/api/cameras" \
  -H "Authorization: Bearer $CAMERAAI_TOKEN"
Account token hiện có toàn quyền. Agent phải mặc định chỉ đọc và xin xác nhận người dùng trước thao tác có nhãn x-agent-risk destructive, financial hoặc secret-write. Không tự retry POST tạo site/tunnel/job.

Production checklist

Interactive API reference