Skip to main content

BriefCam White Papers

BriefCam on Azure white paper

Last Updated: 5 minute read
Version2024r2
LanguageEnglish

This document presents the recommended deployment architecture for BriefCam in the Azure cloud. The deployment strategy relies on IAAS (Infrastructure-as-a-Service), which means using standard infrastructure components in the Azure public cloud (compute, network, and storage).

Disclaimer

The information provided in this document contains some of the possibilities of integrating between BriefCam and Azure and is provided as general guidelines only.

BriefCam advises using professional services, such as system integrators, who have the knowledge and can produce the best results based on the type of network, system architect, bandwidth limitations, and other factors.

Recommended Architecture

The architecture below presents an example deployment of a distributed version of BriefCam in Azure. You can use this diagram as a baseline to plan your specific Azure architecture, considering your system sizing and cost considerations.

This example distributes BriefCam’s components to separate EC2 instances (VS Server, Fetching, Processing, and so on). In smaller scale systems, some of these components can reside on the same EC2 instance. To plan the right architecture that meets your performance requirements, contact your sales manager or BriefCam’s support.

BriefCam Azure deployment.png

Connecting the Azure Cloud with Your On-premises Data Center

Video analytics platforms require a reliable stream of video to be transferred to the public cloud. Relying on public internet infrastructure is risky and can result in poor performance due to unpredictable latency and network fluctuations.

To solve this challenge, Azure provides the Azure ExpressRoute service, which provides a private connection between your on-premises infrastructure (or a colocation facility) and the cloud, bypassing the internet service provider.

It is highly recommended to use this service, and crucial if you plan on using real-time video processing.

If required, you can configure a VPN tunnel between your data center and Azure.

Port Forwarding

If the user is behind a firewall, proper port forwarding needs to be done on the customer site. This will allow connectivity from an Azure machine to a machine behind a firewall (and vice-versa). The steps that need to be done are different for each type of firewall.

Virtual Network Infrastructure

The following describe in detail the recommended Azure components.

  • Azure VPN Gateway

    A VPN gateway allows communication between your VNet and the internet.

  • Subnets

    The recommended network architecture separates BriefCam into public and private subnets (as presented in the above diagram). All the incoming traffic goes through an Application Gateway, and all of the outgoing traffic goes through the NAT gateway.

  • Azure NAT Gateway

    If you decide to use a private subnet, you may optionally deploy a NAT gateway to allow outbound internet communication from your private subnet.

  • Azure Application Gateway

    An Application Gateway is highly advised from both a security aspect and scalability.

    Configure your gateway to handle HTTPS encryption and add a WAF (Web Application Firewall) to restrict incoming traffic to your BriefCam environment.

    The gateway can distribute traffic to multiple instances of BriefCam’s Web Services or RESEARCH as needed.

Compute Infrastructure

BriefCam’s compute instances can be separated into:

  • GPU-based instances – Windows 2022 or 2019 Servers with NVIDIA GPUs.

    You can use one of the Azure NV-Series, based on your environment sizing considerations.

Type

GPU

GPU Spec

vCPUs

Memory (GB)

GPU Memory

Standard_NV6

1

NVIDIA Telsa M60

6

56

8

Standard_NV12

2

NVIDIA Telsa M60

12

112

16

Standard_NV24

4

NVIDIA Telsa M60

24

224

32

  • Regular instances– For the VS Server, PostgreSQL, fetching and for instances that do not require a GPU, you can select one of the general-purpose Windows 2022 Servers or Windows 2019 Servers that match BriefCam’s hardware sizing requirements. See the VMS Series section below.

    Optionally, it is recommended to use memory optimized instances to achieve improved performance.

All your instances must be associated with persistent HDD/SSD disks, as defined in your sizing document.

Storage

For a shared file storage you can use one of the following two solutions:

  1. Azure Files – Azure Files for Windows File Server provides fully managed, highly reliable, and scalable file storage that is accessible over the industry-standard Server Message Block (SMB) protocol. Read more at: https://azure.microsoft.com/en-us/products/storage/files.

  2. SSD disk – A mounted SSD disk connected to one of your instances and shared in your VNet. The shared folder needs to be accessible by all BriefCam servers.

Azure Files can provide better redundancy, and it is recommended if your BriefCam deployment is considered mission critical.

VM Series

In Azure, there are several VM series available, each of which is tailored towards different workload types.

Here's a brief overview of the different series:

D-series: These VMs are general-purpose and have a balance of memory and CPU resources, making them suitable for most applications.

E-series: These VMs are optimized for in-memory hyper-threaded applications, and offer a high memory-to-core ratio. These are suitable for relational database servers, medium to large caches, and in-memory analytics.

F-series: These VMs are compute-optimized and have a high core-to-memory ratio, making them suitable for compute-intensive applications.

L-series: These VMs are storage-optimized, and are ideal for applications that require low latency, high throughput, and high IOPS.

Additional References

The Azure B2C Integration section in the BriefCam Administrator GuideAzure B2C Integration (Deprecated)