A Modern AI-Powered Student Management Platform with Face Authentication, Attendance, Academic Analytics, Assignments, Mock Examinations, and Microservices Architecture.
Overview β’ Highlights β’ Architecture β’ Screenshots β’ Installation β’ Docker β’ Kubernetes β’ License
- π Project Overview
- β¨ Highlights
- ποΈ Architecture Diagram
- πΌοΈ Screenshots
- π Monorepo Explanation
- π» Technology Stack
- π¨ Frontend Architecture
- βοΈ Backend Architecture
- π§ AI Service Architecture
- ποΈ Database Architecture
- π‘οΈ Security Architecture
- π Feature Matrix
- π‘ API Overview
- βοΈ Environment Variables
- π οΈ Installation Guide
- π³ Docker Deployment Details
- βΈοΈ Kubernetes Deployment Overview
- π Performance Highlights
- π£οΈ Future Roadmap
- π License
- π Author & Acknowledgements
The Student Management System (SMS) is a modern, secure, AI-powered student administration platform designed for schools, colleges, universities, and educational institutions. Built using a scalable monorepo architecture, it integrates biometric Multi-Factor Authentication (MFA), deepfake-resistant facial verification, AI-powered student analytics, GPS-based attendance, assignment management, mock examinations, and academic performance prediction into a single unified platform.
Designed around security, scalability, reliability, and modern cloud-native principles, the system combines multiple independent microservices behind an Nginx reverse proxy while maintaining resilient degraded-mode operation to ensure continuous availability even when supporting services become unavailable.
The platform is divided into three primary autonomous services:
-
Frontend
- React
- TypeScript
- TailwindCSS
- Framer Motion
-
Backend API
- Node.js
- Express
- PostgreSQL
- Redis
- Socket.IO
-
Face AI Service
- Python
- Flask
- PyTorch
- OpenCV
- MediaPipe
- ArcFace
Together these services provide secure authentication, intelligent attendance management, AI-assisted academic analysis, assignment workflows, administrative controls, and real-time monitoring.
- β‘ Resilient Degraded Mode Architecture allowing uninterrupted operation even if Redis or the AI service becomes temporarily unavailable.
- π€ AI Face Authentication powered by ArcFace embeddings with multi-frame verification.
- 𧬠Advanced Anti-Spoof Detection using optical flow, FFT analysis, texture analysis, glare detection, landmark stability, and deepfake detection.
- π‘οΈ Zero Trust Security Model with JWT rotation, AES-256-GCM encrypted embeddings, MFA, device validation, and rate limiting.
- π GPS Geofencing Attendance using PostgreSQL spatial validation and the Haversine Formula.
- π Assignment Management System supporting assignment creation, submission, grading, and feedback workflows.
- π Mock Examination Module with configurable negative marking and automatic result generation.
- π Student Marks Prediction using AI models trained on attendance, assignment completion, academic history, study habits, and mock examination performance.
- π¨βπ« Teacher Management Dashboard providing complete classroom administration and academic monitoring.
- π¨βπ Student Dashboard offering attendance history, assignments, examinations, notifications, and academic insights.
- π¨βπΌ Administrator Control Panel for complete institution management.
- π‘ Microservices Architecture enabling independent deployment and scaling.
- βΈοΈ Kubernetes Ready with production-grade deployment manifests.
- π³ Dockerized Infrastructure supporting local development and production deployments.
- π Observability Stack with Prometheus, Grafana, Loki, OpenTelemetry, and centralized logging.
- π Production Ready Authentication Pipeline supporting password login, face authentication, MFA, refresh token rotation, and recovery workflows.
graph TD
User([Browser / Mobile Client]) -->|HTTPS 80/443| Nginx[Nginx Reverse Proxy & TLS Gateway]
subgraph Student Management System
Nginx -->|Proxy: /| Frontend[React + TypeScript Frontend]
Nginx -->|Proxy: /api| Backend[Node.js Express Backend]
Nginx -->|Proxy: /api/register-face| AIService[Python Flask Face AI Service]
Backend -->|REST API| AIService
Backend -->|Cache & Queue| Redis[(Redis)]
AIService -->|Session State| Redis
Backend -->|Read / Write| DB[(PostgreSQL Main Database)]
Backend -->|Read / Write| FaceDB[(PostgreSQL Face Database)]
end
classDef frontend fill:#e3f2fd,stroke:#1565c0,stroke-width:2px;
classDef backend fill:#f1f8e9,stroke:#558b2f,stroke-width:2px;
classDef storage fill:#fff3e0,stroke:#ef6c00,stroke-width:2px;
classDef ai fill:#f3e5f5,stroke:#6a1b9a,stroke-width:2px;
class Frontend frontend;
class Backend backend;
class DB,FaceDB,Redis storage;
class AIService ai;
The Student Management System follows a modular monorepo architecture where every service is isolated while remaining tightly integrated through secure APIs and shared infrastructure. This architecture simplifies maintenance, encourages code reuse, and enables independent scaling of services.
Student-Management-System
β
βββ frontend/
βββ backend-api/
βββ face-ai-service/
βββ database/
βββ nginx/
βββ docs/
βββ screenshots/
βββ terraform/
βββ helm/
βββ k8s/
βββ docker-compose.yml
βββ docker-compose.prod.yml
βββ README.md
Contains the complete React + TypeScript application.
Responsibilities include
- User Interface
- Authentication
- Dashboards
- Attendance
- Assignment Portal
- Mock Exams
- Student Analytics
- Charts
- Notifications
Uses
- React
- TypeScript
- TailwindCSS
- Zustand
- React Router
- Framer Motion
Acts as the central orchestration layer.
Responsibilities
- Authentication
- Authorization
- RBAC
- REST APIs
- Attendance
- Assignment Management
- Mock Exams
- Marks Prediction
- Notifications
- Audit Logging
- Rate Limiting
- Background Jobs
Dedicated AI microservice responsible for
- Face Detection
- Face Alignment
- Face Recognition
- Anti Spoofing
- Deepfake Detection
- Liveness Verification
- ArcFace Embedding Generation
Contains
- SQL Schema
- Migrations
- Triggers
- Seed Data
- Constraints
- Functions
- Stored Procedures
Provides
- Reverse Proxy
- SSL Termination
- Static Asset Hosting
- API Routing
- Load Balancing
Infrastructure provisioning
- Cloud Resources
- Networking
- Security Groups
- Compute
- Storage
Helm Charts for Kubernetes deployments.
Production Kubernetes manifests
- Deployments
- Services
- ConfigMaps
- Secrets
- Ingress
- Persistent Volumes
- Horizontal Pod Autoscalers
| Layer | Technologies | Description |
|---|---|---|
| Frontend | React, TypeScript, Vite, TailwindCSS, Framer Motion | Modern responsive web application |
| Backend | Node.js, Express, Socket.IO, BullMQ | REST APIs, WebSockets, Background Processing |
| AI Service | Python, Flask, PyTorch, OpenCV, MediaPipe | Face Authentication & AI Processing |
| Databases | PostgreSQL, Redis | Persistent Storage & Caching |
| Containerization | Docker, Docker Compose | Development & Production Containers |
| Orchestration | Kubernetes, Helm | Production Deployment |
| Reverse Proxy | Nginx | Routing, SSL & Load Balancing |
| Infrastructure | Terraform | Infrastructure as Code |
| Monitoring | Prometheus, Grafana, Loki | Metrics, Logging & Dashboards |
| Observability | OpenTelemetry, Sentry | Distributed Tracing & Error Monitoring |
| Technology | Purpose |
|---|---|
| React | Frontend Framework |
| TypeScript | Type-safe Development |
| Node.js | Backend Runtime |
| Express | REST API Framework |
| PostgreSQL | Relational Database |
| Redis | Cache & Queue |
| Python | AI Processing |
| Flask | AI API |
| Docker | Containerization |
| Kubernetes | Orchestration |
| Nginx | Reverse Proxy |
| PyTorch | Deep Learning |
| MediaPipe | Facial Landmark Detection |
| ArcFace | Face Recognition |
| OpenCV | Computer Vision |
- Modular Monorepo
- Cloud Native
- AI Powered
- Secure by Design
- Zero Trust Authentication
- Microservices Architecture
- Event Driven Components
- Horizontal Scalability
- High Availability
- Production Ready
- Kubernetes Native
- Docker Optimized
The frontend is built using React, TypeScript, Vite, and TailwindCSS, providing a modern, responsive, and highly interactive user experience. It follows a modular component architecture with centralized state management, secure routing, and optimized bundle loading for production deployments.
- Component-Based Architecture
- Type-Safe Development using TypeScript
- Responsive Design
- Lazy Loading
- Optimistic UI Updates
- Secure Route Protection
- Reusable UI Components
- High Performance Rendering
| Technology | Purpose |
|---|---|
| React 18 | User Interface Framework |
| TypeScript | Static Type Checking |
| Vite | Fast Development & Production Builds |
| TailwindCSS | Utility-First CSS Framework |
| Zustand | Lightweight State Management |
| React Router | Client-side Routing |
| Framer Motion | Animations |
| Axios | HTTP Client |
| Socket.IO Client | Real-time Communication |
| Recharts | Data Visualization |
frontend/
β
βββ public/
βββ src/
β βββ api/
β βββ assets/
β βββ components/
β βββ hooks/
β βββ layouts/
β βββ pages/
β βββ routes/
β βββ services/
β βββ store/
β βββ styles/
β βββ types/
β βββ utils/
β βββ App.tsx
β
βββ vite.config.ts
βββ package.json
βββ tsconfig.json
- JWT Authentication
- Face Authentication Workflow
- Multi-Factor Authentication
- Session Persistence
- Token Refresh
- Protected Routes
Zustand manages
- Authentication State
- User Profile
- Attendance
- Notifications
- Dashboard Statistics
- Assignments
- Mock Exams
- Student Analytics
The application dynamically loads large modules to reduce initial bundle size.
Benefits include
- Faster Initial Load
- Smaller JavaScript Bundles
- Better Lighthouse Scores
- Improved User Experience
The application separates vendor bundles into optimized chunks including
- React
- Router
- Charts
- UI Libraries
- Networking
- Utility Libraries
This significantly improves browser caching and reduces download size for future updates.
Socket.IO powers
- Live Attendance Updates
- Notification Delivery
- Dashboard Statistics
- Assignment Status
- Administrative Events
Optimized for
- Desktop
- Laptop
- Tablet
- Mobile Devices
The backend serves as the central orchestration layer for the entire Student Management System. It exposes REST APIs, manages authentication, coordinates business logic, communicates with the AI service, processes background jobs, and maintains complete auditability across all operations.
- Authentication
- Authorization
- Role-Based Access Control (RBAC)
- Attendance Management
- Assignment Management
- Mock Examination Management
- Marks Prediction
- Notification Delivery
- Security Monitoring
- Audit Logging
- File Upload Management
- Background Processing
| Technology | Purpose |
|---|---|
| Node.js | Runtime |
| Express | REST API |
| PostgreSQL | Database |
| Redis | Cache |
| BullMQ | Job Queue |
| Socket.IO | Real-Time Communication |
| JWT | Authentication |
| Bcrypt | Password Hashing |
| Multer | File Uploads |
| Winston | Logging |
backend-api/
β
βββ src/
β βββ config/
β βββ middleware/
β βββ modules/
β βββ routes/
β βββ services/
β βββ utils/
β βββ websocket/
β βββ app.js
β
βββ uploads/
βββ package.json
βββ Dockerfile
Provides
- Login
- Logout
- Password Authentication
- Face Authentication
- Multi-Factor Authentication
- Password Recovery
- Refresh Tokens
Supports
- Check-In
- Check-Out
- GPS Verification
- Geofencing
- Attendance Reports
- Work Hour Calculations
Supports
- Assignment Creation
- Assignment Submission
- Teacher Feedback
- Grading
- File Uploads
Supports
- MCQ Exams
- Negative Marking
- Automatic Evaluation
- Score Generation
- Leaderboards
Provides
- Marks Prediction
- Attendance Analytics
- Academic Performance
- Risk Analysis
- Performance Trends
Redis queues handle
- Email Delivery
- Notifications
- Attendance Reports
- Scheduled Tasks
- Cleanup Jobs
- Analytics Generation
- Graceful Shutdown
- Automatic Recovery
- Degraded Mode
- Retry Policies
- Request Correlation IDs
- Structured Logging
- Health Checks
- Rate Limiting
The Face AI Service is a dedicated Python-based microservice responsible for secure biometric authentication, liveness verification, anti-spoof detection, deepfake analysis, and facial embedding generation. It operates independently from the backend while communicating through secure REST APIs, allowing AI workloads to scale separately from application services.
Camera Frames
β
βΌ
Face Detection
β
βΌ
Face Alignment
β
βΌ
Liveness Detection
β
βΌ
Anti-Spoof Analysis
β
βΌ
Deepfake Detection
β
βΌ
ArcFace Embedding Generation
β
βΌ
Similarity Comparison
β
βΌ
Authentication Decision
The service first detects and crops facial regions from incoming image frames using MTCNN or OpenCV-based detectors. Detected faces are aligned and normalized before downstream processing.
Detected faces are rotated and resized to standardized dimensions to ensure consistent embedding generation and minimize pose-related inaccuracies.
The system validates that a real person is present by analyzing:
- Eye Blink Detection
- Head Movement
- Facial Landmark Stability
- Eye Aspect Ratio (EAR)
- Temporal Motion Patterns
MediaPipe Face Mesh is used to continuously monitor facial landmarks across multiple captured frames.
Multiple computer vision techniques are fused together to detect presentation attacks including printed photos, mobile screens, tablets, replay attacks, and masks.
Detection techniques include:
- Local Binary Pattern (LBP)
- Fast Fourier Transform (FFT)
- Optical Flow Analysis
- Sobel Gradient Entropy
- HSV Glare Detection
- LAB Color Variance
- Landmark Stability
- Motion Consistency
The AI evaluates structural facial consistency to detect manipulated or AI-generated faces by analyzing:
- Landmark Jitter
- Facial Geometry
- Frame Consistency
- Motion Anomalies
- Texture Irregularities
Once authentication confidence is established, the aligned face is processed using ArcFace (InceptionResnetV1) to generate a normalized 512-dimensional facial embedding.
These embeddings are encrypted before storage.
The generated embedding is compared against the enrolled biometric template using cosine similarity.
Authentication succeeds only when:
- Similarity Threshold is satisfied
- Liveness succeeds
- Anti-Spoof succeeds
- Deepfake Risk remains below configured thresholds
| Technology | Purpose |
|---|---|
| Python | AI Runtime |
| Flask | REST API |
| PyTorch | Deep Learning |
| OpenCV | Image Processing |
| MediaPipe | Landmark Detection |
| ArcFace | Face Recognition |
| NumPy | Numerical Computing |
| Pillow | Image Processing |
- Multi-frame Authentication
- Liveness Detection
- Deepfake Detection
- Replay Attack Protection
- Printed Photo Detection
- Screen Replay Detection
- AES-256-GCM Encrypted Embeddings
- Risk Score Fusion
- Configurable Similarity Thresholds
The Student Management System uses a multi-database architecture to separate operational application data from sensitive biometric information. This separation improves security, scalability, and maintainability.
Stores operational data including:
- Students
- Teachers
- Administrators
- Attendance
- Assignments
- Mock Examinations
- Marks
- Notifications
- Leave Requests
- Audit Logs
Dedicated to facial authentication.
Contains:
- Face Embeddings
- Enrollment Records
- Face Change Requests
- Approval History
- Verification Images
- Face Metadata
Sensitive biometric vectors are encrypted before being stored.
| Database | Purpose |
|---|---|
| PostgreSQL | Primary Relational Database |
| PostgreSQL (Face DB) | Biometric Database |
| Redis | Cache & Background Jobs |
- Normalized Schema
- Foreign Key Constraints
- Indexed Queries
- Transaction Safety
- ACID Compliance
- Audit Trails
- Soft Deletes
- Optimized Read Performance
Database triggers automatically synchronize critical relationships including:
- StudentβTeacher Relationships
- Administrative Configuration
- Notification Status
- Face Registration History
This minimizes manual synchronization and ensures data consistency.
The database employs:
- B-Tree Indexes
- Composite Indexes
- Partial Indexes
- Connection Pooling
- Query Optimization
- Prepared Statements
- Redis Caching
These optimizations maintain excellent performance under large institutional workloads.
The Student Management System follows a Zero Trust Security Model, ensuring every request is authenticated, authorized, validated, and audited before access is granted.
sequenceDiagram
autonumber
actor Student
participant Backend
participant Redis
participant PostgreSQL
participant FaceAI
Student->>Backend: Username & Password
Backend->>PostgreSQL: Verify Credentials
PostgreSQL-->>Backend: User Information
Backend->>Redis: Rate Limit & Token Checks
Redis-->>Backend: Validation
Backend-->>Student: Pre-Authentication Token
Student->>Backend: Face Authentication Request
Backend->>FaceAI: Verify Face
FaceAI-->>Backend: Authentication Result
Backend->>PostgreSQL: Store Login Event
Backend-->>Student: Access Token + Refresh Token
- Password Authentication
- Face Authentication
- Multi-Factor Authentication
- Session Rotation
- Refresh Token Rotation
- Device Validation
- HTTPS
- Reverse Proxy
- Secure Headers
- CORS Protection
- Request Validation
- Role-Based Access Control
- JWT Authentication
- Request Validation
- Input Sanitization
- SQL Injection Protection
- XSS Protection
- AES-256-GCM Encryption
- Password Hashing (Bcrypt)
- Secure Cookies
- Database Encryption
- Token Encryption
Every security-sensitive operation is logged, including:
- Login Attempts
- Face Verification
- Attendance Events
- Administrative Actions
- Permission Changes
- Password Resets
- Failed Authentication
- Audit Events
- Confidentiality
- Integrity
- Availability
- Accountability
- Non-Repudiation
- Least Privilege
- Defense in Depth
The Student Management System combines modern educational management, enterprise-grade security, artificial intelligence, and cloud-native infrastructure into a single integrated platform.
| Category | Feature | Status | Description |
|---|---|---|---|
| π Authentication | Password Authentication | β Fully Implemented | Secure Bcrypt password authentication |
| Face Authentication | β Fully Implemented | ArcFace-based biometric authentication | |
| Multi-Factor Authentication (MFA) | β Fully Implemented | TOTP-based second-factor authentication | |
| Refresh Token Rotation | β Fully Implemented | Secure JWT token lifecycle management | |
| Device Validation | β Fully Implemented | Trusted device verification | |
| Session Management | β Fully Implemented | Secure session lifecycle | |
| Password Recovery | β Fully Implemented | Account recovery workflow | |
| π‘οΈ Security | Anti-Spoof Detection | β Fully Implemented | Multi-layer spoof protection |
| Deepfake Detection | β Fully Implemented | AI-assisted deepfake analysis | |
| AES-256-GCM Encryption | β Fully Implemented | Encrypted biometric storage | |
| Rate Limiting | β Fully Implemented | Request throttling | |
| Audit Logging | β Fully Implemented | Security event tracking | |
| GPS Geofencing | β Fully Implemented | Location-based attendance validation | |
| π Academic | Student Management | β Fully Implemented | Complete student administration |
| Teacher Management | β Fully Implemented | Teacher portal and administration | |
| Attendance Management | β Fully Implemented | GPS-based attendance system | |
| Assignment Management | β Fully Implemented | Assignment creation, submission, grading | |
| Mock Examination | β Fully Implemented | Online MCQ examination system | |
| Student Marks Prediction | β Fully Implemented | AI-powered academic prediction | |
| Academic Analytics | β Fully Implemented | Student performance insights | |
| Leave Management | β Fully Implemented | Student leave workflow | |
| π AI | Face Recognition | β Fully Implemented | ArcFace embeddings |
| Liveness Detection | β Fully Implemented | Multi-frame verification | |
| Face Enrollment | β Fully Implemented | Secure biometric registration | |
| Identity Verification | β Fully Implemented | Face comparison engine | |
| β Infrastructure | Docker Support | β Fully Implemented | Containerized deployment |
| Kubernetes Ready | β Fully Implemented | Cloud-native deployment | |
| Nginx Reverse Proxy | β Fully Implemented | Production routing | |
| Redis Cache | β Fully Implemented | High-speed caching | |
| PostgreSQL | β Fully Implemented | Primary relational database | |
| Monitoring | β Fully Implemented | Prometheus & Grafana | |
| Logging | β Fully Implemented | Centralized observability | |
| π Reliability | Degraded Mode | β Fully Implemented | Graceful service degradation |
| Background Jobs | β Fully Implemented | Redis queue processing | |
| Health Checks | β Fully Implemented | Automated service monitoring | |
| Horizontal Scaling | β Fully Implemented | Kubernetes autoscaling |
The backend exposes a RESTful API organized into modular endpoints. Every endpoint follows consistent validation, authentication, authorization, structured error handling, and audit logging.
| Method | Endpoint | Description |
|---|---|---|
| POST | /pre-login-check |
Performs initial authentication validation and determines required security factors. |
| POST | /login |
Verifies username and password credentials. |
| POST | /face-login |
Performs AI-powered face authentication. |
| POST | /mfa/enroll |
Enrolls a user into Multi-Factor Authentication. |
| POST | /mfa/verify |
Confirms MFA enrollment. |
| POST | /mfa/validate |
Validates MFA during login. |
| POST | /refresh |
Refreshes JWT access tokens. |
| POST | /logout |
Invalidates user session. |
| POST | /recovery/request |
Initiates account recovery workflow. |
| POST | /recovery/reset |
Completes password recovery. |
| Method | Endpoint | Description |
|---|---|---|
| POST | /check-in |
Student attendance check-in with GPS validation. |
| POST | /check-out |
Student attendance check-out. |
| GET | /today |
Retrieves today's attendance record. |
| GET | /history |
Retrieves historical attendance. |
| POST | /request-location-timing |
Requests attendance location updates. |
| Method | Endpoint | Description |
|---|---|---|
| POST | / |
Create assignment. |
| GET | /teacher |
Teacher assignment dashboard. |
| GET | /student |
Student assignment dashboard. |
| POST | /:id/submit |
Submit assignment. |
| PUT | /submissions/:id/grade |
Grade assignment. |
| POST | /predict-marks |
Predict student performance using AI. |
| Method | Endpoint | Description |
|---|---|---|
| POST | / |
Create mock examination. |
| GET | / |
Retrieve available examinations. |
| GET | /:id |
View examination details. |
| POST | /:id/attempt |
Submit examination answers. |
| GET | /:id/results |
View examination results. |
| Method | Endpoint | Description |
|---|---|---|
| GET | /profile |
Retrieve student profile. |
| PUT | /profile |
Update student profile. |
| GET | /dashboard |
Student dashboard statistics. |
| GET | /analytics |
Student performance analytics. |
| Method | Endpoint | Description |
|---|---|---|
| GET | /dashboard |
Teacher dashboard. |
| GET | /students |
Assigned student list. |
| POST | /assignments |
Create assignments. |
| GET | /reports |
Academic reports. |
| Method | Endpoint | Description |
|---|---|---|
| GET | /dashboard |
Administrative dashboard. |
| GET | /users |
User management. |
| POST | /teachers |
Create teacher accounts. |
| POST | /students |
Create student accounts. |
| GET | /analytics |
Institution-wide analytics. |
| GET | /audit-logs |
Security audit history. |
Every API endpoint includes:
- JWT Authentication
- Role-Based Access Control (RBAC)
- Request Validation
- Input Sanitization
- Structured Error Responses
- Audit Logging
- Correlation IDs
- Rate Limiting
- Secure Headers
- HTTPS Enforcement
All API responses follow a consistent JSON structure.
{
"success": true,
"message": "Operation completed successfully.",
"data": {},
"timestamp": "2026-01-01T12:00:00Z"
}The Student Management System uses environment variables to securely configure services without exposing sensitive credentials in source code. Each microservice maintains its own configuration while sharing common infrastructure settings where required.
| Variable | Description | Example |
|---|---|---|
PORT |
Backend API listening port | 3001 |
NODE_ENV |
Runtime environment | production |
DB_HOST |
PostgreSQL host | student-db |
DB_PORT |
PostgreSQL port | 5432 |
DB_NAME |
Database name | student_system |
DB_USER |
Database username | postgres |
DB_PASSWORD |
Database password | ******** |
FACE_DB_HOST |
Face database host | student-face-db |
FACE_DB_PORT |
Face database port | 5432 |
REDIS_URL |
Redis connection string | redis://student-redis:6379 |
JWT_ACCESS_SECRET |
Access token signing key | ******** |
JWT_REFRESH_SECRET |
Refresh token signing key | ******** |
JWT_EXPIRES_IN |
Access token lifetime | 15m |
JWT_REFRESH_EXPIRES_IN |
Refresh token lifetime | 7d |
FACE_AI_SERVICE_URL |
Face AI Service endpoint | http://student-face-ai:8000 |
ENCRYPTION_MASTER_KEY |
AES-256-GCM encryption key | ******** |
SMTP_HOST |
SMTP server | smtp.gmail.com |
SMTP_PORT |
SMTP port | 587 |
SMTP_USER |
SMTP username | example@gmail.com |
SMTP_PASSWORD |
SMTP password | ******** |
| Variable | Description | Example |
|---|---|---|
FACE_RECOGNITION_MODE |
Recognition mode | real |
FACE_DETECTOR_BACKEND |
Detection engine | opencv |
FACE_AI_SPOOF_THRESHOLD |
Spoof detection threshold | 0.55 |
FACE_AI_SIMILARITY_THRESHOLD |
Face similarity threshold | 0.70 |
MODEL_PATH |
AI model directory | /models |
DEVICE |
AI execution device | cuda |
| Variable | Description | Example |
|---|---|---|
VITE_API_BASE_URL |
Backend API URL | http://localhost:3001/api |
VITE_SOCKET_URL |
Socket.IO endpoint | http://localhost:3001 |
VITE_APP_NAME |
Application name | Student Management System |
This project can be executed using Docker for a complete containerized environment or natively for development and debugging.
Before starting, ensure the following software is installed:
- Git
- Docker
- Docker Compose
- Node.js 18+
- npm
- Python 3.10+
- PostgreSQL 15+
- Redis 7+
git clone https://github.com/Arthur-2407/Student-Management-System.git
cd Student-Management-Systemcd backend-api
npm installcd frontend
npm installcd face-ai-service
python -m venv venv
# Windows
venv\Scripts\activate
# Linux / macOS
source venv/bin/activate
pip install -r requirements.txtCreate .env files for:
backend-api/.env
frontend/.env
face-ai-service/.env
Configure each using the environment variable tables above.
cd backend-api
npm run devcd face-ai-service
python src/main.pycd frontend
npm run devAfter all services have started:
| Service | URL |
|---|---|
| Frontend | http://localhost:5173 |
| Backend API | http://localhost:3001 |
| Face AI Service | http://localhost:8000 |
The project includes production-ready Docker configurations for every service.
| Service | Docker Image |
|---|---|
| Frontend | student-management-frontend |
| Backend API | student-management-backend |
| Face AI Service | student-management-face-ai |
| PostgreSQL | postgres:15-alpine |
| Redis | redis:7-alpine |
| Nginx | nginx:alpine |
docker compose up -d --builddocker psdocker compose logs -fdocker compose downdocker compose -f docker-compose.prod.yml up -d --build- Multi-stage Docker builds
- Reduced production image sizes
- Nginx reverse proxy
- Health checks
- Restart policies
- Environment-based configuration
- Persistent database volumes
- Dedicated Docker networks
- Secure container isolation
- Optimized build caching
Browser
β
βΌ
Nginx
β
ββββββββββΊ Frontend
β
ββββββββββΊ Backend API
β β
β ββββββββββΊ PostgreSQL
β β
β ββββββββββΊ Redis
β β
β ββββββββββΊ Face AI Service
The Student Management System is designed with a cloud-native architecture and includes production-ready Kubernetes manifests for scalable, resilient, and highly available deployments.
The Kubernetes configuration enables independent scaling of each microservice while maintaining secure communication between services and persistent storage for critical data.
| Component | Purpose |
|---|---|
| Deployments | Manage application replicas |
| Services | Internal service discovery |
| Ingress | External HTTP/HTTPS routing |
| ConfigMaps | Environment configuration |
| Secrets | Sensitive credentials |
| Persistent Volumes | Database persistence |
| Horizontal Pod Autoscaler | Automatic scaling |
| Network Policies | Secure service communication |
k8s/
β
βββ namespace.yaml
βββ configmap.yaml
βββ secrets.yaml
βββ frontend-deployment.yaml
βββ backend-deployment.yaml
βββ face-ai-deployment.yaml
βββ postgres-deployment.yaml
βββ redis-deployment.yaml
βββ ingress.yaml
βββ hpa.yaml
βββ observability.yaml
βββ data-services.yaml
graph LR
Internet --> Ingress
Ingress --> Frontend
Ingress --> Backend
Backend --> PostgreSQL
Backend --> Redis
Backend --> FaceAI
FaceAI --> Redis
- Rolling Updates
- Zero Downtime Deployment
- Horizontal Pod Autoscaling
- Readiness Probes
- Liveness Probes
- Startup Probes
- Automatic Restart Policies
- Service Discovery
- Secure Secret Management
- ConfigMap Based Configuration
- Persistent Volume Claims
- Resource Requests & Limits
- High Availability
| Service | Default Replicas | Maximum Replicas |
|---|---|---|
| Frontend | 2 | 6 |
| Backend API | 2 | 8 |
| Face AI Service | 1 | 4 |
| PostgreSQL | StatefulSet | StatefulSet |
| Redis | StatefulSet | StatefulSet |
The production deployment integrates with:
- Prometheus
- Grafana
- Loki
- OpenTelemetry
- Health Endpoints
- Application Metrics
- Container Metrics
- Kubernetes Metrics
kubectl apply -f k8s/kubectl get pods
kubectl get svc
kubectl get ingress- Cloud Native
- Highly Available
- Fault Tolerant
- Self Healing
- Auto Scaling
- Secure
- Production Ready
The Student Management System has been engineered for high performance across authentication, attendance processing, AI inference, and academic analytics.
- React Code Splitting
- Lazy Loading
- Dynamic Imports
- Optimized Bundle Chunking
- Asset Compression
- Browser Caching
- Tree Shaking
- Optimized Rendering
- Redis Caching
- Database Connection Pooling
- Prepared Statements
- Efficient SQL Queries
- Background Job Processing
- Asynchronous APIs
- Request Compression
- Rate Limiting
- Multi-frame Processing
- GPU Acceleration Support
- Batch Face Processing
- Optimized ArcFace Inference
- Efficient Image Preprocessing
- Parallel Computer Vision Pipeline
- Indexed Queries
- Composite Indexes
- Partial Indexes
- Optimized Relationships
- Query Caching
- Trigger-Based Synchronization
- Multi-stage Docker Builds
- Kubernetes Auto Scaling
- Reverse Proxy Caching
- Health Monitoring
- Rolling Updates
- Resource Optimization
- Graceful Shutdown
- Automatic Recovery
- Fault Isolation
- Degraded Mode
- Retry Policies
- Centralized Logging
- Distributed Tracing
| Area | Objective |
|---|---|
| Authentication | Fast and secure verification |
| Face Authentication | Low-latency AI inference |
| Attendance | Real-time processing |
| Assignment Management | Responsive user experience |
| Dashboard | Optimized loading |
| Analytics | Efficient reporting |
| Database | High-throughput transactions |
The roadmap focuses on expanding AI capabilities, strengthening security, improving scalability, and enhancing the overall academic experience.
- OAuth 2.0 Authentication
- Microsoft Azure AD Integration
- Google Workspace Login
- Single Sign-On (SSO)
- Advanced Role Management
- Mobile Applications
- Push Notifications
- Offline Attendance
- QR Code Attendance
- Parent Portal
- Student Mobile App
- Teacher Mobile App
- AI Academic Assistant
- AI Assignment Evaluation
- AI Attendance Insights
- AI Student Risk Prediction
- AI Behavioral Analytics
- AI Recommendation Engine
- Multi-Campus Support
- Multi-Tenant Architecture
- LMS Integration
- ERP Integration
- Video Classroom Support
- Live Examination Proctoring
- Blockchain Certificate Verification
- AI-powered Institution Analytics
- Global Language Support
- Enhanced Security
- Faster Performance
- Greater Scalability
- Improved Accessibility
- Better User Experience
- Expanded AI Features
- Stronger Cloud Integration
This project is licensed under the Apache License 2.0.
The Apache License 2.0 allows you to:
- β Use the software commercially
- β Modify the source code
- β Distribute original or modified versions
- β Use the software privately
- β Patent protection provided under the license
You must:
- Include the original license and copyright notice.
- State significant changes made to the software.
- Preserve all required notices.
For the complete license text, see the LICENSE file located in the repository root.
Contributions are welcome and greatly appreciated.
Whether you're fixing bugs, improving documentation, adding features, optimizing performance, or enhancing security, your contributions help make the project better.
- Fork the repository.
- Create a feature branch.
git checkout -b feature/amazing-feature- Commit your changes.
git commit -m "Add amazing feature"- Push the branch.
git push origin feature/amazing-feature- Open a Pull Request.
- Follow the existing project structure.
- Write clean and maintainable code.
- Keep commits meaningful.
- Test changes before submitting.
- Update documentation when required.
If you encounter a bug, have a feature request, or need assistance, please use the appropriate GitHub features.
- π Report bugs using Issues
- π‘ Submit feature requests
- π Open Pull Requests for improvements
- β Star the repository if you find it useful
Arthur-2407
Designed and developed as a modern AI-powered Student Management System focused on security, scalability, cloud-native deployment, and intelligent educational management.
Special thanks to the open-source community and the maintainers of the technologies that power this project.
Core technologies include:
- React
- TypeScript
- Node.js
- Express
- PostgreSQL
- Redis
- Python
- Flask
- PyTorch
- OpenCV
- MediaPipe
- Docker
- Kubernetes
- Nginx
- Prometheus
- Grafana
Their continued innovation makes projects like this possible.
If this repository helps you, consider supporting it by:
- β Starring the repository
- π΄ Forking the repository
- π οΈ Contributing improvements
- π Sharing feedback
- π Recommending it to others
Every contribution, no matter how small, helps improve the project.
React β’ TypeScript β’ Node.js β’ Express β’ PostgreSQL β’ Redis β’ Python β’ Flask β’ Docker β’ Kubernetes
Built for modern educational institutions with AI-powered face authentication, attendance management, academic analytics, assignments, and microservices architecture.
If you found this project useful, don't forget to β Star the repository!






