Start taking control of your memories. Immich is a high-performance, self-hosted backup solution for photos and videos. It is designed to be a drop-in replacement for Google Photos, offering features like automatic backup, facial recognition, and a stunning mobile app, all without the privacy concerns of big tech.
We love Immich because it's fast, actively developed, and gives us complete ownership of our data. Let's walk through a robust Kubernetes deployment.
Architecture & Requirements
Immich is composed of several microservices (Server, Microservices, Machine Learning, Postgres, Redis). Because of its smart search and facial recognition capabilities, it requires a Vector Database.
We will deploy:
- Immich Server & Microservices: The core application.
- Vector Database: A CloudNativePG cluster with
pgvectorextension for machine learning data. - Gateway API: To expose the service securely.
Vector Database Configuration
Immich relies heavily on vector embeddings for its semantic search and facial recognition. Instead of a generic database, we will provision a dedicated PostgreSQL cluster utilizing the Cloudnative Postgres Operator and the vectorchord image which comes with pgvector pre-installed.
This configuration creates a specialized "Vector DB" cluster:
Danger
Do not try to update image version of Postgres Vector DB to the latest version. Rollback is impossible and Immich may not support it. Instead, check the supported versions on the Immich Documentation.
After a few minutes, the cluster should be ready. You can check this way:
Immich Configuration
Now we configure Immich itself.
Chart configuration
We create a values-overrides.yaml file to configure the chart:
Connecting the Database
We create a Kubernetes Secret to manage the connection details to our Vector DB:
Storage for Photos
Photos take up space! We need a specific Persistent Volume Claim (PVC) for the library. In my case, I'm using an SMB share here (likely from a NAS) to provide enough storage:
Exposing with Gateway API
To access Immich from the web (and for the mobile app to connect), we use the Kubernetes Gateway API:
Immich Installation
To install Immich, we'll first deploy configuration we setup earlier:
Then we use the Helm chart provided by the Immich team:
You immich instance should now be accessible at immich.mydomain.com.
Best Practices
- Dedicated Database: Separating your Vector DB allows you to tune it specifically for vector search workloads without affecting other postgres instances.
- Backups: Immich data is precious. Ensure your
pvcand your Postgres clusters have automated backup policies.