From 125143808518f6fba98a07b085b667b37118d8eb Mon Sep 17 00:00:00 2001 From: Timothy Kim Date: Tue, 14 Apr 2026 15:41:11 -0400 Subject: [PATCH] install immich --- docker/immich/.gitignore | 2 + docker/immich/compose.yaml | 76 +++++++++++++++++++ docker/immich/hwaccel.ml.yml | 57 ++++++++++++++ docker/immich/hwaccel.transcoding.yml | 55 ++++++++++++++ .../nginx/conf.d/photos.thekims.family.conf | 48 ++++++++++++ 5 files changed, 238 insertions(+) create mode 100644 docker/immich/.gitignore create mode 100644 docker/immich/compose.yaml create mode 100644 docker/immich/hwaccel.ml.yml create mode 100644 docker/immich/hwaccel.transcoding.yml create mode 100644 docker/nginx/conf.d/photos.thekims.family.conf diff --git a/docker/immich/.gitignore b/docker/immich/.gitignore new file mode 100644 index 0000000..b4986fa --- /dev/null +++ b/docker/immich/.gitignore @@ -0,0 +1,2 @@ +library/ +postgres/ diff --git a/docker/immich/compose.yaml b/docker/immich/compose.yaml new file mode 100644 index 0000000..0b827a5 --- /dev/null +++ b/docker/immich/compose.yaml @@ -0,0 +1,76 @@ +# +# WARNING: To install Immich, follow our guide: https://docs.immich.app/install/docker-compose +# +# Make sure to use the docker-compose.yml of the current release: +# +# https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml +# +# The compose file on main may not be compatible with the latest release. + +name: immich + +services: + immich-server: + container_name: immich_server + image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release} + extends: + file: hwaccel.transcoding.yml + service: nvenc + volumes: + # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file + - ${UPLOAD_LOCATION}:/data + - /etc/localtime:/etc/localtime:ro + env_file: + - .env + ports: + - '2283:2283' + depends_on: + - redis + - database + restart: unless-stopped + healthcheck: + disable: false + + immich-machine-learning: + container_name: immich_machine_learning + # For hardware acceleration, add one of -[armnn, cuda, rocm, openvino, rknn] to the image tag. + # Example tag: ${IMMICH_VERSION:-release}-cuda + image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release} + extends: # uncomment this section for hardware acceleration - see https://docs.immich.app/features/ml-hardware-acceleration + file: hwaccel.ml.yml + service: cuda + volumes: + - model-cache:/cache + env_file: + - .env + restart: unless-stopped + healthcheck: + disable: false + + redis: + container_name: immich_redis + image: docker.io/valkey/valkey:9@sha256:3b55fbaa0cd93cf0d9d961f405e4dfcc70efe325e2d84da207a0a8e6d8fde4f9 + healthcheck: + test: redis-cli ping || exit 1 + restart: unless-stopped + + database: + container_name: immich_postgres + image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23 + environment: + POSTGRES_PASSWORD: ${DB_PASSWORD} + POSTGRES_USER: ${DB_USERNAME} + POSTGRES_DB: ${DB_DATABASE_NAME} + POSTGRES_INITDB_ARGS: '--data-checksums' + # Uncomment the DB_STORAGE_TYPE: 'HDD' var if your database isn't stored on SSDs + # DB_STORAGE_TYPE: 'HDD' + volumes: + # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file + - ${DB_DATA_LOCATION}:/var/lib/postgresql/data + shm_size: 128mb + restart: unless-stopped + healthcheck: + disable: false + +volumes: + model-cache: diff --git a/docker/immich/hwaccel.ml.yml b/docker/immich/hwaccel.ml.yml new file mode 100644 index 0000000..c95ac7e --- /dev/null +++ b/docker/immich/hwaccel.ml.yml @@ -0,0 +1,57 @@ +# Configurations for hardware-accelerated machine learning + +# If using Unraid or another platform that doesn't allow multiple Compose files, +# you can inline the config for a backend by copying its contents +# into the immich-machine-learning service in the docker-compose.yml file. + +# See https://docs.immich.app/features/ml-hardware-acceleration for info on usage. + +services: + armnn: + devices: + - /dev/mali0:/dev/mali0 + volumes: + - /lib/firmware/mali_csffw.bin:/lib/firmware/mali_csffw.bin:ro # Mali firmware for your chipset (not always required depending on the driver) + - /usr/lib/libmali.so:/usr/lib/libmali.so:ro # Mali driver for your chipset (always required) + + rknn: + security_opt: + - systempaths=unconfined + - apparmor=unconfined + devices: + - /dev/dri:/dev/dri + + cpu: {} + + cuda: + deploy: + resources: + reservations: + devices: + - driver: nvidia + count: 1 + capabilities: + - gpu + + rocm: + group_add: + - video + devices: + - /dev/dri:/dev/dri + - /dev/kfd:/dev/kfd + + openvino: + device_cgroup_rules: + - 'c 189:* rmw' + devices: + - /dev/dri:/dev/dri + volumes: + - /dev/bus/usb:/dev/bus/usb + + openvino-wsl: + devices: + - /dev/dri:/dev/dri + - /dev/dxg:/dev/dxg + volumes: + - /dev/bus/usb:/dev/bus/usb + - /usr/lib/wsl:/usr/lib/wsl diff --git a/docker/immich/hwaccel.transcoding.yml b/docker/immich/hwaccel.transcoding.yml new file mode 100644 index 0000000..0857faf --- /dev/null +++ b/docker/immich/hwaccel.transcoding.yml @@ -0,0 +1,55 @@ +# Configurations for hardware-accelerated transcoding + +# If using Unraid or another platform that doesn't allow multiple Compose files, +# you can inline the config for a backend by copying its contents +# into the immich-microservices service in the docker-compose.yml file. + +# See https://docs.immich.app/features/hardware-transcoding for more info on using hardware transcoding. + +services: + cpu: {} + + nvenc: + deploy: + resources: + reservations: + devices: + - driver: nvidia + count: 1 + capabilities: + - gpu + - compute + - video + + quicksync: + devices: + - /dev/dri:/dev/dri + + rkmpp: + security_opt: # enables full access to /sys and /proc, still far better than privileged: true + - systempaths=unconfined + - apparmor=unconfined + group_add: + - video + devices: + - /dev/rga:/dev/rga + - /dev/dri:/dev/dri + - /dev/dma_heap:/dev/dma_heap + - /dev/mpp_service:/dev/mpp_service + #- /dev/mali0:/dev/mali0 # only required to enable OpenCL-accelerated HDR -> SDR tonemapping + volumes: + #- /etc/OpenCL:/etc/OpenCL:ro # only required to enable OpenCL-accelerated HDR -> SDR tonemapping + #- /usr/lib/aarch64-linux-gnu/libmali.so.1:/usr/lib/aarch64-linux-gnu/libmali.so.1:ro # only required to enable OpenCL-accelerated HDR -> SDR tonemapping + + vaapi: + devices: + - /dev/dri:/dev/dri + + vaapi-wsl: # use this for VAAPI if you're running Immich in WSL2 + devices: + - /dev/dri:/dev/dri + - /dev/dxg:/dev/dxg + volumes: + - /usr/lib/wsl:/usr/lib/wsl + environment: + - LIBVA_DRIVER_NAME=d3d12 diff --git a/docker/nginx/conf.d/photos.thekims.family.conf b/docker/nginx/conf.d/photos.thekims.family.conf new file mode 100644 index 0000000..08ea460 --- /dev/null +++ b/docker/nginx/conf.d/photos.thekims.family.conf @@ -0,0 +1,48 @@ +# Template for new app confs. +# 1. Copy this file: cp _template.conf.example .conf +# 2. Replace photos.thekims.family with the actual domain +# 3. Replace UPSTREAM_NAME and CONTAINER:PORT with the app's container and port +# 4. Run issue-cert.sh if cert doesn't exist yet +# 5. Copy to argento, nginx -t && nginx -s reload + +server { + listen 80; + listen [::]:80; + server_name photos.thekims.family; + + location /.well-known/acme-challenge/ { + root /var/www/certbot; + } + + location / { + return 301 https://$host$request_uri; + } +} + +server { + listen 443 ssl; + listen [::]:443 ssl; + http2 on; + server_name photos.thekims.family; + + ssl_certificate /etc/letsencrypt/live/photos.thekims.family/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/photos.thekims.family/privkey.pem; + + include /etc/nginx/conf.d/security-headers.inc; + + # Use a variable so nginx starts even if the upstream is down + set $upstream_UPSTREAM_NAME http://localhost:2283; + + location / { + proxy_pass $upstream_UPSTREAM_NAME; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + # Uncomment if the app uses WebSockets + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + } +}