Immich Immich

[SSO] Self-hosted photo and video backup and management platform

Immich is a high-performance self-hosted solution for backing up, organizing, and viewing photos and videos, with mobile clients, multi-user support, and local machine-learning search and recognition.

Links:

TODO: Configure and regularly test 3-2-1 backups for the library and PostgreSQL volume; review metrics and SSO requirements.

GPU acceleration intentionally disabled for Immich on this host.

Our host has an AMD Vega gfx90c iGPU. Immich’s ROCm/MIGraphX ML image causes GPU hangs and kernel resets that interrupt the desktop display. Immich issue #21648 documents gfx90c APU support being removed from current ROCm images: rocm unsupported on gfx90c APUs · Issue #21648 · immich-app/immich

GPU_COMPOSE_SUFFIX=amdgpu is shared by other services on this host, so retain this no-op override to keep Immich on CPU until upstream support is verified.

Authentik OIDC

Immich uses native OIDC for Authentik’s media group. OAuth settings are persisted in Immich’s database and must be configured through its web administration interface. Keep an existing local Immich administrator and password login for recovery.

Host Configuration

Create config/docker/<host>/immich/authentik-client-secret with mode 0600. Set these values in ignored config/docker/<host>/.env.immich:

IMMICH_AUTHENTIK_CLIENT_ID=immich
IMMICH_AUTHENTIK_SIGNING_KEY=<asymmetric Authentik signing-key UUID>

Create the Authentik application:

scripts/authentik-apps.py --application immich --apply

Immich Settings

Sign in as the local administrator and set Administration > Settings > OAuth:

SettingValue
EnabledEnabled
Issuer URLhttps://sso.<domain>/application/o/immich/
Client IDimmich
Client secretIgnored host secret value
Token endpoint auth methodclient_secret_post
Scopeopenid email profile
ID token signing algorithmRS256
Userinfo signing algorithmnone
Storage label claimpreferred_username
Auto registerEnabled
Auto launchDisabled
Mobile Redirect URI Overridehttps://immich.<domain>/api/oauth/mobile-redirect

Leave role and quota claims unset so Authentik-created accounts remain ordinary Immich users.

Verify

Link an existing local account before making OIDC its normal login path. Test an authorized media member, a non-member, local-password recovery, browser logout, and mobile login/background uploads on every supported platform.

name: immich
services:
  immich-server:
    image: ghcr.io/immich-app/immich-server:v3
    container_name: immich-server
    restart: unless-stopped
    environment:
      TZ: ${TIMEZONE}
      DB_USERNAME: immich
      DB_PASSWORD: ${IMMICH_POSTGRES_PASSWORD}
      DB_DATABASE_NAME: immich
    volumes:
      - ${DOCKER_VOLUMES}/immich/library:/data
      - ${STORAGE_FAMILYMEDIA}:/external/family-media:ro
      # kics-scan ignore-line -- read-only timezone data, not a writable host directory.
      - /etc/localtime:/etc/localtime:ro
    depends_on:
      - redis
      - database
    networks:
      - proxy
      - immich
    labels:
      traefik.enable: true
      traefik.http.routers.immich.rule: Host(`immich.${MYDOMAIN}`)
      traefik.http.routers.immich.middlewares: localaccess@file
      traefik.http.services.immich.loadbalancer.server.port: 2283
      homepage.group: Media
      homepage.name: Immich
      homepage.icon: immich.png
      homepage.href: https://immich.${MYDOMAIN}/
      homepage.description: "[SSO] Self-hosted photo and video backup and management platform"

  immich-machine-learning:
    image: ghcr.io/immich-app/immich-machine-learning:v3
    container_name: immich-machine-learning
    restart: unless-stopped
    environment:
      TZ: ${TIMEZONE}
    volumes:
      - immich-model-cache:/cache
    networks:
      - immich

  redis:
    image: docker.io/valkey/valkey:9
    container_name: immich-redis
    restart: unless-stopped
    healthcheck:
      test: redis-cli ping || exit 1
    networks:
      - immich

  database:
    image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0
    container_name: immich-postgres
    restart: unless-stopped
    environment:
      POSTGRES_PASSWORD: ${IMMICH_POSTGRES_PASSWORD}
      POSTGRES_USER: immich
      POSTGRES_DB: immich
      POSTGRES_INITDB_ARGS: --data-checksums
    volumes:
      - immich-postgres:/var/lib/postgresql/data
    shm_size: 128mb
    healthcheck:
      disable: false
    networks:
      - immich

volumes:
  immich-model-cache:
  immich-postgres:

networks:
  proxy:
    external: true
  immich: