Immich Photo Manager (Self-Hosted)

Reading with interest.

Right now, I’m oldschool. My life’s photo collection is on a “good old fashioned hard drive at home” (backed up to iDrive with E2EE, however) under a folder called “Photos” and I’m not sure I’m even ready to bust out the cuppa and the “Change my mind” table about it. It’s nice and simple and I don’t have to fill in a data request to move it elsewhere. The camera roll on my phone is temporary - every so often I group it all into albums and extract it out onto the hard drive. iCloud Photo Library is on but I might knock it off once I have a better transfer system - we don’t have ADP in this country and although I have nothing illegal, I don’t feel it’s anyone’s business to just routinely scan my photos without a warrant.

Said hard drive isn’t even encrypted at all, it’s a USB drive I leave plugged into my Mac Mini which is sort of doubling as a NAS. There’s method in the madness - if something happens to me, my family can unplug the drive, plug it into theirs and enjoy the memories without any encryption hurdles, “legacy contact” systems etc. (I don’t put spicy pics there, I wouldn’t wish that sight on my family, lol).

What software I use boils down to how I want to browse and organise it beyond the filesystem structure, and to introduce some carefully managed remote access.

Weighing up the risks of not having my photo library encrypted at rest in my own home - yes my photos mean a lot and tell a big story… to me and my family. I’m not a person of interest, I’m very boring. If we got burgled, I’d have much bigger worries than someone snooping through my holiday reels and random phone pics. Probably the biggest risk is stealer malware but let’s be honest it’s more likely to target crypto wallets, Discord, etc. And in most scenarios I can think of, by the time you’re into my computer with a good enough stealer you already won the jackpot, got all my local documents etc and if the library were encrypted, the decryption key would be in RAM anyway because I would want to leave it open.

So that brings us to remote access. I just connect in with Tailscale. That is already an encrypted tunnel. (I mean sure, port forwarding in the year 2026 would be begging to have your shit hacked and stolen). The only downside to Tailscale is it knocks VPN off (on iOS anyway), but I can live with that. So I’m thinking that additional E2EE is unnecessary for my use case.

I just installed PhotoPrism a few days ago - so not settled yet - and it’s indexed my existing photos folder. All good aside from how it can’t tell the difference between a dog and a horse, but seeing how they’re handling monetisation has me concerned that they’ll shift more features behind the paywall so that’s got me looking at Immich now so that I don’t have the pain of migration later. I feel that if Immich had been listed on this site, I’d probably have gone for it from the outset rather than possibly wasting time with PhotoPrism.

Buuut that’s my specific setup and threat profile. I can see how it’s hard to recommend to the average Joe who never backs anything up and wouldn’t know WTF a Tailscale is. I wish it were more accessible as I still find it insane that most of the world nowadays uploads their entire lives to the cloud, E2EE or not. I mean there’s the hosting cost as well especially if you like shooting in RAW.

I’m in the same boat. After years of only having pictures, I gave in and started using Apple Photos. Big mistake: took a lot of time to organise things, only to realise that I wanted out of the Apple ecosystem, and that held me back. Then I tried Immich, which took a lot of time for the tens of thousands of pictures to be analysed. I was kinda happy with it, until I realised that the external hard-drive where old pictures are has to be plugged in for Immich to work. Which means that I could not just fire it up on my laptop to look at the locally-stored new pictures; it just wouldn’t start until my hard-drive was plugged in. That was a deal-breaker, because the hard-drive in question is often stored away, as I rarely need it. I’m the end, I went back to local storage and hard-drive and I use DigiKam – it doesn’t mess with my pictures, let’s me plug or unplug my hard-drive. So far so good.

Yeah I’ve switched back and forth between iOS and Android multiple times so have learned to prefer neutral platforms. Interesting issue with the drive. For my workflow it might not be an issue as that Mac Mini is sort of acting as a NAS and I can also Tailscale into it. But again that’s the risk tradeoff I’ve chosen rather than disconnecting the drive and putting it away.

It’s Immich all the way for me. I work with a team of photographers handling a lot of clients and hundreds of thousands of images and videos. We currently self host Immich, and client privacy is extremely important to us, especially because some members of the team shoot boudoir.

Keeping control of the server and storage ourselves is a needed advantage. We would love to use Ente, and the option to self host makes it appealing. But its organization and metadata limitations make it impossible for a professional photography workflow. Not just professionally, either. I cannot even comfortably use it for my own personal photos. With my personal stuff, I don’t even have some giant list of demands.

The lack of nested albums is not great, although it would not necessarily be a dealbreaker by itself. We could easily, and even preferably, work around that with tags, as they are far more flexible and really better than a folder hierarchy.

The problem is that Ente does not currently provide a proper general purpose tagging system either, and requests for tags have been open for years. Ente does read and preserve embedded xmp and iptc metadata I think, but it does not properly turn most of that information into usable, searchable organizational data. Changes made inside Ente are also stored separately and exported as json instead of being written back into standard xmp metadata.

It also does not look like it provides proper general purpose support for importing / updating, and exporting external .xmp sidecar files as part of a workflow. Larger xmp support, including keywords, ratings, and proper write back, is still being requested by users.

For a library that has hundreds of thousands of professionally managed images and videos, that is the mother of all dealbreakers. Tags are not a convenience or some extra feature for us. They should be standard. For us they might contain client names, event types, locations, licensing information, usage status, photographer assignments, editing stages, and other details.

Even more importantly, proper xmp support would mean that this information could remain portable between compatible photo management and editing applications rather than becoming trapped inside one service or stored only in its private database.

This is one of those rare situations where practical control and workflow requirements outweigh e2ee for us. We are not choosing convenience over privacy without thinking this through. We are choosing a system that we operate ourselves and that can actually preserve and organize the information attached to our work.

I understand that encrypted metadata might create technical challenges. But I do not understand how tags and proper standard xmp interoperability are not among the highest priorities for a serious photo management system.

Like I said, organization on ente is such a nightmare that I cannot even use it for my personal stuff. Immich is just too good.

We do follow the 3-2-1 backup method, but that is a good reminder for everyone. But is Immich still in the “underdevelopment” phase? Because I’m pretty sure it hit stable a year ago, and they even recently just put out 3.0

That is a bot account. It has two sentence replies in a lot of posts, all in a timeframe of one minute.

I was about to start my own thread for this, but searched for it first. I figured I’d throw my hat into the ring as well. I’ve been using Immich for about 5 months now, and I am incredibly happy with it. The developer is extremely responsive on his Discord, and has a small staff that regularly responds as well.

I think it would make a good addition to the self-hosting section of the site, alongside PhotoPrism.

Thanks. I’ve previously asked Ente to focus on prosumers; ex: Photographers / (content) Creators. I’ll be sure to pass on your feedback (to make my case) with their product team (if they haven’t seen it already).

What is meant by “zero-trust architecture”?

Only you can access/view your photos and videos. No one else.

In what way is Immich not zero-trust? You run the backup client on your phone, and the server runs on your PC or your NAS. The files are only transferred over local network connections. There is no way at all for anybody else to see your photos.

It is a totally different architecture.

Ente is end-to-end encrypted. No one could see your photos even if they wanted to as everything is encrypted on-device before it is sent to the server.

Immich is different. It is built with self-hosting in mind. It doesn’t do E2EE and the server has total access to your photos and does ML on them.

When you’re self-hosting this is fine but if someone has access to your physical server they can see everything.

That’s also why no one should offer Immich as a hosted solution on a VPS or other.

It is simply built for a different purpose. Ente is built to be hosted in the cloud not by you (though it can also be self-hosted and it solves the issue of an attacker having physical access to your server).

Yeah, that’s what I had thought. I think it would be a shame to encourage people away from a self hosted, high functioning solution to a paid, cloud storage option just because of a lack of knowledge. I still think Immich should be a part of the self hosted section of the site.