Skip to content

Immich Public Proxy Immich Public Proxy

Description / nameInput element
Container Registry
Timezone
Immich Public Proxy Host Port

Build Status Last Commit OCI Pulls

Share Immich photos and albums publicly without exposing the Immich instance itself.

Port 3000
Registry ghcr.io/daemonless/immich-public-proxy
Daemonless daemonless/immich-public-proxy
Source alangrainger/immich-public-proxy
Website github.com/alangrainger/immich-public-proxy

Version Tags

Tag Description Best For
latest Upstream Binary. Built from official release. Most users — recommended.

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.

Deployment

services:
  immich-public-proxy:
    image: "ghcr.io/daemonless/immich-public-proxy:latest"
    container_name: immich-public-proxy
    environment:
      - IMMICH_URL=http://your-internal-immich-server:2283  # URL of your (private) Immich instance, e.g. http://immich-server:2283
      - PUBLIC_BASE_URL=https://your-proxy-url.com  # Public base URL this proxy is served from, no trailing slash (optional - derived from the request hostname if unset)
      - TZ=UTC  # Timezone for the container
      - IPP_PORT=  # Internal webserver port (default 3000)
    ports:
      - "3000:3000"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

1
2
3
4
5
6
7
# .env

DIRECTOR_PROJECT=immich-public-proxy
IMMICH_URL=http://your-internal-immich-server:2283
PUBLIC_BASE_URL=https://your-proxy-url.com
TZ=UTC
IPP_PORT=
# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  immich-public-proxy:
    name: immich_public_proxy
    options:
      - container: 'args:--pull'
      - expose: '3000:3000 proto:tcp'
    oci:
      user: root
      environment:
        - IMMICH_URL: !ENV '${IMMICH_URL}'
        - PUBLIC_BASE_URL: !ENV '${PUBLIC_BASE_URL}'
        - TZ: !ENV '${TZ}'
        - IPP_PORT: !ENV '${IPP_PORT}'
1
2
3
4
5
6
7
# Makejail

ARG tag=latest

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/immich-public-proxy:${tag}

Save the files above, then run appjail-director up.

Experimental

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  immich-public-proxy:
    name: immich-public-proxy
    image: "ghcr.io/daemonless/immich-public-proxy:latest"
    network:
      - mode: host
    environment:
      - IMMICH_URL=http://your-internal-immich-server:2283
      - PUBLIC_BASE_URL=https://your-proxy-url.com
      - TZ=UTC
      - IPP_PORT=

Save as bastille-compose.yml, then run bastille up.

Access at: http://localhost:3000

Interactive Configuration

Parameters

Environment Variables

Variable Default Description
IMMICH_URL http://your-internal-immich-server:2283 URL of your (private) Immich instance, e.g. http://immich-server:2283
PUBLIC_BASE_URL https://your-proxy-url.com Public base URL this proxy is served from, no trailing slash (optional - derived from the request hostname if unset)
TZ UTC Timezone for the container
IPP_PORT `` Internal webserver port (default 3000)

Ports

Port Protocol Description
3000 TCP Web UI

This image is part of the Immich Stack.

Implementation Details

  • Architectures: amd64
  • User: bsd (UID/GID set via PUID/PGID). Defaults to 1000:1000.
  • Base: Built on ghcr.io/daemonless/base (FreeBSD 15.1).

Need help? Join our Discord community.