Back to articles
Technology Insight

Building a Private Family Cloud: Deploying Immich on VPS with Synology NAS Backup

May 27, 2026

Introduction: The Quest for Complete Photo Sovereignty

For years, cloud-hosted services like Google Photos and Apple iCloud have been the default repositories for our family memories. They offer undeniable convenience, seamless mobile synchronization, and powerful search capabilities. However, recent developments have forced tech-savvy users and privacy-conscious families to reconsider. Frequent subscription price hikes, arbitrary storage limitations, and growing concerns over data privacy and automated algorithmic scanning have made public cloud platforms less attractive.

The solution lies in creating a private, self-hosted photo management system. This architecture combines the high availability and performance of a Virtual Private Server (VPS) with the robust, cost-effective storage capacity of an on-premise Synology Network Attached Storage (NAS). In this deep-dive guide, we will explore how to deploy Immich—the premier open-source Google Photos alternative—on a VPS, connect it securely to your family's devices, and establish an automated backup pipeline to your home Synology NAS.

Data sovereignty is not just about keeping files away from big tech companies; it is about ensuring that your digital legacy remains accessible, unmonitored, and securely backed up under your own terms.

Architectural Overview: VPS Performance Meets On-Premise Storage

When designing a self-hosted photo infrastructure for a family, relying solely on a home server can be problematic due to asymmetric residential internet upload speeds, dynamic IP addresses, and occasional power outages. Conversely, hosting hundreds of gigabytes of media entirely on a VPS can quickly become cost-prohibitive due to storage premiums.

Our hybrid architecture solves these challenges by splitting roles optimized for each environment:

  • The Front-End Hub (VPS): A modest cloud VPS hosting the Immich container stack. It provides a static public IP, high-speed network connectivity, and rapid processing power for metadata, facial recognition, and machine learning features. It serves as the single point of contact for family mobile applications.
  • The Storage and Backup Vault (Synology NAS): Located safely inside your home network. It provides abundant, cost-effective storage via RAID arrays. Periodically, it securely pulls new data from the VPS, acting as the ultimate disaster recovery vault.

Phase 1: Setting Up Immich on a Cloud VPS

Immich relies heavily on Docker for deployment, ensuring all microservices (including the database, machine learning models, and web reverse proxies) run in harmony. To ensure optimal performance, your chosen VPS should possess a minimum of 2 vCPUs and 4GB of RAM, primarily to handle Immich's machine learning pipelines during initial library indexing.

Step 1.1: Environment Preparation

First, log in to your VPS via SSH and ensure system packages are up to date. Then, verify that Docker and the Docker Compose plugin are correctly installed:

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose-plugin -y

Step 1.2: Deploying Immich via Docker Compose

Create a dedicated directory for your Immich installation and download the necessary configuration templates directly from the official repository:

mkdir -p ~/immich-app && cd ~/immich-app
wget https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml
wget https://github.com/immich-app/immich/releases/latest/download/example.env -O .env

Open the .env file using your preferred text editor to customize critical parameters. Pay special attention to the UPLOAD_LOCATION variable, which dictates where your family's photos will reside on the VPS file system, and update the DB_PASSWORD to a secure, randomly generated string.

Launch the application stack using Docker Compose in detached mode:

sudo docker compose up -d

At this point, Immich is running internally on port 2283. To expose it safely to the internet, deploy a reverse proxy such as Nginx Proxy Manager or Caddy. Acquire an SSL certificate via Let's Encrypt to ensure all mobile-to-server communications are fully encrypted via HTTPS.

Phase 2: Configuring Multi-User Family Onboarding

With the server accessible via a secure domain name (e.g., https://photos.yourfamily.com), navigate to the web UI to initialize the administrator account. Immich is built from the ground up to support isolated, multi-user environments, making it ideal for families.

  1. Create User Accounts: From the administration dashboard, navigate to User Management and create unique accounts for each family member. Each user will have their own isolated library, login credentials, and mobile backup settings.
  2. Configure Mobile Synchronization: Instruct family members to download the Immich application from the iOS App Store or Google Play Store. Input the server URL and log in with their respective credentials.
  3. Enable Automated Backups: Within the mobile app, enable the "Backup" feature. Customize settings to restrict uploads to unmetered Wi-Fi connections and specify whether to synchronize background folders, historical system rolls, or newly captured media exclusively.

Phase 3: Secure Networking with Tailscale

To safely transfer media files from the VPS to your home Synology NAS without exposing sensitive storage protocols or management ports to the public internet, we establish a secure virtual private network using Tailscale. Tailscale utilizes the WireGuard protocol to construct an encrypted mesh network between your infrastructure components.

Step 3.1: Install Tailscale on the VPS

Execute the official installation script on your cloud instance and authenticate it with your network profile:

curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up

Step 3.2: Configure Tailscale on Synology NAS

Log in to your Synology DSM interface. Open the Package Center, search for "Tailscale," and install the official package. Once installed, open the application icon, follow the login prompts to authenticate the NAS onto the same Tailscale network tailnet, and note the private Tailscale IP addresses assigned to both your VPS and NAS.

Phase 4: Automated Backup Pipeline to Synology NAS

With a secure, high-speed tunnel active between the cloud server and home hardware, we can construct the automated replication system. This ensures that even if the cloud VPS experiences catastrophic data corruption or hosting provider issues, your family's memories remain safe on physical storage drives at home.

Step 4.1: Setting up SSH Key-Based Authentication

To automate transfers without hardcoding plain-text passwords into scripts, generate an SSH key pair on your Synology NAS and append the public component to the VPS's authorized keys list. This permits the NAS to securely query and pull file data from the cloud server automatically.

Step 4.2: Writing the Synchronization Script

On your Synology NAS, create a backup shell script (e.g., backup_immich.sh). This script uses rsync to incrementally download the Immich upload directory via the secure Tailscale interface, preserving timestamps, file permissions, and directory structures:

#!/bin/bash
# Configuration Variables
VPS_USER="root"
VPS_TAILSCALE_IP="100.x.y.z"
VPS_SOURCE_DIR="/root/immich-app/upload/"
NAS_DEST_DIR="/volume1/NetBackup/Immich_Family_Backup/"
LOG_FILE="/volume1/NetBackup/logs/immich_sync.log"

echo "=== Backup Started: $(date) ===" >> $LOG_FILE
rsync -avz --delete -e "ssh -i /volume1/homes/admin/.ssh/id_rsa" \
$VPS_USER@$VPS_TAILSCALE_IP:$VPS_SOURCE_DIR $NAS_DEST_DIR >> $LOG_FILE 2>&1
echo "=== Backup Ended: $(date) ===" >> $LOG_FILE

Step 4.3: Scheduling the Automation via Synology Task Scheduler

To guarantee hands-off redundancy, embed the execution script directly into the DSM management software:

  • Open the Synology Control Panel and navigate to Task Scheduler.
  • Click Create > Scheduled Task > User-defined script.
  • Name the task "Hourly Immich Cloud Sync" and configure the execution user as root.
  • Under the Schedule tab, set the frequency to run daily or hourly depending on your family's data generation volume.
  • In the Task Settings tab, reference the script path: bash /volume1/scripts/backup_immich.sh.

Conclusion: Long-Term Digital Independence

By implementing this hybrid cloud architecture, you successfully construct a photo management platform tailored for the modern era. Immich provides your family with a beautiful, fast, and feature-rich interface that rivals commercial applications, complete with AI-powered search, object recognition, and map visualizations. Meanwhile, the background Tailscale tunnel and Synology automation guarantee that your primary copy is backed up locally to hardware you own.

This implementation eliminates recurring monthly subscription fees, completely shields your private family data from public cloud monetization frameworks, and ensures that your irreplaceable family history remains resilient against both cloud outages and local hardware failures.

Building a Private Family Cloud: Deploying Immich on VPS with Synology NAS Backup | DPTCloud