Building a Secure Family Photo & Video Storage System: Syncing Immich on VPS with a Home NAS
Introduction: The Modern Digital Preservation Dilemma
In an era where our most cherished memories are captured in 4K video and high-resolution photography, modern families face a critical challenge: how to store, organize, and preserve media safely without compromising privacy or incurring skyrocketing subscription costs. While mainstream public cloud services offer convenience, they present long-term vulnerabilities, including data privacy concerns, sudden pricing shifts, and the risk of account lockouts.
For tech-savvy households and business-minded individuals, the answer lies in self-hosting. Immich has emerged as the premier open-source, self-hosted alternative to Google Photos, offering blistering speed, facial recognition, and a polished mobile interface. However, running Immich entirely at home can suffer from limited residential upload speeds, while running it entirely in the cloud can quickly become cost-prohibitive due to storage limits.
The ultimate architectural solution? A hybrid deployment. By hosting the Immich frontend and application layer on a Virtual Private Server (VPS) for maximum availability and syncing the underlying data repository to a local Network Attached Storage (NAS) device at home, you achieve the perfect balance of performance, accessibility, and high-capacity security.
The Hybrid Architecture: Why VPS + Home NAS?
Deploying a hybrid infrastructure solves the traditional bottlenecks of 100% cloud or 100% local setups. Let us examine how these two components work in tandem to create a seamless ecosystem:
- The VPS Role (The Frontend): Acting as the public-facing gateway, the VPS hosts the Immich Docker containers. Because data centers possess massive symmetric bandwidth, mobile devices can upload photos and stream videos smoothly from anywhere in the world without choking your home network.
- The Home NAS Role (The Vault): Your local NAS serves as the ultimate source of truth and heavy-duty archive. Hard drives are significantly cheaper per terabyte when owned locally rather than rented in the cloud. By pulling data from the VPS to your home network, you retain physical custody of your family legacy.
Key Insight: This hybrid blueprint ensures that even if your home loses power or internet connectivity, the mobile app remains fully functional, caching uploads safely on the VPS until your home infrastructure comes back online.
Step 1: Setting Up Immich on Your VPS
The foundation of this architecture begins in the cloud. You will need a VPS running a stable Linux distribution (such as Ubuntu Server or Debian) with at least 4GB of RAM to comfortably handle Immich’s machine learning features (facial recognition and object detection).
1.1 Prerequisites and Docker Installation
First, ensure your VPS system packages are fully updated, and install the Docker engine alongside the Docker Compose plugin. Secure your server by setting up a basic firewall (UFW) allowing only SSH, HTTP, and HTTPS traffic.
1.2 Configuring the Immich Docker Compose
Create a dedicated directory for Immich and download the official configuration files. You will modify the docker-compose.yml and .env files to define your database credentials, upload directory locations, and reverse proxy settings.
To ensure external security, it is highly recommended to route your Immich traffic through a reverse proxy like Nginx Proxy Manager or Traefik, secured with a complimentary Let's Encrypt SSL certificate. This guarantees all media uploads from your family's smartphones are fully encrypted in transit.
Step 2: Preparing Your Home NAS for Synchronization
With the cloud instance live and accessible via your custom domain, attention must turn to your local repository. Whether you utilize a pre-built system like Synology DSM or a custom TrueNAS build, the NAS must be configured to receive and secure incoming data transfers.
2.1 Storage Pool and User Permissions
Create a dedicated dataset or shared folder named /immich-backup. Configure your storage pool with fault tolerance (such as RAID 1, RAID 5, or ZFS RAIDZ) to protect against physical drive failures. Create a non-root system user specifically tasked with executing the synchronization tasks, adhering strictly to the principle of least privilege.
2.2 Establishing a Secure Connection
To safely bridge your VPS and your home NAS without exposing your home network to the open internet, establish a secure encrypted tunnel. WireGuard or a zero-configuration mesh network like Tailscale represents the industry standard. By installing Tailscale on both the VPS and the NAS, they can communicate over a private, isolated virtual network as if they were sitting on the same physical switch.
Step 3: Implementing the Automated Sync Protocol
The crux of this strategy rests on automation. We must establish a routine scheduled process that duplicates data from the VPS storage volumes down to the home NAS.
3.1 Leveraging Rsync over SSH
The most robust tool for this task is rsync. It analyzes changes between directories and transmits only altered or newly created files, preserving bandwidth. A typical production-grade sync command looks like this:
rsync -avz --delete -e "ssh -i /path/to/key" user@vps-tailscale-ip:/usr/src/app/upload/ /volume1/immich-backup/
The --delete flag ensures that if you curate your library and delete unwanted media from the Immich frontend, those deletions mirror down to your NAS, keeping the storage optimized.
3.2 Automating with Cron Jobs
To eliminate manual overhead, wrap your sync script into a automated scheduler. For most families, running the sync script once daily at 2:00 AM minimizes network congestion. Edit your NAS or VPS crontab to execute the shell script reliably, ensuring output logs are saved to track success or failure states.
Step 4: Advanced Optimizations and Best Practices
An enterprise-grade home cloud requires careful fine-tuning. Consider the following optimizations to ensure long-term stability and peak performance:
- Immich Database Backups: The raw photos are only half the equation; the PostgreSQL database holds your metadata, facial recognition models, and album structures. Use
pg_dumpto export the database daily, and include this backup file in your rsync routine. - VPS Storage Management: To keep VPS costs minimal, you do not need to store years of data in the cloud. Once files are verified safely on your home NAS, you can leverage Immich’s offline storage or archiving workflows to free up active SSD space on your server.
- Hardware Acceleration: If your VPS provider supports it, pass through GPU capabilities to accelerate video transcoding and machine learning tasks, preventing CPU spikes during heavy import sessions.
Conclusion: Ultimate Peace of Mind
By architecting a hybrid storage system using Immich, a VPS, and a home NAS, you effectively build a private enterprise-grade media cloud. You bypass the restrictive fee structures of big tech platforms while retaining complete control over your data privacy. More importantly, you gain the confidence that your family’s digital legacy is preserved simultaneously in a high-availability cloud environment and on redundant, physical disks inside your own home.
