Back to articles
Technology Insight

Building a Self-Hosted, Enterprise-Grade Google Photos Alternative: Deploying Immich on a VPS with Cloudflare R2 Storage

June 4, 2026

Introduction: The Growing Need for Media Sovereignty

In the digital landscape of 2026, data privacy and cloud storage costs have reached a critical tipping point. For years, mainstream platforms like Google Photos provided seamless backup experiences. However, shrinking free tiers, rising subscription fees, and mounting privacy concerns have driven technical professionals and businesses to seek independent alternatives. Enter Immich—a high-performance, self-hosted photo and video management solution that mirrors the feature-rich UX of Google Photos while granting you absolute data sovereignty.

While self-hosting is empowering, storing terabytes of media on a standard Virtual Private Server (VPS) can quickly become financially prohibitive due to local block storage costs. The optimal solution? A hybrid architecture. By deploying Immich on a cost-effective VPS for compute operations and offloading the actual media assets to Cloudflare R2 Storage—an object storage service renowned for its zero-egress fee model—you can build a resilient, infinitely scalable backup system at a fraction of traditional cloud costs.


Architecture Overview: Why VPS + Cloudflare R2?

Before diving into the deployment, it is vital to understand why this specific hybrid stack is superior to traditional single-server setups:

  • Compute Efficiency: The VPS handles the Immich core application, database, and intensive machine learning tasks (such as facial recognition and object detection).
  • Cost-Effective Scalability: Cloudflare R2 stores the raw, high-resolution media files. Unlike AWS S3, Cloudflare R2 charges nothing for data egress (download traffic), making it incredibly economical for frequent media viewing and synchronization.
  • Reliability and Backups: Separating compute from storage means your photos remain safe even if your VPS crashes or needs to be migrated to another provider.

To bridge the VPS file system with Cloudflare R2, we utilize GeeseFS or rclone, allowing Immich to interact with the cloud bucket as if it were a local directory.


Prerequisites and Environment Setup

To follow this guide successfully, ensure you have the following infrastructure components ready:

  1. A Linux VPS: Minimum 2 vCPUs and 4GB RAM (Immich's machine learning models for facial recognition require adequate memory; 8GB is recommended for smooth performance). Ubuntu 24.04 LTS is preferred.
  2. Docker and Docker Compose: Installed and running on your VPS.
  3. A Cloudflare Account: With an active R2 bucket created.
  4. A Domain Name: Pointing to your VPS IP address for secure HTTPS access via a reverse proxy (e.g., Nginx Proxy Manager, Caddy, or Cloudflare Tunnels).

Step 1: Configuring Cloudflare R2 and API Access

First, log in to your Cloudflare dashboard, navigate to R2 Object Storage, and click Create bucket. Name your bucket uniquely (e.g., my-immich-media-storage) and keep the default settings.

Next, you need to generate API credentials so your VPS can authenticate with the bucket:

  • Navigate to R2 > Manage R2 API Tokens.
  • Click Create API Token.
  • Provide a name, grant Edit permissions (Read/Write access is required), and scope it to your specific bucket.
  • Copy the Access Key ID, Secret Access Key, and the S3 Endpoint URL. Note: Keep these confidential as they grant full access to your data.

Step 2: Mounting Cloudflare R2 on the VPS

To make Immich see Cloudflare R2 as a local folder, we will mount the bucket using rclone. Execute the following steps on your VPS terminal:

1. Install rclone

Run the official installation script:

sudo -v && curl [https://rclone.org/install.sh](https://rclone.org/install.sh) | sudo bash

2. Configure the R2 Remote

Launch the interactive configuration utility:

rclone config

Create a new remote (name it cloudflare_r2), choose Amazon S3 Compliant Storage (option 5 in most versions), and select Cloudflare R2 as the provider. Input your Access Key, Secret Key, and custom Endpoint URL when prompted.

3. Mount the Bucket on Boot

Create a dedicated directory for your Immich data:

sudo mkdir -p /mnt/immich-r2

To ensure the mount persists after a system reboot, create a Systemd service file at /etc/systemd/system/rclone-immich.service:

[Unit]
Description=RClone Mount for Immich Cloudflare R2
After=network-online.target

[Service]
Type=notify
ExecStart=/usr/bin/rclone mount cloudflare_r2:my-immich-media-storage /mnt/immich-r2 --allow-other --vfs-cache-mode writes --vfs-cache-max-age 24h --buffer-size 64M
ExecStop=/bin/fusermount -u /mnt/immich-r2
Restart=always
User=root

[Install]
WantedBy=multi-user.target

Enable and start the service:

sudo systemctl enable --now rclone-immich.service

Step 3: Deploying Immich via Docker Compose

With our storage backend safely mounted at /mnt/immich-r2, we can proceed to deploy Immich. Create a new directory for Immich and download the necessary configuration templates:

mkdir ~/immich-app && cd ~/immich-app
wget [https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml](https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml)
wget [https://github.com/immich-app/immich/releases/latest/download/example.env](https://github.com/immich-app/immich/releases/latest/download/example.env) -O .env

Modifying the .env File

Open the .env file in your preferred text editor. You must adjust the UPLOAD_LOCATION variable to point directly to your mounted R2 directory:

# Core Settings
UPLOAD_LOCATION=/mnt/immich-r2
IMMICH_VERSION=release

# Database Settings
DB_PASSWORD=your_secure_random_password_here

Optimizing docker-compose.yml for Machine Learning

If your VPS lacks a dedicated GPU (which is typical for budget VPS offerings), ensure that the immich-machine-learning service container is configured to use CPU execution. Immich handles this automatically, but verifying that your system has adequate swap space configured is highly recommended to prevent out-of-memory errors during initial batch indexing.

Launch the containers in detached mode:

docker compose up -d

Step 4: Securing the Installation with a Reverse Proxy

Exposing raw ports directly to the public web is highly discouraged. To secure traffic with an SSL certificate, utilize a reverse proxy like Caddy. It automatically handles Let's Encrypt certificates with minimal configuration.

Create a Caddyfile:

photos.yourdomain.com {
    reverse_proxy localhost:2283
}

Restart your Caddy service, and your Immich instance will now be securely accessible via [https://photos.yourdomain.com](https://photos.yourdomain.com).


Step 5: Post-Deployment Configuration and Best Practices

Upon navigating to your domain, you will be prompted to create the initial admin account. Once logged in, consider optimizing these key settings for a cloud-hybrid deployment:

  • Thumbnail Generation: Under Administration > System Settings > Thumbnail Settings, ensure that low-resolution thumbnails are stored locally if you want to optimize bandwidth, though R2's zero-egress policy makes cloud storage perfectly viable for thumbnails too.
  • Smart Search & Machine Learning: If your VPS CPU spikes permanently during initial imports, you can navigate to Machine Learning Settings and schedule facial recognition to run only during off-peak hours.
  • Mobile App Syncing: Download the official Immich app from the Apple App Store or Google Play Store. Input your server URL and credentials to enjoy instant background photo syncing, identical to the native Google Photos workflow.

Conclusion: True Data Autonomy Awaits

By shifting away from restrictive public cloud ecosystems, you have successfully built a private, enterprise-grade media backup infrastructure. Combining the modern, intuitive frontend of Immich with the processing capability of a VPS and the unbounded, cost-efficient scaling of Cloudflare R2 offers the ultimate balance between performance, privacy, and budget. You are no longer just a tenant in someone else's cloud—you are the sole administrator of your digital heritage.

Building a Self-Hosted, Enterprise-Grade Google Photos Alternative: Deploying Immich on a VPS with Cloudflare R2 Storage | DPTCloud