Building a Self-Hosted Intelligent Photo Gallery: Deploying Immich on a 4GB RAM VPS
Introduction: The Quest for Data Sovereignty in Digital Photography
In an era where digital memories accumulate at an unprecedented rate, modern smartphone users find themselves heavily reliant on centralized cloud storage giants like Google Photos and Apple iCloud. While these platforms offer undeniable convenience and advanced features like facial recognition and object detection, they come with significant trade-offs: escalating subscription costs, privacy concerns, and the risk of vendor lock-in. For businesses and privacy-conscious individuals alike, data sovereignty is no longer a luxury—it is a necessity.
Enter Immich, a high-performance, self-hosted photo and video management solution that acts as a direct, feature-rich alternative to mainstream cloud services. Immich delivers a seamless mobile backup experience, geospatial mapping, multi-user support, and critically, machine learning-powered tagging and facial recognition. However, running resource-intensive AI models typically demands heavy infrastructure. This guide demonstrates how to strategically deploy Immich on a cost-effective 4GB RAM Virtual Private Server (VPS), balancing optimal performance with budget constraints.
---Why Immich? The Enterprise-Grade Self-Hosted Alternative
Before diving into the technical implementation, it is essential to understand why Immich has emerged as the premier choice for self-hosted media management. Unlike legacy web galleries, Immich is designed from the ground up for modern workflows:
- Native Mobile Applications: Fully functional iOS and Android apps offer automatic background uploading, matching the seamless UX of commercial alternatives.
- Advanced AI Pipeline: Integrated machine learning models handle facial recognition, object detection, and semantic search (CLIP) directly on your server.
- Multi-User Architecture: Isolated user spaces allow teams or families to share a single instance securely while maintaining private libraries.
- Robust Metadata Handling: Read and write support for EXIF data, including GPS coordinates, timestamps, and camera configurations.
Note: Immich is under rapid, active development. While it is highly stable and production-ready for personal and small business use, regular backups are strongly recommended to safeguard your data assets.---
Pre-Requisites and VPS Capacity Planning
Deploying an AI-driven application on a 4GB RAM footprint requires deliberate optimization. Machine learning objects, combined with the underlying PostgreSQL database and Redis cache, can easily saturate system memory if left unconfigured. Here is the recommended baseline architecture for your VPS:
Hardware Specification
- CPU: 2 vCPUs (Intel/AMD or ARM64)
- Memory: 4GB Physical RAM
- Storage: NVMe SSD (Capacity depends on your library size; 100GB+ recommended)
- OS: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS
Network Configuration
Ensure your VPS provider allows traffic on standard web ports. You will need a fully qualified domain name (FQDN) pointing to your VPS public IP address to facilitate secure SSL connections via Let's Encrypt.
---Step 1: Preparing the Server Environment
First, access your VPS via SSH and update the core system packages to the latest security baselines. Then, we will configure a swap file. This is a critical step for a 4GB RAM server; during initial media ingestion and AI indexing, memory spikes can trigger the Linux Out-Of-Memory (OOM) killer. A swap file acts as an insurance policy.
sudo apt update && sudo apt upgrade -y
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstabVerify that your swap space is active by executing free -m. Next, install the foundational containerization tools: Docker and Docker Compose.
sudo apt install docker.io docker-compose-v2 -y
sudo systemctl enable --now docker---Step 2: Configuring the Immich Architecture via Docker Compose
Immich provides an official orchestration template using Docker Compose. Create a dedicated directory for your deployment and download the necessary configuration baselines:
mkdir -p ~/immich && cd ~/immich
wget [https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml](https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml)
wget [https://github.com/immich-app/immich/releases/latest/download/example.env](https://github.com/immich-app/immich/releases/latest/download/example.env) -O .envOptimizing the Environment File (.ENV)
Open the .env file using your preferred text editor (e.g., nano .env) and update the core variables. To ensure system stability on a 4GB RAM VPS, we must enforce strict hardware constraints on the machine learning microservice. Locate or add the following parameters:
# Core Configuration
UPLOAD_LOCATION=./library
IMMICH_VERSION=release
# Database Credentials
DB_PASSWORD=YourSecurePasswordHere
DB_USERNAME=postgres
DB_DATABASE_NAME=immich
# Performance Tuning for 4GB RAM
TYPESENSE_MEM_LIMIT=512mb
IMMICH_MACHINE_LEARNING_URL=http://immich-machine-learning:3003Modifying docker-compose.yml for Resource Restrictions
To prevent Immich from consuming excessive memory during deep learning tasks, edit the docker-compose.yml file to cap resource usage on the immich-machine-learning container. Add a deploy block as shown below:
immich-machine-learning:
container_name: immich_machine_learning
image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION}
# ... existing configuration ...
deploy:
resources:
limits:
cpus: '1.5'
memory: 1500M
restart: alwaysThis configuration ensures that even under heavy indexing, the AI subsystems leave ample memory headroom for the operating system, database, and web server infrastructure.
---Step 3: Launching Immich and Initial Ingestion
With configurations in place, initialize the container ecosystem. Fetch the required images and start the services in detached mode:
sudo docker compose up -dMonitor the initialization process using sudo docker compose logs -f. Once the database migrations finish and the health checks report positive statuses, the web service will be accessible locally on port 2283.
Step 4: Securing Immich with a Reverse Proxy and SSL
Exposing raw application ports directly to the internet is an anti-pattern in enterprise security architectures. Instead, route your traffic through a reverse proxy. Nginx Proxy Manager or standard Nginx paired with Certbot offers lightweight, reliable TLS termination.
Example Nginx Server Block Configuration
Create an Nginx server configuration block at /etc/nginx/sites-available/immich:
server {
listen 80;
server_name gallery.yourdomain.com;
# Allow large file uploads for 4K video assets
client_max_body_size 50000M;
location / {
proxy_pass [http://127.0.0.1:2283](http://127.0.0.1:2283);
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Websocket support for real-time upload indicators
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}Link the configuration to the active directory, test for syntax validity, and reload Nginx:
sudo ln -s /etc/nginx/sites-available/immich /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginxSecure the endpoint by executing sudo certbot --nginx -d gallery.yourdomain.com to acquire and auto-renew Let's Encrypt SSL certificates.
Step 5: Post-Deployment Administration & AI Optimization
Navigate to [https://gallery.yourdomain.com](https://gallery.yourdomain.com) in your browser to create the root administrative account. Once inside the main dashboard, proceed directly to Administration -> System Settings -> Machine Learning Settings.
To guarantee peak performance on limited hardware, adjust the execution pipeline:
- Model Selection: Utilize lightweight models for facial recognition (e.g.,
buffalo_lorantelope) and object detection. Avoid running extra-large language models unless your hardware scales up. - Concurrency Control: Set the maximum number of concurrent workers to 1. This linearizes the processing queue, ensuring system memory never hits saturation limits during asset crunching.
Conclusion: A Sustainable, Self-Hosted Future
By leveraging containerization and precise resource constraints, deploying a world-class, AI-enhanced photo library like Immich on a modest 4GB RAM VPS is entirely achievable. You gain full ownership of your data, eliminate recurring monthly subscription costs, and maintain absolute privacy over personal and corporate assets. As your library grows, the underlying architecture detailed here scales seamlessly, allowing you to easily adjust memory allocations or transition to larger physical infrastructure when required.
