Back to articles
Technology Insight

Self-Hosting Immich on a VPS: The Ultimate Enterprise-Grade Google Photos Alternative for Family Backups

May 28, 2026

Introduction: The Growing Need for Cloud Independence

In the digital age, family photographs and videos represent irreplaceable historical assets. For over a decade, commercial cloud platforms—most notably Google Photos—have served as the default repository for these assets, leveraging seamless mobile synchronization and sophisticated computer vision algorithms. However, recent systemic shifts have forced technology leaders and privacy-conscious users to re-evaluate this reliance. The elimination of Google's unlimited free storage tiers, paired with rising subscription costs and escalating concerns over data privacy, corporate data mining, and arbitrary account suspensions, has accelerated the demand for self-hosted alternatives.

Enter Immich, a high-performance, self-hosted photo and video management solution designed to replicate and, in many respects, exceed the core functionalities of Google Photos. When deployed on a Virtual Private Server (VPS), Immich transitions from a localized hobbyist tool into a robust, high-availability cloud infrastructure capable of serving an entire household. This guide provides an enterprise-grade blueprint for architecting, deploying, and maintaining Immich on a VPS as a complete, production-ready replacement for commercial photo clouds.

Why Immich and a VPS Form the Ideal Architecture

Selecting the right infrastructure for your family backup system requires balancing accessibility, performance, and data sovereignty. While a local Network Attached Storage (NAS) device is excellent for local storage, it often suffers from restricted residential upload speeds, complex dynamic DNS configurations, and vulnerability to localized disasters like fire or theft.

Deploying Immich on a remote VPS mitigates these limitations by offering several distinct advantages:

  • High Availability and Symmetrical Bandwidth: Data centers provide redundant power supplies, enterprise-grade networking, and symmetrical gigabit uplinks, ensuring your mobile devices can back up media instantly from anywhere in the world.
  • Cost Efficiency: Modern VPS providers offer scalable compute and storage tiers. By leveraging block storage or object storage integrations, a VPS can often deliver a superior cost-per-gigabyte ratio compared to scaling premium Google One tiers across multiple family accounts.
  • Feature Parity: Immich provides native iOS and Android applications with background backup capabilities, multi-user isolation, face recognition powered by machine learning, object detection, and geographical map views.

System Architecture and Prerequisites

To ensure optimal performance, particularly during the initial ingestion phase when machine learning models process thousands of images, the underlying VPS infrastructure must meet specific baseline requirements.

Recommended VPS Specifications

  • Compute: Minimum 2 vCPUs (Shared CPU instances from premium providers like Hetzner, DigitalOcean, or Linode are acceptable; dedicated CPUs are preferred for large libraries).
  • Memory: Minimum 4GB RAM. The machine learning pipeline (typesense, facial recognition) is memory-intensive. 4GB ensures system stability; 8GB is optimal.
  • Storage: A fast NVMe or SSD boot drive (20GB–40GB) for the operating system and Immich application database, paired with scalable block storage or an attached S3-compatible object storage bucket for the raw media assets.
  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS for maximum stability and Docker compatibility.

Prerequisites Checklist

  1. A fully qualified domain name (FQDN), e.g., photos.yourfamily.com, with an A record pointing to your VPS public IP address.
  2. Docker Engine (v24.0+) and Docker Compose (v2.20+) installed on the target server.
  3. An SSH client and basic familiarity with Linux command-line administration.

Step-by-Step Deployment Guide

Immich is designed natively microservice-first and is officially distributed via Docker Compose. The stack consists of the core Immich application server, a PostgreSQL database with the pgvector extension for vector embeddings, a Redis cache instance, and a machine learning service container.

Step 1: Establishing the Directory Structure

Log into your VPS via SSH and create a dedicated directory to isolate the Immich stack configuration files:

mkdir -p /opt/immich && cd /opt/immich

This path follows standard Linux conventions for optional, self-contained software packages.

Step 2: Downloading and Customizing the Docker Configuration

Immich provides official template files for rapid deployment. Fetch the latest stable configurations using wget or curl:

wget https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml
wget https://github.com/immich-app/immich/releases/latest/download/example.env -O .env

Open the environment configuration file (.env) in a text editor like Nano to configure vital system variables:

nano .env

Ensure you modify the following parameters to secure your installation:

  • UPLOAD_LOCATION: Define where your media will be stored. If using attached block storage, point this to the correct mount point (e.g., /mnt/storage/immich-media).
  • DB_PASSWORD: Replace the default value with a cryptographically secure, high-entropy password to protect your relational database metadata.
  • IMMICH_VERSION: It is highly recommended to pin this to the release tag to receive stable updates automatically when restarting the stack.

Step 3: Orchestrating the Containers

With the environment variables set, execute the Docker Compose command to pull the required container images and initialize the multi-container application stack in detached mode:

docker compose up -d

Verify that all microservices (immich-server, immich-machine-learning, redis, and database) are running correctly by checking the container status:

docker compose ps

Securing the Deployment: Reverse Proxy and SSL

By default, Immich exposes its interface on port 2283 over unencrypted HTTP. Exposing this port directly to the public internet presents severe security risks, including credential interception and data leakage. To mitigate this, we must implement a reverse proxy layer using Nginx, Caddy, or Traefik to handle Transport Layer Security (TLS/SSL) encryption.

For simplicity, high efficiency, and automated certificate management, Caddy Server is an exceptional choice. Install Caddy on your VPS and configure the Caddyfile as follows:

photos.yourfamily.com {
    reverse_proxy 127.0.0.1:2283
    encode gzip zstd
    tls [email protected]
}

When Caddy initialises, it communicates automatically with Let's Encrypt to provision, validate, and install a trusted SSL certificate, ensuring all traffic between your family's mobile devices and the VPS is encrypted via TLS 1.3.

Optimizing Immich for Production and Machine Learning

Once you navigate to your domain and complete the initial administrator account creation, you must optimize the system configuration via the Immich Admin Web Dashboard.

Machine Learning Pipeline Management

Immich utilizes advanced Machine Learning models for facial recognition and semantic clip search (allowing you to search for terms like "dog in the park" without manual tagging). Because VPS instances often rely on shared CPUs without hardware acceleration (CUDA/GPUs), the initial processing of thousands of legacy photos can saturate the CPU, driving usage to 100% and causing temporary interface lag.

To maintain system responsiveness during large-scale uploads, navigate to Administration -> System Settings -> Machine Learning. Under the concurrency settings, limit the execution threads to 1 or 2, and consider scheduling the jobs to run during low-traffic overnight hours.

Multi-User Isolation and Privacy

As the administrator, you can invite family members under the Users management tab. Each user receives an entirely isolated sandbox environment. They cannot view other users' photos unless explicit permission is granted through the Partner Sharing or Shared Albums features, perfectly mirroring the collaborative yet private mechanics of Google Photos.

Enterprise-Grade Backup Strategies (The 3-2-1 Rule)

Hosting your data on a VPS does not absolve you from the responsibility of maintaining rigorous backups. A single server instance remains a single point of failure against user error, database corruption, or provider-wide outages. To ensure absolute data safety, you must adhere to the industry-standard 3-2-1 backup strategy.

  1. 3 Copies of Data: Maintain the live database and media files on the VPS, plus two distinct backup copies.
  2. 2 Different Media Types: Store data across different infrastructural mechanisms (e.g., local block storage and remote object cloud storage).
  3. 1 Off-site Location: Ensure at least one backup is located completely away from your primary VPS infrastructure.

Automating the Backup Pipeline

A production backup strategy requires two components: backing up the asset database metadata and backing up the physical files.

Create a automated cron job script that executes a pg_dump of the PostgreSQL database daily:

docker exec -t immich_postgres pg_dumpall -c -U postgres | gzip > /opt/immich/backups/database_backup_$(date +%F).sql.gz

Subsequently, utilize a professional tool like Rclone or BorgBackup to sync both the database dumps and the raw UPLOAD_LOCATION media directory to an external, off-site location such as Backblaze B2, AWS S3, or a physical NAS located at a relative's house.

Conclusion: The Path to True Data Sovereignty

Migrating from Google Photos to a self-hosted Immich instance on a VPS requires an initial investment of technical effort, but the long-term rewards are profound. You effectively eliminate ongoing subscription costs, establish absolute ownership over your family's private moments, and unlock a tailored, modern cloud experience free from corporate observation.

By selecting a reliable VPS provider, securing your data endpoints with modern encryption protocols, and implementing automated off-site backups, your self-hosted instance will serve as a secure, high-performance digital vault protecting your family's memories for decades to come.

Self-Hosting Immich on a VPS: The Ultimate Enterprise-Grade Google Photos Alternative for Family Backups | DPTCloud