Back to articles
Technology Insight

Self-Hosting Immich on a VPS with Cloudflare R2: The Ultimate Unlimited Google Photos Alternative

May 30, 2026

Introduction: The Cost of Convenience in Cloud Photo Storage

For years, Big Tech cloud solutions like Google Photos and Apple iCloud have been the default repositories for our digital memories. However, the landscape of personal data storage has shifted dramatically. With the elimination of unlimited free tiers, aggressive subscription price hikes, and growing discomfort over automated AI data mining on personal imagery, tech-savvy users and business professionals alike are seeking viable alternatives.

While traditional Network Attached Storage (NAS) setups offer data ownership, they suffer from high upfront hardware costs, single-point-of-failure vulnerabilities, and dependency on residential internet bandwidth. Enter Immich: a high-performance, self-hosted photo and video management solution that mirrors the exact user experience, mobile backup capabilities, and facial recognition of Google Photos. By decoupling compute from storage—running the Immich server on a lightweight Virtual Private Server (VPS) and mounting Cloudflare R2 Object Storage—you can construct an enterprise-grade, infinitely scalable photo cloud with predictable, rock-bottom infrastructure costs.

---

Why Immich, VPS, and Cloudflare R2 Make the Perfect Trio

Deploying Immich locally on a machine with limited storage creates a bottleneck. Instead, utilizing a hybrid cloud topology provides a production-ready environment that matches the reliability of commercial applications.

  • Immich: Delivers a stunning web and mobile interface, automated multi-user background backups (iOS and Android), reverse geocoding, and advanced machine learning utilities like face clustering and CLIP-based semantic search (e.g., searching for "dog on a beach" without manual tagging).
  • Virtual Private Server (VPS): Placing your Immich engine on a cloud VPS (such as Hetzner, DigitalOcean, or Linode) ensures 99.99% uptime, static IPv4/IPv6 allocation, and enterprise-grade network throughput. Because storage is offloaded, you only need a cheap, compute-optimized VPS instance.
  • Cloudflare R2 Object Storage: An S3-compatible, highly durable object storage solution. R2 is uniquely disruptive because it charges zero egress fees. You only pay for the raw data stored (typically $0.015 per GB) and operations, eliminating the unpredictable data transfer costs associated with traditional cloud providers.
---

Architectural Overview and Cost Comparison

To understand the financial efficacy of this setup, let us examine a data point comparing a standard 2TB storage tier over a multi-year horizon:

Storage StrategyMonthly Cost (Approx.)Egress/Transfer FeesPrivacy & Data ControlScalability Limits
Google One (2 TB)$9.99IncludedLow (Subject to data mining)Hard capped at tier limit
Self-Hosted VPS (Local NVMe)$20.00 - $40.00VariableHigh (Full ownership)Expensive to upgrade disk
VPS + Cloudflare R2 (2 TB)~$35.00 (Flat)$0.00 (Zero Egress)Absolute (Encrypted/Private)Infinite (Pay-as-you-grow)

Note: In the hybrid model, the VPS requires only a modest 40GB to 80GB local SSD to run the operating system, Docker containers, database index, and generated image cache/thumbnails. The actual multi-terabyte library of original master files sits securely on Cloudflare R2.

---

Step-by-step Implementation Guide

1. Prerequisites and Infrastructure Provisioning

Before executing the deployment, ensure you have the following assets ready:

  1. A Linux VPS running Ubuntu 24.04 LTS with at least 2 vCPUs and 4GB of RAM (required to execute the machine learning pipelines smoothly).
  2. A registered domain name with access to its DNS management zone.
  3. A Cloudflare Account with an R2 bucket initialized and an active API token containing read/write permissions.

2. Configuring the Object Storage Layer (S3-Compat via S3fs/Rclone)

Since Immich reads and writes assets through a designated local directory pathway, we use a high-performance utility like rclone or s3fs to securely mount the Cloudflare R2 bucket directly to the server's file system as a virtual directory. Install and configure Rclone on your server:

sudo apt update && sudo apt install rclone -y
rclone config

Define a new remote using the S3-compatible configuration parameters provided in your Cloudflare R2 dashboard. Ensure you substitute your specific Account ID and access keys:

  • Type: s3
  • Provider: Cloudflare
  • access_key_id: YOUR_R2_ACCESS_KEY_ID
  • secret_access_key: YOUR_R2_SECRET_ACCESS_KEY
  • endpoint: https://YOUR_CLOUDFLARE_ACCOUNT_ID.r2.cloudflarestorage.com

Once verified, create a systemd service file to automatically mount the bucket to /mnt/immich-storage at system boot, passing performance flags such as --vfs-cache-mode writes to ensure seamless background media transfers.

3. Deploying Immich via Docker Compose

Navigate to your deployment directory and pull the official microservices configuration stack. Immich relies on PostgreSQL (with the pgvector extension for AI embeddings) and Redis for task queues.

mkdir -p ~/immich-app && cd ~/immich-app
wget https://github.com/immich-app/immich/releases/latest/download/docker-compose.ymlnwget https://github.com/immich-app/immich/releases/latest/download/example.env -O .env

Modify the .env file to re-route the structural media directory to your newly mounted cloud storage path:

# Core Immich Directory Configuration
UPLOAD_LOCATION=/mnt/immich-storage
DB_PASSWORD=YourSecureGeneratedDatabasePassword
TZ=Asia/Ho_Chi_Minh

Launch the container ecosystem in detached mode:

docker compose up -d

4. Securing the Application with Caddy Reverse Proxy

To avoid exposing raw ports and to enforce modern cryptographic standards (TLS encryption), implement a Caddy reverse proxy server. Create a Caddyfile mapping your domain:

photos.yourdomain.com {
    reverse_proxy localhost:2283
    
    # Security optimizations for heavy media payloads
    request_body {
        max_size 10g
    }
}

Run Caddy, and it will automatically provision and renew a Let's Encrypt SSL certificate.

---

Optimizing Performance: ML and Caching Strategy

Running object storage over a network interface introduces slight latency compared to raw local NVMe disks. To achieve an instantaneous scrolling experience across thousands of historical photos, utilize these optimization practices within the Immich administrator setting pane:

Thumbnail Isolation

Keep thumbnails and machine learning cache artifacts strictly on the local fast SSD of the VPS. Under Administration > Settings > Storage Template, configure the template structure to dictate how original media is stored, while keeping volatile runtime indexes stored locally.

Machine Learning Scheduling

Immich leverages heavy AI models for facial recognition and object detection. To maintain lower monthly VPS costs, configure the Machine Learning and Smart Search pipelines to run asynchronously during off-peak hours or queue them to execute in batches rather than instantaneously upon upload.

---

Conclusion: Future-Proofing Your Digital Legacy

By shifting your photo backup infrastructure to a self-hosted Immich instance paired with Cloudflare R2, you effectively transcend the artificial constraints imposed by mainstream cloud subscriptions. You gain absolute ownership over your metadata, remove data-privacy risks entirely, and achieve an enterprise-grade cloud ecosystem that scales elastically as your media library grows over the decades. The peace of mind knowing that your family or organizational data is locked under your cryptographic control makes this modern hybrid setup the definitive gold standard for self-hosted infrastructure.

Self-Hosting Immich on a VPS with Cloudflare R2: The Ultimate Unlimited Google Photos Alternative | DPTCloud