No description
Find a file
2026-09-02 21:51:06 -04:00
deploy/thor-k3s fix: let Hickory own the LAN override 2026-09-02 21:51:06 -04:00
.gitignore Initial commit 2026-09-01 20:47:18 +00:00
LICENSE Initial commit 2026-09-01 20:47:18 +00:00
README.md Deploy Immich on Thor k3s 2026-09-01 17:36:27 -04:00

Immich Photos

GitOps deployment of Immich on the Thor k3s cluster, published at https://photos.kerryhatcher.com through the existing Cloudflare Tunnel.

Architecture

Cloudflare terminates public TLS and forwards the hostname through the existing cloudflared connector to the shared Traefik service. Traefik routes the hostname to the Immich server service in the immich namespace.

The deployment uses:

  • the official Immich OCI Helm chart, pinned in Chart.yaml;
  • CloudNativePG with PostgreSQL 18 and VectorChord;
  • the chart-provided Valkey service;
  • a retained local PV at /hatch1/media/immich for the managed library; and
  • a persistent model cache for the machine-learning service.

Bootstrap

The host dataset must exist before Argo CD syncs the application:

sudo zfs create -o mountpoint=/hatch1/media/immich hatch1/media/immich
sudo zfs set quota=1T hatch1/media/immich
sudo chown 1000:1000 /hatch1/media/immich

Register this private repository in Argo CD, then apply deploy/thor-k3s/applications/immich.yaml. The application creates the namespace and continuously reconciles the Helm release.

The remotely managed Cloudflare Tunnel needs an exact public-hostname route for photos.kerryhatcher.com pointing to http://traefik.civpulse-infra.svc.cluster.local:80.

Operations

Immich creates daily database backups inside the managed library. A complete disaster-recovery copy must include both /hatch1/media/immich and the PostgreSQL database. The library, upload, and profile directories contain the critical original data; thumbnails and encoded videos can be regenerated.

Cloudflare limits the size of individual requests. Use a direct LAN or Tailscale route for video uploads larger than the Cloudflare account limit.