| deploy/thor-k3s | ||
| .gitignore | ||
| LICENSE | ||
| README.md | ||
Immich Photos
GitOps deployment of Immich on the Thor k3s cluster, published at https://photos.kerryhatcher.com through the existing Cloudflare Tunnel.
Architecture
Cloudflare terminates public TLS and forwards the hostname through the existing
cloudflared connector to the shared Traefik service. Traefik routes the
hostname to the Immich server service in the immich namespace.
The deployment uses:
- the official Immich OCI Helm chart, pinned in
Chart.yaml; - CloudNativePG with PostgreSQL 18 and VectorChord;
- the chart-provided Valkey service;
- a retained local PV at
/hatch1/media/immichfor the managed library; and - a persistent model cache for the machine-learning service.
Bootstrap
The host dataset must exist before Argo CD syncs the application:
sudo zfs create -o mountpoint=/hatch1/media/immich hatch1/media/immich
sudo zfs set quota=1T hatch1/media/immich
sudo chown 1000:1000 /hatch1/media/immich
Register this private repository in Argo CD, then apply
deploy/thor-k3s/applications/immich.yaml. The application creates the
namespace and continuously reconciles the Helm release.
The remotely managed Cloudflare Tunnel needs an exact public-hostname route for
photos.kerryhatcher.com pointing to
http://traefik.civpulse-infra.svc.cluster.local:80.
Operations
Immich creates daily database backups inside the managed library. A complete
disaster-recovery copy must include both /hatch1/media/immich and the
PostgreSQL database. The library, upload, and profile directories contain
the critical original data; thumbnails and encoded videos can be regenerated.
Cloudflare limits the size of individual requests. Use a direct LAN or Tailscale route for video uploads larger than the Cloudflare account limit.