←back to thread

Self-hosting my photos with Immich

(michael.stapelberg.ch)
659 points birdculture | 1 comments | | HN request time: 0.193s | source
Show context
WD-42 ◴[] No.46170203[source]
Self hosting used to mean conceding on something. I can honestly say Immich is better in every way than Google Photos or whatever Apple calls it. The only thing is having to set it up yourself.
replies(8): >>46170508 #>>46170879 #>>46171072 #>>46171096 #>>46171210 #>>46171919 #>>46172322 #>>46175671 #
ptk ◴[] No.46170508[source]
How does sharing an album with others work on Immich?
replies(3): >>46170576 #>>46170670 #>>46170681 #
jasonjayr ◴[] No.46170576[source]
You get a link and you can set read or write permissions on it.

Whoever gets that link can browse it in a web browser.

I've used this to share albums of photos with gatherings of folks; it works very well. It does assume you have your Immich installation publicly available, however. (Not open to the public, but on a publicly accessible web server)

replies(2): >>46171665 #>>46171693 #
cromka ◴[] No.46171665[source]
OK. Then you concede your security, as I can't imagine any single person self-hosting can be better at keeping their public service more secure than engineers at Google can. Especially with limited time.
replies(3): >>46172147 #>>46172227 #>>46173816 #
esseph ◴[] No.46173816[source]
If you're not Cloudflare averse...

Setup immich VM or docker container with a cloudflare tunnel

Front access with Cloudflare Access (ZeroTrust) for free.

Set "can only be accessed by users with email = xyz@myuser”

Done.

Now assuming this is the same user email as the one you shared photos with, there is a base level of security keeping the riffraff away.

Home IP is never exposed either, because it's proxied through the cf tunnel.

replies(1): >>46210201 #
1. cromka ◴[] No.46210201[source]
I dont need that. I use wireguard to connect to my LAN. I meant risk of getting your data stolen either through physical breakup or some security vulnerability