Files
Arnout van Westen 03b1607e79 revert(infra): back to bridge networking, remove TNC dependency
Per request: TNC removed, all stacks back on default bridge with legacy
links for inter-container DNS (default bridge has no embedded DNS —
verified: nameserver passthrough to AdGuard). Kept: traefik router labels
(dnsweaver records), dawarich prod + SECRET_KEY_BASE, teslamate/bookorbit
hostport removals (service DNS now via links), komodo periphery as
separate project with 8120 hostport + server address change.
2026-10-05 10:15:39 +02:00

183 lines
7.8 KiB
YAML

#
# WARNING: To install Immich, follow our guide: https://docs.immich.app/install/docker-compose
#
# Make sure to use the docker-compose.yml of the current release:
#
# https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml
#
# The compose file on main may not be compatible with the latest release.
name: immich
services:
immich-server:
network_mode: bridge
labels:
- traefik.http.routers.immich.rule=Host(`photos.arnoutvw.nl`)
- pangolin.proxy-resources.immich.name=immich
- pangolin.proxy-resources.immich.full-domain=photos.arnoutvw.nl
- pangolin.proxy-resources.immich.protocol=http
- pangolin.proxy-resources.immich.ssl=true
- pangolin.proxy-resources.immich.targets[0].method=http
- pangolin.proxy-resources.immich.targets[0].hostname=192.168.10.144
- pangolin.proxy-resources.immich.targets[0].port=8693
- pangolin.proxy-resources.immich.targets[0].healthcheck.hostname=192.168.10.144
- pangolin.proxy-resources.immich.targets[0].healthcheck.port=8693
- pangolin.proxy-resources.immich.targets[0].healthcheck.enabled=true
- pangolin.proxy-resources.immich.auth.sso-enabled=false
- pangolin.proxy-resources.immich.rules[0].match=region
- pangolin.proxy-resources.immich.rules[0].action=allow
- pangolin.proxy-resources.immich.rules[0].value=EU
- pangolin.proxy-resources.immich.rules[1].match=ip
- pangolin.proxy-resources.immich.rules[1].action=allow
- pangolin.proxy-resources.immich.rules[1].value=172.21.0.1
- pangolin.proxy-resources.immich.rules[2].match=ip
- pangolin.proxy-resources.immich.rules[2].action=allow
- pangolin.proxy-resources.immich.rules[2].value=212.227.105.183
- pangolin.proxy-resources.immich.rules[3].match=country
- pangolin.proxy-resources.immich.rules[3].action=deny
- pangolin.proxy-resources.immich.rules[3].value=ALL
- net.unraid.docker.icon="https://raw.githubusercontent.com/imagegenius/templates/main/unraid/img/immich.png"
- net.unraid.docker.managed="dockerman"
container_name: immich_server
image: ghcr.io/immich-app/immich-server:v3.2.4
extends:
file: hwaccel.transcoding.yml
service: vaapi
volumes:
# Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file
- ${UPLOAD_LOCATION}:/photos
- /etc/localtime:/etc/localtime:ro
- "/mnt/user/photos:/icloud"
- /mnt/cache/appdata/immich:/config
- "21d10919ae9b171bf84d0e683c0c8b0ebee59196730a2d9fe49a4200cb47c474:/libraries"
env_file:
- .env
ports:
- '8693:2283'
depends_on:
- redis
- database
restart: always
healthcheck:
disable: false
immich-machine-learning:
network_mode: bridge
ports:
- '3003:3003'
container_name: immich_machine_learning
# For hardware acceleration, add one of -[armnn, cuda, rocm, openvino, rknn] to the image tag.
# Example tag: ${IMMICH_VERSION:-release}-cuda
image: ghcr.io/immich-app/immich-machine-learning:v3.2.4-openvino
extends: # uncomment this section for hardware acceleration - see https://docs.immich.app/features/ml-hardware-acceleration
file: hwaccel.ml.yml
service: openvino # set to one of [armnn, cuda, rocm, openvino, openvino-wsl, rknn] for accelerated inference - use the `-wsl` version for WSL2 where applicable
volumes:
- model-cache:/cache
- /mnt/cache/appdata/immich:/config
env_file:
- .env
restart: always
healthcheck:
disable: false
redis:
container_name: immich_redis
image: docker.io/valkey/valkey:9.1.2-alpine
network_mode: "bridge"
ports:
- '6380:6379'
healthcheck:
test: redis-cli ping || exit 1
restart: always
database:
container_name: immich_postgres
image: ghcr.io/immich-app/postgres:16-vectorchord0.4.2-pgvectors0.3.0
network_mode: "bridge"
ports:
- '5434:5432'
labels:
net.unraid.docker.icon: "https://github.com/SpaceinvaderOne/Docker-Templates-Unraid/blob/master/spaceinvaderone/docker_icons/postgresql-immich-logo.png?raw=true"
net.unraid.docker.managed: "dockerman"
environment:
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
POSTGRES_DB: ${DB_DATABASE_NAME}
POSTGRES_INITDB_ARGS: '--data-checksums'
# Uncomment the DB_STORAGE_TYPE: 'HDD' var if your database isn't stored on SSDs
# DB_STORAGE_TYPE: 'HDD'
volumes:
# Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file
- ${DB_DATA_LOCATION}:/var/lib/postgresql/data
shm_size: 128mb
restart: always
prometheus-immich-exporter:
container_name: "prometheus-immich-exporter"
environment:
- "IMMICH_API_TOKEN=IjxHR5IYwi9iGFaUMyvQ7B8aSYSMcOsAmF3rd09RpQ"
- "IMMICH_HOST=192.168.10.144"
- "IMMICH_PORT=8693"
- "TZ=Europe/Berlin"
- "EXPORTER_PORT=8000"
- "EXPORTER_LOG_LEVEL=INFO"
image: "friendlyfriend/prometheus-immich-exporter:1.2.4-dev"
labels:
net.unraid.docker.icon: "https://github.com/friendlyFriend4000/prometheus-immich-exporter/blob/master/unraid/immich-logo.png?raw=true"
net.unraid.docker.managed: "dockerman"
net.unraid.docker.webui: "http://[IP]:[PORT:8000]"
network_mode: "bridge"
ports:
- "8028:8000/tcp"
power-tools:
container_name: immich_power_tools
image: ghcr.io/varun-raj/immich-power-tools:0.19.1
network_mode: bridge
labels:
- traefik.http.routers.immich-powertools.rule=Host(`immich-power-tools.arnoutvw.nl`)
ports:
- "8029:3000"
env_file:
- .env
immich-proxy:
container_name: immich_proxy
image: ghcr.io/arnoutvw/yaiiu/immich-proxy:sha-8a197d0
network_mode: bridge
ports:
- "8694:8080"
environment:
- IMMICH_SERVER_URL=http://192.168.10.144:8693
- IMMICH_API_KEY=8FeEvF5Fdybpp9GM15x29VgchYtKqqgAgozX9Z5TbW4
labels:
- traefik.http.routers.immich-proxy.rule=Host(`immich-proxy.arnoutvw.nl`)
- pangolin.proxy-resources.immich-proxy.name=immich-proxy
- pangolin.proxy-resources.immich-proxy.full-domain=immich-proxy.arnoutvw.nl
- pangolin.proxy-resources.immich-proxy.protocol=http
- pangolin.proxy-resources.immich-proxy.ssl=true
- pangolin.proxy-resources.immich-proxy.targets[0].method=http
- pangolin.proxy-resources.immich-proxy.targets[0].hostname=192.168.10.144
- pangolin.proxy-resources.immich-proxy.targets[0].port=8694
- pangolin.proxy-resources.immich-proxy.targets[0].healthcheck.hostname=192.168.10.144
- pangolin.proxy-resources.immich-proxy.targets[0].healthcheck.port=8694
- pangolin.proxy-resources.immich-proxy.targets[0].healthcheck.enabled=true
- pangolin.proxy-resources.immich-proxy.auth.sso-enabled=false
- pangolin.proxy-resources.immich-proxy.rules[0].match=region
- pangolin.proxy-resources.immich-proxy.rules[0].action=allow
- pangolin.proxy-resources.immich-proxy.rules[0].value=EU
- pangolin.proxy-resources.immich-proxy.rules[1].match=ip
- pangolin.proxy-resources.immich-proxy.rules[1].action=allow
- pangolin.proxy-resources.immich-proxy.rules[1].value=172.21.0.1
- pangolin.proxy-resources.immich-proxy.rules[2].match=ip
- pangolin.proxy-resources.immich-proxy.rules[2].action=allow
- pangolin.proxy-resources.immich-proxy.rules[2].value=212.227.105.183
- pangolin.proxy-resources.immich-proxy.rules[3].match=country
- pangolin.proxy-resources.immich-proxy.rules[3].action=deny
- pangolin.proxy-resources.immich-proxy.rules[3].value=ALL
volumes:
model-cache:
21d10919ae9b171bf84d0e683c0c8b0ebee59196730a2d9fe49a4200cb47c474:
external: true