From 2b116d3834aa02504f6c6c5703c9d90b7d950147 Mon Sep 17 00:00:00 2001 From: Jack Spiering <46534141+jackspiering@users.noreply.github.com> Date: Sun, 4 Oct 2026 01:15:12 +0200 Subject: [PATCH] Immich: document Tailnet access for remote machine learning --- services/immich/README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/services/immich/README.md b/services/immich/README.md index 1bb9a1cc..82258116 100644 --- a/services/immich/README.md +++ b/services/immich/README.md @@ -25,6 +25,7 @@ In this deployment, the `tailscale-immich` service runs the Tailscale client to * **Keep `TS_ACCEPT_DNS` disabled.** The `application` service shares the DNS configuration of the `tailscale` service. With `TS_ACCEPT_DNS=true`, Tailscale replaces Docker's DNS with MagicDNS, which cannot resolve the `database`, `redis`, and `immich-machine-learning` services. Immich then fails to start with `getaddrinfo ENOTFOUND database`. You can reach Immich over your Tailnet without this setting. * **Resolving MagicDNS names from Immich.** If Immich itself must look up other Tailnet devices by name, such as an OAuth provider or SMTP server, uncomment the `dns` block of the `tailscale` service and set `100.100.100.100` as the DNS server. Docker keeps resolving the service names and forwards all other lookups to MagicDNS. Use the full name, such as `device.example.ts.net`. +* **Remote machine learning.** If you run the machine learning container on another Tailnet device, your Tailnet policy must allow the Immich node to reach that device on TCP port `3003`. Otherwise the `tailscale` service logs `rejected due to acl`. A grant from the Immich node to the machine learning host with `"ip": ["tcp:3003"]` is enough. Keep `TS_USERSPACE=false`, because Immich must open connections to the Tailnet. Use the host's Tailscale IP address in the machine learning URL, or its MagicDNS name with the `dns` block described above. * **Storage locations.** `UPLOAD_LOCATION` and `DB_DATA_LOCATION` in `.env` set where Immich stores your media and its database. The defaults are `./immich-data/upload` and `./immich-data/database`. To move your media to another disk, set `UPLOAD_LOCATION` to an absolute path. Keep the database on a local disk, because Immich does not support network shares for it. * **Updating an existing installation.** Earlier versions of this stack ignored both variables and always used the default folders. If your `.env` still contains `UPLOAD_LOCATION=./library` or `DB_DATA_LOCATION=./postgres`, replace them with the defaults above before you restart. Otherwise Immich starts with an empty library and a new database. Your existing files stay untouched in `./immich-data`. * **Renamed services.** Immich connects to the hostnames `database` and `redis` by default. If you rename these services in `compose.yaml`, set `DB_HOSTNAME` and `REDIS_HOSTNAME` in `.env` to the new names.