Files
ansible-playbooks/roles/immich
Clément Désiles 7972fe09ad security: deploy pod manifests containing credentials with mode 0600
gitea.yaml, immich.yaml, and metabase.yaml embed database passwords in
env vars; per repo policy, rendered files containing secrets must not
be world-readable.
2026-07-04 00:06:29 +02:00
..
2025-11-14 00:23:03 +01:00

Immich Role

This Ansible role deploys Immich - a high performance self-hosted photo and video management solution - using Podman with k8s files.

Role Variables

See defaults/main.yml for all available variables and their default values.

Required Passwords

Both passwords must be set in your inventory (min 12 characters):

  • immich_postgres_password - PostgreSQL database password
  • immich_valkey_password - Valkey/Redis password

External Libraries

Mount host paths read-only into the server container via immich_external_libraries, then add the in-container mount_path in the Immich UI (Administration → External Libraries). The {{ ansible_user }} running the rootless pod must have read access on the host path.

Troubleshooting

Valkey ACL Issues

Test Immich user credentials:

valkey-cli
AUTH immich <immich_valkey_password>
SELECT 0
PING
# Should return PONG

# Try a restricted command (should fail)
FLUSHDB
# Should return: (error) NOPERM

Going further: Immich GitHub Discussion #19727