Warning
Alpha build for testing only. Do not use it in production. latest and the 3 tags are unchanged, so existing installs will not update to it.
v4.0 alpha
Visitors can upload photos (very much OPTIONAL)
To ensure IPP remains read-only by default, uploads work by running an optional second container alongside IPP. Turn on Allow public user to upload on a share in Immich, and the gallery shows an Add photos button.
Full guide: https://github.com/alangrainger/immich-public-proxy/blob/4.0/docs/visitor-uploads.md
No API key, same as always
IPP 4.0 still never asks for an Immich API key, and the main container is still read-only. The new upload feature runs in a separate, optional container that talks to Immich with the share's own key, exactly as Immich's public share page does when "Allow public user to upload" is on. If you don't add the upload container, nothing about IPP changes.
Breaking changes from 3.x
- Immich 3.0.0 or newer is required. IPP checks the server version at startup and exits against an older Immich.
- Old config keys are no longer read. Keys that 1.x to 3.x mapped to new names at startup are ignored in 4.0. The full list is at https://github.com/alangrainger/immich-public-proxy/blob/4.0/docs/config/upgrading.md
- IPP will not start while
showMetadata.exif.enabledorshowMetadata.location.enabledis in your config. Remove the key, and set totrueonly the per-field flags for what visitors may see. allowDownloadtakes only0,1or2. Any other value, such astrue, turns downloads off.- A custom
invalidRequestHandler.jsmust be copied again from the 4.0 image. A copy taken from 3.x fails to load.
Enabling uploads
Add the upload service to the docker-compose.yml that runs IPP, and set both package versions to 4.0.0-alpha.2:
services:
immich-public-proxy:
image: alangrainger/immich-public-proxy:4.0.0-alpha.3
# ... your existing IPP service ...
ipp-upload:
image: alangrainger/immich-public-proxy-upload:4.0.0-alpha.3
container_name: ipp-upload
restart: always
ports:
- "3001:3000"
environment:
IMMICH_URL: http://your-internal-immich-server:2283
PUBLIC_BASE_URL: https://your-proxy-url.com
read_only: true
cap_drop:
- ALL
security_opt:
- no-new-privileges
healthcheck:
test: curl -sf -m 4 http://localhost:3000/healthcheck -o /dev/null || exit 1
start_period: 10s
timeout: 5s
For any share that has "Allow public user to upload" enabled inside Immich, an upload button will automatically appear in the gallery at top-right.