github alangrainger/immich-public-proxy v4.0.0-alpha.3

pre-release5 hours ago

Warning

Alpha build for testing only. Do not use it in production. latest and the 3 tags are unchanged, so existing installs will not update to it.

v4.0 alpha

Visitors can upload photos (very much OPTIONAL)

To ensure IPP remains read-only by default, uploads work by running an optional second container alongside IPP. Turn on Allow public user to upload on a share in Immich, and the gallery shows an Add photos button.

Full guide: https://github.com/alangrainger/immich-public-proxy/blob/4.0/docs/visitor-uploads.md

No API key, same as always

IPP 4.0 still never asks for an Immich API key, and the main container is still read-only. The new upload feature runs in a separate, optional container that talks to Immich with the share's own key, exactly as Immich's public share page does when "Allow public user to upload" is on. If you don't add the upload container, nothing about IPP changes.

Breaking changes from 3.x

  • Immich 3.0.0 or newer is required. IPP checks the server version at startup and exits against an older Immich.
  • Old config keys are no longer read. Keys that 1.x to 3.x mapped to new names at startup are ignored in 4.0. The full list is at https://github.com/alangrainger/immich-public-proxy/blob/4.0/docs/config/upgrading.md
  • IPP will not start while showMetadata.exif.enabled or showMetadata.location.enabled is in your config. Remove the key, and set to true only the per-field flags for what visitors may see.
  • allowDownload takes only 0, 1 or 2. Any other value, such as true, turns downloads off.
  • A custom invalidRequestHandler.js must be copied again from the 4.0 image. A copy taken from 3.x fails to load.

Enabling uploads

Add the upload service to the docker-compose.yml that runs IPP, and set both package versions to 4.0.0-alpha.2:

services:
  immich-public-proxy:
    image: alangrainger/immich-public-proxy:4.0.0-alpha.3
    # ... your existing IPP service ...

  ipp-upload:
    image: alangrainger/immich-public-proxy-upload:4.0.0-alpha.3
    container_name: ipp-upload
    restart: always
    ports:
      - "3001:3000"
    environment:
      IMMICH_URL: http://your-internal-immich-server:2283
      PUBLIC_BASE_URL: https://your-proxy-url.com
    read_only: true
    cap_drop:
      - ALL
    security_opt:
      - no-new-privileges
    healthcheck:
      test: curl -sf -m 4 http://localhost:3000/healthcheck -o /dev/null || exit 1
      start_period: 10s
      timeout: 5s

For any share that has "Allow public user to upload" enabled inside Immich, an upload button will automatically appear in the gallery at top-right.

Don't miss a new immich-public-proxy release

NewReleases is sending notifications on new releases.