# Immich stack environment variables - EXAMPLE # Copy this to immich.env (untracked, see .gitignore) and fill in # IMMICH_KIOSK_BASICAUTH with a real value. Do NOT commit immich.env. # # Pattern C (partial): DB_PASSWORD as Docker secret (_FILE), IMMICH_KIOSK_BASICAUTH # in host .env (Traefik label). # # NOTE 2026-08-26: the paths below are the REAL, confirmed-correct values for # this homelab (verified via `docker service inspect immich_ --format # '{{json .PreviousSpec.TaskTemplate.ContainerSpec.Mounts}}'` against actual # on-disk data). An earlier version of this file had plausible-looking but # WRONG generic paths (/volume1/docker/immich/db, /volume1/docker/immich/uploads), # which caused a real incident when immich.env was regenerated from this # template without checking against the live services first. If you ever # need to regenerate immich.env from this file, these paths should still be # correct — but if in doubt, re-verify with the PreviousSpec command above # before deploying. IMMICH_VERSION=release UPLOAD_LOCATION=/volume1/Immich-Photos/ BULK_UPLOAD_LOCATION=/volume1/Immich-Photos/bulk-upload DB_DATA_LOCATION=/volume1/docker/immich-postgresql REDIS_DATA_LOCATION=/volume1/docker/immich/redis DB_USERNAME=immich DB_DATABASE_NAME=immich DB_HOSTNAME=immich_postgresql DB_PORT=5432 REDIS_HOSTNAME=immich_redis REDIS_PORT=6379 REDIS_DBINDEX=0 IMMICH_TRUSTED_PROXIES=172.16.0.0/12 IMMICH_TRAEFIK_HOST=immich.bryanmail.net IMMICH_KIOSK_HOST=immich-kiosk.bryanmail.net IMMICH_KIOSK_BASICAUTH=user:changeme