为 Immich 配置反向代理

可以部署自定义反向代理,将请求转发到 Immich。这样可以由反向代理处理 TLS 终止、负载均衡及其他高级功能。位于用户和 Immich 之间的所有反向代理都必须转发全部请求头,并为 Host、X-Real-IP、X-Forwarded-Proto 和 X-Forwarded-For 设置合适的值。此外,反向代理还应允许足够大的上传文件。遵循这些做法,可以保证自定义反向代理与 Immich 兼容。

caution

Immich 不支持部署在子路径下,例如 location /immich {。必须通过一个域名或子域名的根路径提供服务。

info

如果反向代理使用 Let’s Encrypt 的 http-01 验证方式,应确认 Immich 的 well-known 端点 /.well-known/immich 被正确转发到 Immich。否则,这个请求可能被路由到其他位置,导致移动应用连接出现问题。

Nginx 配置示例

下面是 nginx 配置示例。请将 public_url 设置为实例面向用户的访问 URL,将 backend_url 设置为 Immich 服务器的地址。

server {    server_name <public_url>;    # allow large file uploads    client_max_body_size 50000M;    # disable buffering uploads to prevent OOM on reverse proxy server and make uploads twice as fast (no pause)    proxy_request_buffering off;    # increase body buffer to avoid limiting upload speed    client_body_buffer_size 1024k;    # Set headers    proxy_set_header Host              $host;    proxy_set_header X-Real-IP         $remote_addr;    proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;    proxy_set_header X-Forwarded-Proto $scheme;    # enable websockets: http://nginx.org/en/docs/http/websocket.html    proxy_http_version 1.1;    proxy_redirect     off;    # set timeout    proxy_read_timeout 600s;    proxy_send_timeout 600s;    send_timeout       600s;    location / {        proxy_pass http://<backend_url>:2283;        proxy_set_header   Upgrade    $http_upgrade;        proxy_set_header   Connection "upgrade";    }    # useful when using Let's Encrypt http-01 challenge    # location = /.well-known/immich {    #     proxy_pass http://<backend_url>:2283;    # }}

Caddy 配置示例

除 nginx 之外,也可以使用 Caddy 作为反向代理,并利用其自动 HTTPS 配置。下面是一个配置示例。

immich.example.org {    reverse_proxy http://<snip>:2283}

Apache 配置示例

下面是 Apache2 站点配置示例。

<VirtualHost *:80>   ServerName <snip>   ProxyRequests Off   # set timeout in seconds   ProxyPass / http://127.0.0.1:2283/ timeout=600 upgrade=websocket   ProxyPassReverse / http://127.0.0.1:2283/   ProxyPreserveHost On</VirtualHost>

Traefik Proxy 配置示例

以下示例适用于 Traefik 3。

最重要的是增加 Immich 所使用入口点的 respondingTimeouts。本例使用端口 443 对应的 websecure 入口点。默认超时为 60 秒,会导致视频上传在一分钟后停止,并返回 499 错误。下面的配置将超时延长到 10 分钟,通常已经足够;如有需要,可以继续增大。

traefik.yaml

[...]entryPoints:  websecure:    address: :443    # this section needs to be added    transport:      respondingTimeouts:        readTimeout: 600s        idleTimeout: 600s

第二部分位于运行 Immich 的 docker-compose.yml 文件中。按照示例添加 Traefik 专用标签。

docker-compose.yml

services:  immich-server:    [...]    labels:      traefik.enable: true      # increase readingTimeouts for the entrypoint used here      traefik.http.routers.immich.entrypoints: websecure      traefik.http.routers.immich.rule: Host(`immich.example.com`)      traefik.http.services.immich.loadbalancer.server.port: 2283

请注意,Traefik 必须能够访问 Immich 所在的网络。通常可以通过将 immich-server 加入 Traefik 网络来实现。


原文:Reverse Proxy。作者/来源:Immich 文档贡献者。本文依据所列原文整理为中文,代码、命令与配置示例保留原文。

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容