Sharing a large Immich library without melting the server

I share a photo library between two Immich users, my photos visible in my partner’s account, using an external library. Instead of uploading, Immich points at a folder on disk and imports whatever it finds there. It’s a lovely setup right up until the library gets big. Mine is big: over 750,000 photos, with more than half a million in a single external library.

Running out of memory

My server was struggling, chewing into swap all the time and running out of memory.

microservices worker error: Error [ERR_WORKER_OUT_OF_MEMORY]:
Worker terminated due to reaching memory limit: JS heap out of memory

I had Immich running in a 6GB Docker container but reduced that to 4GB for other reasons, and it appeared to work ok for a while, but it took a while for me to notice it was using the entirety of the 4GB of RAM. I increased the RAM allocated to the container, but it was still a heavy user.

The library watcher

External libraries have two ways to notice new files. There’s a periodic scan, which I’d already disabled because it’s brutal at this size. And there’s the watcher, which uses filesystem notifications to spot new files the moment they land. That’s what makes photos I add show up automatically.

The watcher is the convenient one. It’s also the expensive one. Watching a folder tree with 750,000 files means holding an enormous number of filesystem watches plus the bookkeeping that goes with them, and on my library that was around 3GB of resident memory, sitting there permanently doing nothing most of the time.

I turned it off in the admin settings. Memory use went from ~4GB pinned at the limit to about 1GB. Nightly jobs suddenly had room to breathe and the crash loop stopped.

Except now new photos don’t get imported, because the watcher was the thing importing them. So: how do you add a photo to a huge external library without a watcher and without a full scan?

The obvious fix that doesn’t work

Immich has an API endpoint to scan a library:

POST /api/libraries/{id}/scan

It scans the whole library. On my photo archive that’s a long, heavy crawl, and I’d already learned the hard way what a scan does to this box. Not something you run every time you drop in a picture.

Enqueue the import job yourself

So I went looking at what the watcher actually does when it sees a new file, expecting something complicated. It’s almost nothing. It queues one background job:

jobRepository.queue({
    name: 'LibrarySyncFiles',
    data: { libraryId, paths: [path] },
})

LibrarySyncFiles takes an explicit list of paths and imports exactly those files, without crawling the other 500,000. The per-file import I wanted was already sitting there. The watcher was only ever the trigger, and I was paying 3GB for the trigger.

I can pull that trigger myself. Immich uses BullMQ (backed by Redis/Valkey) for its job queue, so I can push the same job onto the same queue. The photos I add already go through a little script that moves them into the library folder by date, so the import hooks straight into that. When the script moves a new file in, it queues a LibrarySyncFiles job for that exact file:

docker exec -w /usr/src/app/server immich_server node -e '
  const { Queue } = require("bullmq");
  const q = new Queue("library", {
    prefix: "immich_bull",
    connection: { host: "redis", port: 6379 },
  });
  q.add("LibrarySyncFiles", {
    libraryId: "your-library-id",
    paths: ["/path/inside/the/container/to/new-photo.jpg"],
  }).then(() => q.close());
'

Immich picks it up, runs its normal import pipeline on that one file (metadata, thumbnails, the lot) and the photo appears. No watcher sitting on gigabytes of RAM, no full-library scan, and new photos still land within a cycle of my import script.

The caveats, because this is a hack

It leans on Immich’s internals, so: only send files that are genuinely new. The job handler inserts unconditionally, so hand it a path that’s already imported and you get a duplicate-key error in the logs. My script only queues files it actually moved.

More seriously, this is an internal job queue, not a public API. The queue name, the job name and the payload shape are implementation details, and an upgrade could rename or reshape any of them. The failure mode is silent: photos would just quietly stop importing and I wouldn’t find out until I went looking for one. My script shouts if the enqueue fails, which covers some of that but not all of it. This was working on Immich 3.0.2.

And turning off the watcher also turns off deletion detection, since the watcher is what removes assets when their files vanish. My workflow only ever adds files, so it doesn’t bite me. It might bite you.

There is a discussion here asking for an API endpoint to scan single files, but it hasn’t received much attention in 2 years, so I guess not many people have this issue, or realise it is an issue.

Was it worth it?

For a library this size, yes. About 3GB of RAM back, no more crash loop, and photos still import on their own. If your external library is small this is all irrelevant, so leave the watcher on and get on with your life. But if you’re in the hundreds of thousands of files and your server keeps falling over, check the watcher first.

Playing around with Immich again

Immich Logo

Immich is a self-hosted Google Photos. That’s the simplest way to describe it. It can run in a Docker container and will happily live on your local network, without access to the Internet unless you want to. They do warn you that, “The project is under very active development”, so bugfixes are happening all the time. At the same time, bugs are sometimes introduced, and breaking changes are sign posted weeks in advance.

Immich. How do you pronounce it? I say it with a hard “CH” at the end, but others will say it sounds more like “image”, which leads me to think that’s probably the way to pronounce it.

It looks uncannily like Google Photos. It doesn’t have all the bells and whistles of it’s older, proprietary inspiration, but it does have some very useful features.

I love the face and object recognition in Immich. I can search by people on the Explore page, and search for objects too. It doesn’t present animals on the Explore page, but searching for “chihuahua” leads me to lots of photos of Diego. It’s face recognition that doesn’t go to feeding a gigantic corporation too. It works pretty well, but make sure your Docker install has enough RAM, or it will silently fail.

A screenshot of the Immich mobile app showing a search for chihuahua and thumbnails of my dog.

It has partner sharing too, which is of course a handy feature for families. I noticed that partner shared photos can’t be discovered through the Explore page, where you find face recognition and places. There’s a GitHub issue about this, so it’s something they’re aware of. To be fair, Google Photos has the same limitation (I think) unless you’ve copied the photos to your account, using your precious free space.

To get around this limitation, I symlink any shared photos to my wife’s account. I use External Libraries for 99% of my photos, and 100% of the photos that come from Adobe Lightroom. I export photos to “single” or “shared” directories, and a shell script moves them all to my Immich External Library, and symlinks the shared photos to my wife’s one. On the External Libraries admin page, I simply “Scan new library files” to import the symlinked files. Immich is smart enough to pick up the new files in my External Library. Files are scanned twice, with thumbnails made twice, and face recognition done twice, but the overhead in space used isn’t too bad.

The Quick Start docs tell you to use Docker to install, and if you are at all familiar with Docker, this should be easy enough to follow.

When you do get Immich installed, make sure you perform backups. I have all the images stored elsewhere, but I back up the database file with the docker command listed on that page. Syncthing copies it to another machine, where it’s backed up daily.

Another option is the Nextcloud Memories app which is very slick and looks great. It has face and object recognition too, but it depends on another Nextcloud app to do those jobs. It doesn’t have partner sharing, however, which is the main reason I tried out Immich.

If you do decide to expose your Immich install to the Internet, take a look at Cosmos Cloud. There are other options too, like Caddy or Nginx Proxy Manager. Getting an HTTPS certificate has never been easier. If you don’t know your IP, have a look at https://checkip.amazonaws.com too.