Skip to content

Immich: document Tailnet access for remote machine learning - #360

Open
jackspiering wants to merge 1 commit into
mainfrom
immich-remote-ml-note
Open

jackspiering wants to merge 1 commit into
mainfrom
immich-remote-ml-note

Conversation

@jackspiering

Copy link
Copy Markdown
Collaborator

Summary

Adds a usage note to the Immich README for running the machine learning container on another Tailnet device.

Follow-up to a report in #298: Immich could not reach a remote machine learning container, and the tailscale service logged rejected due to acl for port 3003. The cause is the Tailnet policy, not the compose file, so this is documentation only.

The note covers:

  • The Tailnet policy must allow the Immich node to reach the machine learning host on TCP port 3003.
  • TS_USERSPACE=false must stay set, because Immich opens connections to the Tailnet.
  • The machine learning URL needs the host's Tailscale IP address, or its MagicDNS name with the dns block.

Checks

  • rumdl check --config .markdownlint.yml services/immich/README.md: passed
  • git diff --check: passed
  • docker compose config --quiet: not run, no compose file changed
  • Not tested against a live remote machine learning setup on a Tailnet

@jackspiering
jackspiering requested a review from crypt0rr October 3, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant