Published Jul 17, 2026, 8:30 AM EDT His love of PCs and their components was born out of trying to squeeze every ounce of performance out of the family computer. Tinkering with his own build at age 10 turned into building PCs for friends and family, fostering a passion that would ultimately take shape as a career path. Besides being the first call for tech support for those close to him, Ty is a computer science student, with his focus being cloud computing and networking. He also competed in semi-pro Counter-Strike for 8 years, making him intimately familiar with everything to do with peripherals. For someone who's tech-inclined like myself, Immich can easily fully replace Google Photos, but for someone who isn't, it's probably 90% there. That last 10% can feel like an insurmountable gap for non-techie folk like my family, who probably think VPN stands for "very prudent news." My library is full of photos my parents and siblings want to see, and for months, the answer to "can you send me those?" was me exporting albums in full, something I wanted to avoid in the first place. Then, when I switched to NetBird for remote access to my home lab, I realized I could simply expose my Immich front-end via a reverse proxy. That way, all that stood between my family from the photos I wanted them to see was a link and a couple of passwords. A VPN client was never going to happen Installing something is a bridge too far, even when it's simple The obvious way to share a self-hosted service is to put everyone on your network. Tailscale, plain WireGuard, and NetBird's own agent all handle this well, and if your audience is even a little bit technical, that's probably where this journey starts and stops. Unfortunately, mine isn't, and this means I need to get crafty to address remote access. Asking my parents to install a VPN client and log into an identity provider every time they want to see photos just wasn't going to work, even if it's not all that different from the solution I came up with. The other traditional routes had their own problems. Port forwarding puts Immich's login page directly on the open internet, and that's off the table anyway, since my ISP put me behind CGNAT. Cloudflare Tunnel works, but it's not great for large amounts of data like you would be dealing with in the case of a photo and video library. It's also not hosted on my own infrastructure, which I consider to be a con. What I wanted was a public URL with authentication in front of it, terminating on infrastructure I control, and that's precisely what NetBird's reverse proxy is. Introduced in version 0.65, it's built into the management server and exposes internal services through the mesh, with TLS termination and authentication handled at the proxy layer. My Immich container never gets a public IP and no ports open on my home network. Traffic hits the proxy on my VPS, passes the authentication gate, and rides the existing WireGuard tunnel down to the Immich LXC on my Proxmox box. From my family's side, none of that machinery exists. There's a URL, a password prompt, and then their photos. Setup was already done I just had to provide them with credentials Since I self-host NetBird, there was some groundwork. Self-hosted deployments need Traefik in front of the management server, because the reverse proxy feature depends on TLS passthrough that other proxies don't provide, and if your existing deployment runs Nginx or Caddy, that means a migration. You also need a wildcard DNS record pointing service subdomains at your server, port 443 reachable for automatic certificate provisioning, and a separate proxy container connected to the management server. NetBird publishes a migration guide that walks through adding all of this to an existing deployment, and it took me an afternoon. The good news is, I set all of this up for my own access long before my family wanted it, so the only work that was left was trivial. Exposing Immich itself is a single dashboard page. Under Reverse Proxy, you add a service, choose a subdomain, and point the target at the peer where Immich lives. NetBird provisions the domain and TLS certificate on its own. On the authentication tab for the service I created, I enabled password protection, set a strong shared password, and sent it to my family through a channel that wasn't the same as the link. Sessions persist via tokens after the first login, so they aren't retyping it every visit. Everyone gets a real account, but I control the private door Two walls of authentication A shared password gets family through the proxy, but the better half of this setup is what's behind it. Rather than pointing everyone at public share links, I created individual Immich accounts, so each person logs in with their own credentials and gets their own library, shared albums, and partner sharing. It behaves far more like the Google Photos experience they left than a folder of exported JPEGs ever could. The honest wrinkle is that this means two logins on a first visit: the proxy password, then their Immich credentials. In practice, both sessions persist, so it's a one-time toll rather than a recurring one. The same reverse proxy also handles the opposite requirement. Some things, like the Immich admin panel and the rest of my home lab dashboards, should never be reachable from the public internet at all. NetBird's answer is NetBird-Only access, added in version 0.72, which makes a service private: there's no login page, and the proxy instead verifies that the request comes from a peer inside your NetBird network belonging to an approved group. Peer identity is the credential, and because NetBird-Only is mutually exclusive with password authentication on the same service, the pattern for a backend that needs both is two services on different subdomains, one public and password-gated for family, one private for my own devices. There are real caveats to this approach You need a VPS that isn't bandwidth limited The whole thing presumes you're already running a self-hosted NetBird server on a VPS. If you're starting from zero, a tunnel service will get you a public URL faster. Every byte of my family's photo browsing also hairpins through that VPS, so your practical ceiling is whatever bandwidth and transfer allowance your provider gives you, and photo libraries are not light traffic. And because the password gate is a browser flow, the Immich mobile app can't get through it; this is a browser-only experience for everyone on the outside, but you could feasibly switch to NetBird-Only access for the service and lock it behind the mesh VPN, and then you could hit it from the app just fine, but that's the friction I'm trying to avoid with non-techie family. This is the best version of sharing a library with my family The test I'd apply to any family-facing home lab service is if the weakest link tech knowledge-wise can still access the system, and in this case, they can. A link and a password passes that test easily, and while installing a VPN and getting past the initial setup really isn't that complicated, it's still foreign enough that something else had to be deployed. NetBird's reverse proxy is in beta and has sharp edges on the admin side, but it moved my Immich library from something I use into something we use. Immich Key highlights Self-hosted iOS compatible Yes
My family can now browse my self-hosted photos from anywhere, but not the way you'd think
Full Article
Original Source
Read the full article at Xda-developers →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.