Smart search, face detection and OCR were all failing with Machine learning request to "http://immich-machine-learning:3003" failed while the container still reported Up. Podman only sees PID 1: gunicorn's master was alive and holding the listening socket, but its worker had died at a WORKER TIMEOUT and was never respawned -- hence a connect timeout rather than a refusal. The dead worker was a zombie whose remaining thread was stuck in uninterruptible sleep in exit_mmap, so it survived SIGKILL, podman rm -f and rm -f -t 0, and kept the container name and network alias until the host was rebooted. MACHINE_LEARNING_MODEL_TTL=0 addresses the cause rather than the symptom. The default unloads models after 300s idle, so every search following a gap reloaded four of them (CLIP, buffalo_l detection + recognition, PP-OCRv5) on a CPU-only 4-core box and then tore those mappings back down -- and that teardown is what wedged. Keeping them resident costs ~1-2 GB and removes the path. IMMICH_MACHINE_LEARNING_URL is now set explicitly instead of relying on immich's implicit default, so the ML container can be renamed without silently losing search, and the name is a variable so a replacement can be stood up beside a broken one without editing tasks. Verified after deploy: zero ML failures, "in-memory cache with unloading disabled", ping 200 from immich-server, 26/26 containers healthy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Deploy Home
There's no place like home!
Just as Dorothy managed the simple task of clicking her heels together, the desire for an equally simple one-button push deployment was in my heart. Thus, this repository was made.
Ansible
Ansible, along with double encrypted secrets, deploys the necessary configurations to make the home fit for certain needs and desires. Namely, having access to my home from anywhere, securely, and a self-hosted CI server that easily ties into existing workflows.
Makefile
The makefile is primarily used as a wrapper script to ensure that necessary
files, such as the secret vault password file, are provisioned as part of this.
One such addition to the task is utilizing dependency pinning through the
utilization of Python's virtualenv to lock down the specific dependency
versions within the requirements.txt file. This, ideally, prevents any
deployment issues with dependency version woes (e.g. version conflicts, major
updates in newest versions, etc.)
| Target Name | Description |
|---|---|
lint |
(default) Runs yamllint and ansible-lint on all YAML files in ansible/ |
deploy |
Deploys everything, or only tasks specified in TAGS= environment variable |
check |
Runs deploy in a "dry-run", showing diff-style outputs on tasks indicating changes |
vault |
Opens the Ansible vault file for editing |