Deploying immich_server with alternative DB_PASSWORD not possible #5007

Closed
opened 2026-02-05 11:04:06 +03:00 by OVERLORD · 1 comment
Owner

Originally created by @manuveli on GitHub (Dec 23, 2024).

The bug

Within the deployment process I set the following as environment variable:

DB_PASSWORD=justatest

and receive the following error whenever starting immich_server:

`[Nest] 7 - 12/23/2024, 1:50:16 PM LOG [NestFactory] Starting Nest application...

[Nest] 7 - 12/23/2024, 1:50:16 PM ERROR [TypeOrmModule] Unable to connect to the database. Retrying (1)...

microservices worker exited with code 1`

Whenever I set DB_PASSWORD to default "postgres" it's working and the immich_server is fully starting.

Looks like just immich_server is affected as the other containers are starting in any case as they should.

I wonder if "postgres" as password is a default value within the image of immich_server and it's not being overwritten by the .env-variable?

Sorry if my description is not perfect, as I'm not a developer, trying my best :-) Merry Christmas!

The OS that Immich Server is running on

Portainer 2.21.4

Version of Immich Server

v1.123.0

Version of Immich Mobile App

v1.123.0

Platform with the issue

  • Server
  • Web
  • Mobile

Your docker-compose.yml content

#
# WARNING: Make sure to use the docker-compose.yml of the current release:
#
# https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml
#
# The compose file on main may not be compatible with the latest release.
#

name: immich

services:
  immich-server:
    container_name: immich_server
    image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release}
    # extends:
    #   file: hwaccel.transcoding.yml
    #   service: cpu # set to one of [nvenc, quicksync, rkmpp, vaapi, vaapi-wsl] for accelerated transcoding
    volumes:
      # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file
      - ${UPLOAD_LOCATION}:/usr/src/app/upload
      - /etc/localtime:/etc/localtime:ro
        #    env_file:
        #      - .env
    ports:
      - '2283:2283'
    depends_on:
      - redis
      - database
    restart: unless-stopped
    healthcheck:
      disable: false

  immich-machine-learning:
    container_name: immich_machine_learning
    # For hardware acceleration, add one of -[armnn, cuda, openvino] to the image tag.
    # Example tag: ${IMMICH_VERSION:-release}-cuda
    image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release}
    # extends: # uncomment this section for hardware acceleration - see https://immich.app/docs/features/ml-hardware-acceleration
    #   file: hwaccel.ml.yml
    #   service: cpu # set to one of [armnn, cuda, openvino, openvino-wsl] for accelerated inference - use the `-wsl` version for WSL2 where applicable
    volumes:
      - model-cache:/cache
        #    env_file:
        #      - .env
    restart: unless-stopped
    healthcheck:
      disable: false

  redis:
    container_name: immich_redis
    image: docker.io/redis:6.2-alpine@sha256:eaba718fecd1196d88533de7ba49bf903ad33664a92debb24660a922ecd9cac8
    healthcheck:
      test: redis-cli ping || exit 1
    restart: unless-stopped

  database:
    container_name: immich_postgres
    image: docker.io/tensorchord/pgvecto-rs:pg14-v0.2.0@sha256:90724186f0a3517cf6914295b5ab410db9ce23190a2d9d0b9dd6463e3fa298f0
    environment:
      POSTGRES_PASSWORD: ${DB_PASSWORD}
      POSTGRES_USER: ${DB_USERNAME}
      POSTGRES_DB: ${DB_DATABASE_NAME}
      POSTGRES_INITDB_ARGS: '--data-checksums'
    volumes:
      # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file
      - pgdata-immich:/var/lib/postgresql/data
    healthcheck:
      test: >-
        pg_isready --dbname="$${POSTGRES_DB}" --username="$${POSTGRES_USER}" || exit 1;
        Chksum="$$(psql --dbname="$${POSTGRES_DB}" --username="$${POSTGRES_USER}" --tuples-only --no-align
        --command='SELECT COALESCE(SUM(checksum_failures), 0) FROM pg_stat_database')";
        echo "checksum failure count is $$Chksum";
        [ "$$Chksum" = '0' ] || exit 1
      interval: 5m
      start_interval: 30s
      start_period: 5m
    command: >-
      postgres
      -c shared_preload_libraries=vectors.so
      -c 'search_path="$$user", public, vectors'
      -c logging_collector=on
      -c max_wal_size=2GB
      -c shared_buffers=512MB
      -c wal_compression=on
    restart: unless-stopped

volumes:
  model-cache:
  pgdata-immich:

Your .env content

## You can find documentation for all the supported env variables at https://immich.app/docs/install/environment-variables

# The location where your uploaded files are stored
UPLOAD_LOCATION=./library
# The location where your database files are stored
DB_DATA_LOCATION=./postgres

# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
# TZ=Etc/UTC

# The Immich version to use. You can pin this to a specific version like "v1.71.0"
IMMICH_VERSION=v1.123.0

# Connection secret for postgres. You should change it to a random password
# Please use only the characters `A-Za-z0-9`, without special characters or spaces
DB_PASSWORD=justatest

# The values below this line do not need to be changed
###################################################################################
DB_USERNAME=postgres
DB_DATABASE_NAME=immich
TZ=Europe/Berlin

Reproduction steps

  1. Fresh Deployment with env DB_PASSWORD=justatest --> immich_server not starting, can't connect
  2. Change env DB_PASSWORD=postgres --> immich_server starting and connecting successfully to DB

Relevant log output

Initializing Immich v1.123.0

Detected CPU Cores: 4

Starting api worker

Starting microservices worker

(node:7) [DEP0060] DeprecationWarning: The `util._extend` API is deprecated. Please use Object.assign() instead.

(Use `node --trace-deprecation ...` to show where the warning was created)

(node:7) [DEP0060] DeprecationWarning: The `util._extend` API is deprecated. Please use Object.assign() instead.

(Use `node --trace-deprecation ...` to show where the warning was created)

(node:17) [DEP0060] DeprecationWarning: The `util._extend` API is deprecated. Please use Object.assign() instead.

(Use `node --trace-deprecation ...` to show where the warning was created)

[Nest] 7  - 12/23/2024, 2:01:12 PM     LOG [NestFactory] Starting Nest application...

[Nest] 7  - 12/23/2024, 2:01:12 PM   ERROR [TypeOrmModule] Unable to connect to the database. Retrying (1)...

microservices worker exited with code 1

Killing api process

Additional information

No response

Originally created by @manuveli on GitHub (Dec 23, 2024). ### The bug Within the deployment process I set the following as environment variable: `DB_PASSWORD=justatest` and receive the following error whenever starting immich_server: `[Nest] 7 - 12/23/2024, 1:50:16 PM LOG [NestFactory] Starting Nest application... [Nest] 7 - 12/23/2024, 1:50:16 PM ERROR [TypeOrmModule] Unable to connect to the database. Retrying (1)... microservices worker exited with code 1` Whenever I set DB_PASSWORD to default "postgres" it's working and the immich_server is fully starting. Looks like just immich_server is affected as the other containers are starting in any case as they should. I wonder if "postgres" as password is a default value within the image of immich_server and it's not being overwritten by the .env-variable? Sorry if my description is not perfect, as I'm not a developer, trying my best :-) Merry Christmas! ### The OS that Immich Server is running on Portainer 2.21.4 ### Version of Immich Server v1.123.0 ### Version of Immich Mobile App v1.123.0 ### Platform with the issue - [X] Server - [ ] Web - [ ] Mobile ### Your docker-compose.yml content ```YAML # # WARNING: Make sure to use the docker-compose.yml of the current release: # # https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml # # The compose file on main may not be compatible with the latest release. # name: immich services: immich-server: container_name: immich_server image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release} # extends: # file: hwaccel.transcoding.yml # service: cpu # set to one of [nvenc, quicksync, rkmpp, vaapi, vaapi-wsl] for accelerated transcoding volumes: # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file - ${UPLOAD_LOCATION}:/usr/src/app/upload - /etc/localtime:/etc/localtime:ro # env_file: # - .env ports: - '2283:2283' depends_on: - redis - database restart: unless-stopped healthcheck: disable: false immich-machine-learning: container_name: immich_machine_learning # For hardware acceleration, add one of -[armnn, cuda, openvino] to the image tag. # Example tag: ${IMMICH_VERSION:-release}-cuda image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release} # extends: # uncomment this section for hardware acceleration - see https://immich.app/docs/features/ml-hardware-acceleration # file: hwaccel.ml.yml # service: cpu # set to one of [armnn, cuda, openvino, openvino-wsl] for accelerated inference - use the `-wsl` version for WSL2 where applicable volumes: - model-cache:/cache # env_file: # - .env restart: unless-stopped healthcheck: disable: false redis: container_name: immich_redis image: docker.io/redis:6.2-alpine@sha256:eaba718fecd1196d88533de7ba49bf903ad33664a92debb24660a922ecd9cac8 healthcheck: test: redis-cli ping || exit 1 restart: unless-stopped database: container_name: immich_postgres image: docker.io/tensorchord/pgvecto-rs:pg14-v0.2.0@sha256:90724186f0a3517cf6914295b5ab410db9ce23190a2d9d0b9dd6463e3fa298f0 environment: POSTGRES_PASSWORD: ${DB_PASSWORD} POSTGRES_USER: ${DB_USERNAME} POSTGRES_DB: ${DB_DATABASE_NAME} POSTGRES_INITDB_ARGS: '--data-checksums' volumes: # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file - pgdata-immich:/var/lib/postgresql/data healthcheck: test: >- pg_isready --dbname="$${POSTGRES_DB}" --username="$${POSTGRES_USER}" || exit 1; Chksum="$$(psql --dbname="$${POSTGRES_DB}" --username="$${POSTGRES_USER}" --tuples-only --no-align --command='SELECT COALESCE(SUM(checksum_failures), 0) FROM pg_stat_database')"; echo "checksum failure count is $$Chksum"; [ "$$Chksum" = '0' ] || exit 1 interval: 5m start_interval: 30s start_period: 5m command: >- postgres -c shared_preload_libraries=vectors.so -c 'search_path="$$user", public, vectors' -c logging_collector=on -c max_wal_size=2GB -c shared_buffers=512MB -c wal_compression=on restart: unless-stopped volumes: model-cache: pgdata-immich: ``` ### Your .env content ```Shell ## You can find documentation for all the supported env variables at https://immich.app/docs/install/environment-variables # The location where your uploaded files are stored UPLOAD_LOCATION=./library # The location where your database files are stored DB_DATA_LOCATION=./postgres # To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List # TZ=Etc/UTC # The Immich version to use. You can pin this to a specific version like "v1.71.0" IMMICH_VERSION=v1.123.0 # Connection secret for postgres. You should change it to a random password # Please use only the characters `A-Za-z0-9`, without special characters or spaces DB_PASSWORD=justatest # The values below this line do not need to be changed ################################################################################### DB_USERNAME=postgres DB_DATABASE_NAME=immich TZ=Europe/Berlin ``` ### Reproduction steps 1. Fresh Deployment with env DB_PASSWORD=justatest --> immich_server not starting, can't connect 2. Change env DB_PASSWORD=postgres --> immich_server starting and connecting successfully to DB ### Relevant log output ```shell Initializing Immich v1.123.0 Detected CPU Cores: 4 Starting api worker Starting microservices worker (node:7) [DEP0060] DeprecationWarning: The `util._extend` API is deprecated. Please use Object.assign() instead. (Use `node --trace-deprecation ...` to show where the warning was created) (node:7) [DEP0060] DeprecationWarning: The `util._extend` API is deprecated. Please use Object.assign() instead. (Use `node --trace-deprecation ...` to show where the warning was created) (node:17) [DEP0060] DeprecationWarning: The `util._extend` API is deprecated. Please use Object.assign() instead. (Use `node --trace-deprecation ...` to show where the warning was created) [Nest] 7 - 12/23/2024, 2:01:12 PM LOG [NestFactory] Starting Nest application... [Nest] 7 - 12/23/2024, 2:01:12 PM ERROR [TypeOrmModule] Unable to connect to the database. Retrying (1)... microservices worker exited with code 1 Killing api process ``` ### Additional information _No response_
Author
Owner

@danieldietzler commented on GitHub (Dec 23, 2024):

The correct password must be set on initial startup of the DB, since that's the when this stuff is configured. If you later want to change it you need to do that manually in the DB

@danieldietzler commented on GitHub (Dec 23, 2024): The correct password must be set on initial startup of the DB, since that's the when this stuff is configured. If you later want to change it you need to do that manually in the DB
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: immich-app/immich#5007