Pin deployment inputs
Use the same release as this documentation build: its manifests, CLI and UI match these instructions, and a different version's won't. The promoted route vendors the published deployment bundle, whose packaging substitutes app/inference image tags and Terraform example pins. A raw source archive or floating Git URL skips those substitutions.
Download and verify
From an empty directory with curl, tar, shasum and awk installed:
set -eu
BUNDLE=immich-memories-deploy-1.0.0-rc.1.tar.gz
ASSETS=https://github.com/sam-dumont/immich-memories/releases/download/v1.0.0-rc.1
curl -fLO "$ASSETS/$BUNDLE"
curl -fLO "$ASSETS/SHA256SUMS"
awk -v bundle="$BUNDLE" '$2 == bundle {print}' SHA256SUMS > bundle.sha256
test -s bundle.sha256
shasum -a 256 -c bundle.sha256
mkdir -p vendor/immich-memories
tar -xzf "$BUNDLE" -C vendor/immich-memories
The generated commands pin this docs build's exact version, verify the bundle against its
published SHA-256 list and extract into vendor/immich-memories. Commit that clean vendored
tree and the recorded version/checksum. Keep your own overlay, credentials and state separate.
A development preview without published assets deliberately supplies no install command.
Kustomize
With kubectl/Kustomize installed, from the same directory:
kubectl kustomize vendor/immich-memories/deploy/kubernetes/base > rendered.yaml
The current base expects an existing immich-memories-secrets Secret. Supply the real reachable
Immich URL, minimum read key and app authentication outside Git using
the Secret setup, or SOPS/External Secrets. Choose the actual
cluster context and local/block StorageClass before applying. Never commit a credential-bearing
render or generated plaintext Secret. Your custom overlay can refer to the vendored base;
keep the bundle unchanged so the next update produces a useful diff.
Terraform
The bundle's example already has a real relative module path, ../../, and a release-pinned
image_tag. With Terraform 1.9+ installed:
terraform -chdir=vendor/immich-memories/deploy/terraform/examples/basic init -backend=false -input=false
terraform -chdir=vendor/immich-memories/deploy/terraform/examples/basic validate
Before plan/apply, configure your protected state backend and cluster provider, then copy
terraform.tfvars.example to a private terraform.tfvars and set Immich's URL/read key and
storage/authentication choices. -backend=false above is validation only. Retain the
versioned image pin. The module reference shows the module path
when called from a root configuration beside vendor.
Update and review
Download the next matching release bundle into a second directory, verify its checksum, then
diff -ru the two vendored deploy trees. Review image pins, PVCs, resource budgets, policies and
Secret-layout changes before updating your overlay. Commit .terraform.lock.hcl with the chosen
provider versions. Render/init/validate again before plan/apply; keep credentials, plans and state
out of the public repository.
The checksum detects changed bytes against the published value, not who built them. Provenance verification checks attested identity where supplied; neither validates your cluster configuration, network policies or secrets.
A packaging render check is not a live Kubernetes rollout, an observed QoS class, a provider connectivity test, or an Immich outage/recovery test. See the deployment matrix for what each route has actually verified.