
He mentions that he uses Hetzner’s volumes for storage and storage box for backups. Hetzner’s docs don’t mention anything about at-rest encryption and Immich does not encrypt data either, so anyone with access to the VPS or Hetzner account would be able to see them.
If you want end-to-end encryption I’d suggest self-hosting something like Ente

and I just found out that running
sudo apt full-upgrademay update your kernel which means you have to do the module setup again for the new kernel