Portainer EE
Overview
Portainer Enterprise Edition is the primary container management interface for Centerpoint. It provides a web UI for deploying stacks, viewing container logs, managing volumes and networks, and monitoring resource usage across the Docker environment.
All compose stacks are deployed and managed through Portainer rather than by
running docker compose directly on the host. Portainer stores stack definitions
internally (under /data/compose/) and rebuilds containers from those definitions
when updated.
Access
| Type | URL | Notes |
|---|---|---|
| Internal | https://portainer.home.local |
LAN access via Step-CA TLS |
| HTTPS UI | https://192.168.1.85:9443 |
Direct IP fallback |
| Tunnel | Port 8001 (agent) |
For Edge Agent / remote access |
Portainer does not have an external (internet-facing) Traefik route. Access is LAN-only or via Tailscale.
Configuration
Image: portainer/portainer-ee:latest
Compose project: portainer
Ports
| Port | Protocol | Purpose |
|---|---|---|
8001 |
TCP | Edge Agent tunnel port |
9443 |
TCP | HTTPS management UI (host-bound) |
Traefik Labels
traefik.enable: "true"
traefik.http.routers.portainer.rule: Host(`portainer.home.local`)
traefik.http.routers.portainer.entrypoints: websecure
traefik.http.routers.portainer.tls.certresolver: step-ca
traefik.http.services.portainer.loadbalancer.server.port: 9443
Internal-only route — no external Traefik router.
Volumes / Bind Mounts
| Host Path / Volume | Container Path | Purpose |
|---|---|---|
portainer_portainer_data |
/data |
Portainer state and stack data (named volume, external) |
/var/run/docker.sock |
/var/run/docker.sock |
Direct Docker socket access |
The
portainer_portainer_datavolume is declaredexternal: true— it must exist before the stack is started.
Note: Portainer mounts the Docker socket directly. This is intentional for Portainer EE; it is the only service with direct socket access.
Dependencies
- Docker socket (
/var/run/docker.sock) — no other service dependencies - Traefik on
traefik-netfor theportainer.home.localroute - Step-CA for the internal TLS certificate
Notes / Gotchas
- Portainer stores all deployed stack definitions under
/data/compose/<id>/v<version>/. These are the authoritative copies of each stack'sdocker-compose.ymlwhile managed through Portainer. Files under/home/jeeves/docker/may be out of date if a stack was edited directly in the Portainer UI. - Portainer EE licence key is stored in the Portainer UI and must be re-entered if
the
portainer_portainer_datavolume is lost. - The
portainer-ee:latesttag follows the latest stable EE release. Pin to a specific version (e.g.portainer-ee:2.22.0) before any planned maintenance to avoid unintended upgrades. - Portainer agent is not separately deployed on Centerpoint — Portainer connects to its local Docker daemon directly via the socket.
- Portainer does not work over Traefik - I have not been troubleshooting this, and is a future action or Task to manage
FUTURE WORK
- Identify issue with Portainer and Traefik interaction
- Migrate Portainer cert with Step-CA cert for consistent cert management
Last Updated: 2026-06-16