# Portainer
Portainer is a web UI to manage containers. You deploy it as a container, give it access to the Docker socket, and you get a dashboard in the browser to start, stop, inspect and remove containers, and to clean up the images, volumes and networks they leave behind. It started in 2016, and it's by far the best known tool in this category (38K+ stars on [[GitHub]]).
What sets it apart is the breadth. Portainer doesn't only talk to [[Docker]]. It also manages Docker Swarm clusters, [[Kubernetes]] clusters and [[Podman]] hosts, from one interface. Remote machines connect through the Portainer Agent, or through the Edge Agent when the host sits behind NAT and has to call home.
## Community edition vs business edition
Portainer comes in two flavors:
- **Community Edition (CE)**: [[Open Source]] (Zlib license), free. The project itself describes it as meant for homelabs and learning, provided as-is, without support
- **Business Edition (BE)**: commercial. Adds RBAC, SSO, audit logs, GitOps features, edge management and support
Over the years, more and more of the interesting features moved to the Business Edition. CE still does the basics well, but you feel the upsell.
## Stacks
Portainer calls a [[Docker Compose]] project a "stack". You paste a compose file in the editor, or point Portainer to a [[Git]] repository, and it deploys it.
Keep in mind that Portainer wants to OWN those stacks. It stores them in its own data volume. Stacks you started from the command line show up, but with limited control. If your compose files already live in a Git repository and you deploy them with a script, Portainer and your workflow will fight each other.
## My take
Portainer makes sense when you manage several hosts or a mix of Docker and Kubernetes, and when you want to give other people access with roles. For a single [[Virtual Private Server (VPS)]] with a handful of compose projects, it's more than I need. [[Dockge]] or [[Arcane]] fit better there, because they read and write the compose files where they already are.
Security first: Portainer mounts `/var/run/docker.sock`, and access to that socket is root access to the host. Never expose the UI publicly. Bind it to localhost and reach it through [[Tailscale]], a [[Cloudflare Tunnel]] with access control, or an SSH tunnel ([[Secure Shell (SSH)]]).
## References
- https://www.portainer.io/
- https://github.com/portainer/portainer
- https://docs.portainer.io/
## Related
- [[Dockge]]
- [[Arcane]]
- [[Coolify]]
- [[LazyDocker]]
- [[Docker]]
- [[Docker Compose]]
- [[Docker Desktop]]
- [[Kubernetes]]
- [[Podman]]
- [[Containerization]]
- [[Self-hosting]]
- [[Virtual Private Server (VPS)]]