Documentation for the Portainer service used to manage Docker on Enclari.
web/opt/stack/system/docker-compose.yml (service in the system stack, container system-portainer-1)Portainer Gate, proxy provider in Forward auth (single application) mode, assigned to the Embedded OutpostPortainer, provider portainer-oidc) or the local admin account as fallbackwebsecure with Let's Encrypt DNS-01 Hetznersystem_portainer_dataA minimal pattern that works with Traefik + ForwardAuth. Choose one of the two service port options depending on your Portainer configuration.
services:
portainer:
image: portainer/portainer-ce:latest
container_name: portainer
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- portainer_data:/data
networks: [web]
restart: unless-stopped
labels:
- traefik.enable=true
- traefik.docker.network=web
- traefik.http.routers.portainer.rule=Host(`portainer.enclari.com`)
- traefik.http.routers.portainer.entrypoints=websecure
- traefik.http.routers.portainer.tls=true
- traefik.http.routers.portainer.tls.certresolver=le
- traefik.http.routers.portainer.middlewares=authentik-forwardauth@file,secure-headers@docker
# Option A: Portainer HTTPS on 9443 (default in recent versions)
- traefik.http.services.portainer.loadbalancer.server.port=9443
- traefik.http.services.portainer.loadbalancer.server.scheme=https
# Option B: Portainer HTTP on 9000 (older configs or if you explicitly enable it)
# - traefik.http.services.portainer.loadbalancer.server.port=9000
# - traefik.http.services.portainer.loadbalancer.server.scheme=http
volumes:
portainer_data:
networks:
web:
external: true
The middleware
authentik-forwardauth@fileis defined in/opt/stack/traefik/dynamic/authentik.ymland reused here.
Portainer Gate (Proxy Provider, forward auth single application, external host https://portainer.enclari.com). An OAuth2/OpenID provider cannot be used for ForwardAuth: the outpost only accepts Proxy Providers, otherwise Authentik returns Not Found.portainer-oidc). With an active Authentik session the OAuth button logs in without a password.Portainer Gate has no policy bindings (any Authentik user). TODO: compare with PMA and align.system stack: /opt/stack/system and volume system_portainer_data (tag service=system)./root/backup.sh backup system
/root/backup.sh list system
cd /opt/stack/system && docker compose stop portainer
rsync -aHAX --delete /opt/restore/system-<TS>/var/lib/docker/volumes/system_portainer_data/_data/ /var/lib/docker/volumes/system_portainer_data/_data/
docker compose up -d portainer
# Update Portainer
cd /opt/stack/system
docker compose pull portainer && docker compose up -d portainer
# Logs
docker compose logs -f --tail=200 portainer
# Health
curl -I https://portainer.enclari.com