--- schema_version: 1 id: home-server.portainer type: reference scope: [jupiter, portainer, deployment, configuration-state] sensitivity: private-infrastructure last_reviewed: "2026-10-06" sources: - kind: owner-report reference: "Deployed container, ~/portainer_start.sh and updated Backrest plan, 2026-10-06" - kind: owner-report reference: "GitHub main/PAT access, Portainer environment values, manual redeployment and container inspection, 2026-10-06" - kind: repository repository: jupiter-stacks revision: working-tree base_revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15 paths: - stacks/portainer/portainer_start.sh related: [home-server.reference, home-server.storage, home-server.authentication, home-server.backups, home-server.deployment] update_triggers: [script-change, portainer-upgrade, state-migration, backup-plan-change] unknowns: [local-hostname-dns-resolution, successful-state-and-secret-restore] --- # Portainer ## Deployment Managed by handwritten `~/portainer_start.sh`, **not a Compose stack**. Reference script: [portainer_start.sh](https://github.com/jayo60013/jupiter-stacks). | Setting | Deployed value | | --- | --- | | Image | `portainer/portainer-ce:2.45.1` | | Container | `portainer` | | Restart policy | `always` | | Network | External Docker network `traefik` | | State | Host `/data/portainer` -> container `/data` | | Docker API | `/var/run/docker.sock` bind mount | | Host publication | TCP `9123` -> container `9000` | | HTTPS routers | `portainer.umbra.mom`, `portainer.local.umbra.mom` | | Traefik backend | HTTP; container port `9000` | | TLS | `https` entrypoint; `letsencrypt` resolver | Script stops/removes the existing container, then recreates it; bind-mounted state persists. Requires Docker, the `traefik` network, and mounted `/data`. Supplied routers attach no Authelia middleware. Local router does not establish local DNS resolution. ## Stack management Portainer fetches , branch `main`, using a GitHub PAT. Stack environment values/secrets are managed in Portainer. Repository changes are pulled/redeployed manually; committing alone does not update containers. See [deployment](deployment.md). ## Backups Daily 03:00 UTC; Google Drive; last four snapshots. Backrest reads `/userdata/portainer` from host `/data/portainer`. - Before snapshot: stop `portainer`; timeout `120s`; errors fatal. - Snapshot end/error: start `portainer`; restart errors ignored. - Restore remains untested; script itself is outside the listed backup paths. The former `portainer_data` named volume is not used by the deployed container.