Managed by handwritten ~/portainer_start.sh, not a Compose stack.
Reference script: portainer_start.sh.
Setting
Deployed value
Image
portainer/portainer-ce:2.45.1
Container
portainer
Restart policy
always
Network
External Docker network traefik
State
Host /data/portainer -> container /data
Docker API
/var/run/docker.sock bind mount
Host publication
TCP 9123 -> container 9000
HTTPS routers
portainer.umbra.mom, portainer.local.umbra.mom
Traefik backend
HTTP; container port 9000
TLS
https entrypoint; letsencrypt resolver
Script stops/removes the existing container, then recreates it; bind-mounted
state persists. Requires Docker, the traefik network, and mounted /data.
Supplied routers attach no Authelia middleware. Local router does not establish
local DNS resolution.
Stack management
Portainer fetches https://github.com/jayo60013/jupiter-stacks, branch main,
using a GitHub PAT. Stack environment values/secrets are managed in Portainer.
Repository changes are pulled/redeployed manually; committing alone does not
update containers. See deployment.
Backups
Daily 03:00 UTC; Google Drive; last four snapshots. Backrest reads
/userdata/portainer from host /data/portainer.
Before snapshot: stop portainer; timeout 120s; errors fatal.