Container management of the base platform: official Portainer CE, non-root, linux/amd64 and arm64
434
The container management of the base platform: the official Portainer CE, unchanged, made to run as a non-root user behind a proxy that limits what it may do with Docker.
Not a general-purpose Portainer image. It is set up for one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use the official image.
One tag per release, X.Y.Z, the same version as the other base-* images of that release. There is
no latest: deployments reference a version and its digest.
Platforms: linux/amd64, linux/arm64.
portainer/portainer-ce, pinned by digest, unchanged: the program and its web interfacewget; the official image has no shell or toolsnobody, so that a new volume can be written without root9000 only, Docker at tcp://portainer-proxy:2375Portainer never gets the Docker socket. It talks to a socket proxy over TCP, which lets through reading and the start, stop, restart and kill of containers, and refuses everything else: creating or removing, exec, builds and pulls, and copying files out of containers or images. TLS ends at the reverse proxy in front of it.
| Path | Content |
|---|---|
/data | users and settings; keep it in a volume |
services:
portainer:
image: christianmaier/base-portainer:X.Y.Z
command: ["--http-enabled", "-H", "tcp://portainer-proxy:2375", "--admin-password=<bcrypt hash>"]
volumes: ["portainer-data:/data"]
networks: [portainer-web, portainer-api]
read_only: true
cap_drop: ["ALL"]
security_opt: ["no-new-privileges:true"]
healthcheck:
test: ["CMD", "/bin/busybox", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:9000/api/system/status"]
networks:
portainer-web:
internal: true
portainer-api:
internal: true
volumes:
portainer-data: {}
--admin-password takes a bcrypt hash and applies only on the first start; later starts skip it once
an administrator exists. Without it, Portainer waits for the administrator to be created in the
browser.
nobody, needs no capabilities, read-only root filesystemContent type
Image
Digest
sha256:2bfb81164…
Size
43.5 MB
Last updated
1 day ago
docker pull christianmaier/base-portainer:2.9.4