Sign inSign up

christianmaier/base-portainer

By christianmaier

•Updated 1 day ago

Container management of the base platform: official Portainer CE, non-root, linux/amd64 and arm64

Image
Monitoring & observability
0

434

christianmaier/base-portainer repository overview

⁠base-portainer

The container management of the base platform: the official Portainer CE⁠, unchanged, made to run as a non-root user behind a proxy that limits what it may do with Docker.

Not a general-purpose Portainer image. It is set up for one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use the official image⁠.

⁠Tags

One tag per release, X.Y.Z, the same version as the other base-* images of that release. There is no latest: deployments reference a version and its digest.

Platforms: linux/amd64, linux/arm64.

⁠What is inside

  • portainer/portainer-ce, pinned by digest, unchanged: the program and its web interface
  • A static busybox, used only by the healthcheck's wget; the official image has no shell or tools
  • A data directory owned by nobody, so that a new volume can be written without root
  • Defaults: HTTP on port 9000 only, Docker at tcp://portainer-proxy:2375

⁠Running

Portainer never gets the Docker socket. It talks to a socket proxy over TCP, which lets through reading and the start, stop, restart and kill of containers, and refuses everything else: creating or removing, exec, builds and pulls, and copying files out of containers or images. TLS ends at the reverse proxy in front of it.

PathContent
/datausers and settings; keep it in a volume
services:
  portainer:
    image: christianmaier/base-portainer:X.Y.Z
    command: ["--http-enabled", "-H", "tcp://portainer-proxy:2375", "--admin-password=<bcrypt hash>"]
    volumes: ["portainer-data:/data"]
    networks: [portainer-web, portainer-api]
    read_only: true
    cap_drop: ["ALL"]
    security_opt: ["no-new-privileges:true"]
    healthcheck:
      test: ["CMD", "/bin/busybox", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:9000/api/system/status"]
networks:
  portainer-web:
    internal: true
  portainer-api:
    internal: true
volumes:
  portainer-data: {}

--admin-password takes a bcrypt hash and applies only on the first start; later starts skip it once an administrator exists. Without it, Portainer waits for the administrator to be created in the browser.

⁠Security

  • Runs as nobody, needs no capabilities, read-only root filesystem
  • Docker only through a proxy that refuses every write except start, stop, restart and kill
  • Before every release and weekly: scanned for vulnerabilities with a fix (Trivy), for Dockerfile misconfigurations and for secrets (gitleaks). Known findings in the official image that this image cannot fix without rebuilding Portainer are listed with their reason and an expiry date in the platform's repository.
  • SBOM (SPDX) and build provenance attached to every release

Tag summary

Content type

Image

Digest

sha256:2bfb81164…

Size

43.5 MB

Last updated

1 day ago

docker pull christianmaier/base-portainer:2.9.4