Portainer Community Edition (CE) is a free web interface for managing Docker. From your browser you can start and stop containers, read their logs, open a console, deploy Compose stacks and manage images, networks and volumes. In this tutorial you will run Portainer CE as a container on Ubuntu 24.04, create the administrator account, connect it to the local Docker environment and learn how to update it.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 1 GB of RAM.
- A non-root user with
sudoprivileges. - Docker Engine installed from Docker's official repository. Check it with
docker --version. - Port 9443/tcp reachable from your computer.
ImportantPortainer mounts the Docker socket, and anyone who can control Docker can gain root access to the host. Treat the Portainer admin account like a root password and do not expose it more than necessary.
Step 1 - Creating a volume for Portainer data
Portainer stores its settings, users and stack definitions in /data inside the container. Put that directory in a named volume so it survives container updates:
sudo docker volume create portainer_data
Verify that the volume exists:
sudo docker volume ls
DRIVER VOLUME NAME
local portainer_data
Step 2 - Running the Portainer container
Start Portainer CE with the following command:
sudo docker run -d \
-p 9443:9443 \
--name portainer \
--restart=always \
-v /var/run/docker.sock:/var/run/docker.sock \
-v portainer_data:/data \
portainer/portainer-ce:lts
What each option does:
-p 9443:9443publishes the web interface over HTTPS. Portainer generates a self-signed certificate on first start.--restart=alwaysstarts Portainer again after a reboot or a crash.-v /var/run/docker.sock:/var/run/docker.socklets Portainer manage the local Docker engine.-v portainer_data:/datakeeps Portainer's data in the volume from Step 1.portainer/portainer-ce:ltsuses the long-term support release, which is the channel Portainer recommends for production.
Older guides publish port 9000 for plain HTTP. Current Portainer versions serve the interface over HTTPS on 9443, so you do not need port 9000. Port 8000 is only used by Edge Agents on remote hosts; publish it with -p 8000:8000 only if you plan to use them.
Check that the container is running:
sudo docker ps --filter name=portainer
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
3f2a9c1d8e7b portainer/portainer-ce:lts "/portainer" 20 seconds ago Up 19 seconds 8000/tcp, 9000/tcp, 0.0.0.0:9443->9443/tcp, [::]:9443->9443/tcp portainer
Confirm that the interface responds on the server:
curl -sk -o /dev/null -w '%{http_code}\n' https://localhost:9443
200
Step 3 - Controlling access to port 9443
Docker writes its own iptables rules for published ports, and those rules are evaluated before UFW's. A port published with -p 9443:9443 is therefore reachable from the Internet even if UFW does not allow it. Choose one of these approaches:
- Keep port 9443 open and rely on HTTPS and a strong admin password. This is the simplest option.
- Restrict access at the network level with a firewall in front of the server that only allows your IP address to reach 9443.
- Publish only on localhost and reach Portainer through an SSH tunnel. Run the container with
-p 127.0.0.1:9443:9443instead of-p 9443:9443, then open the tunnel from your computer:
ssh -L 9443:127.0.0.1:9443 your_user@your_server_ip
With the tunnel open, browse to https://localhost:9443 on your computer.
Step 4 - Creating the administrator account
Open the interface in your browser, replacing your_server_ip with your server's IP address:
https://your_server_ip:9443
The browser warns about the self-signed certificate. Accept it to continue.
Portainer asks you to create the initial administrator. Enter a username and your_strong_password (at least 12 characters), then click Create user.
NoteFor security, Portainer only waits 5 minutes for the initial administrator to be created. If you see a message saying the instance timed out, restart the container with
sudo docker restart portainerand reload the page.
Step 5 - Connecting the local Docker environment
After you log in, the Environment Wizard opens. Click Get Started to use the local environment, which is the Docker engine Portainer is running on through the mounted socket.
Open Home and select the environment named local. The dashboard shows the number of containers, images, volumes and networks. To confirm that Portainer sees the same containers as the command line, open Containers: the portainer container should be listed as running, just like in the docker ps output from Step 2.
From here you can:
- Deploy Compose files from Stacks > Add stack.
- Read logs and open a shell from a container's Logs and Console buttons.
- Remove unused images and volumes from Images and Volumes.
Step 6 - Updating Portainer
Portainer keeps all its data in the portainer_data volume, so updating means replacing the container with a new image. Pull the latest image first:
sudo docker pull portainer/portainer-ce:lts
Stop and remove the current container. Your data stays in the volume:
sudo docker stop portainer
sudo docker rm portainer
Start it again with the same command from Step 2:
sudo docker run -d \
-p 9443:9443 \
--name portainer \
--restart=always \
-v /var/run/docker.sock:/var/run/docker.sock \
-v portainer_data:/data \
portainer/portainer-ce:lts
Log in again and check the version shown at the bottom of the left menu.
Troubleshooting
- The page does not load. Check the container with
sudo docker ps -a --filter name=portainerand read its logs withsudo docker logs portainer. Make sure you are usinghttps://and port 9443, not port 9000. - "Your Portainer instance timed out for security purposes". The admin account was not created within 5 minutes. Run
sudo docker restart portainerand create it right away. - Forgot the admin password. Portainer CE has no password reset in the interface. Portainer publishes a
portainer/helper-reset-passwordimage for this case; follow the password reset procedure in the official Portainer documentation.
Conclusion
Portainer CE is now running on Ubuntu 24.04 over HTTPS, connected to the local Docker engine and storing its data in a persistent volume. As next steps, deploy your first application from Stacks with a Compose file, and consider putting Portainer behind a reverse proxy with a trusted Let's Encrypt certificate, or keeping it on localhost behind an SSH tunnel.
