Portainer Community Edition (CE) is a free web interface for managing Docker. From your browser you can start and stop containers, read their logs, open a console, deploy Compose stacks and manage images, networks and volumes. In this tutorial you will run Portainer CE as a container on Ubuntu 24.04, create the administrator account, connect it to the local Docker environment and learn how to update it.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 1 GB of RAM.
  • A non-root user with sudo privileges.
  • Docker Engine installed from Docker's official repository. Check it with docker --version.
  • Port 9443/tcp reachable from your computer.

Step 1 - Creating a volume for Portainer data

Portainer stores its settings, users and stack definitions in /data inside the container. Put that directory in a named volume so it survives container updates:

sudo docker volume create portainer_data

Verify that the volume exists:

sudo docker volume ls
DRIVER    VOLUME NAME
local     portainer_data

Step 2 - Running the Portainer container

Start Portainer CE with the following command:

sudo docker run -d \
  -p 9443:9443 \
  --name portainer \
  --restart=always \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v portainer_data:/data \
  portainer/portainer-ce:lts

What each option does:

  • -p 9443:9443 publishes the web interface over HTTPS. Portainer generates a self-signed certificate on first start.
  • --restart=always starts Portainer again after a reboot or a crash.
  • -v /var/run/docker.sock:/var/run/docker.sock lets Portainer manage the local Docker engine.
  • -v portainer_data:/data keeps Portainer's data in the volume from Step 1.
  • portainer/portainer-ce:lts uses the long-term support release, which is the channel Portainer recommends for production.

Older guides publish port 9000 for plain HTTP. Current Portainer versions serve the interface over HTTPS on 9443, so you do not need port 9000. Port 8000 is only used by Edge Agents on remote hosts; publish it with -p 8000:8000 only if you plan to use them.

Check that the container is running:

sudo docker ps --filter name=portainer
CONTAINER ID   IMAGE                        COMMAND        CREATED          STATUS          PORTS                                                   NAMES
3f2a9c1d8e7b   portainer/portainer-ce:lts   "/portainer"   20 seconds ago   Up 19 seconds   8000/tcp, 9000/tcp, 0.0.0.0:9443->9443/tcp, [::]:9443->9443/tcp   portainer

Confirm that the interface responds on the server:

curl -sk -o /dev/null -w '%{http_code}\n' https://localhost:9443
200

Step 3 - Controlling access to port 9443

Docker writes its own iptables rules for published ports, and those rules are evaluated before UFW's. A port published with -p 9443:9443 is therefore reachable from the Internet even if UFW does not allow it. Choose one of these approaches:

  • Keep port 9443 open and rely on HTTPS and a strong admin password. This is the simplest option.
  • Restrict access at the network level with a firewall in front of the server that only allows your IP address to reach 9443.
  • Publish only on localhost and reach Portainer through an SSH tunnel. Run the container with -p 127.0.0.1:9443:9443 instead of -p 9443:9443, then open the tunnel from your computer:
ssh -L 9443:127.0.0.1:9443 your_user@your_server_ip

With the tunnel open, browse to https://localhost:9443 on your computer.

Step 4 - Creating the administrator account

Open the interface in your browser, replacing your_server_ip with your server's IP address:

https://your_server_ip:9443

The browser warns about the self-signed certificate. Accept it to continue.

Portainer asks you to create the initial administrator. Enter a username and your_strong_password (at least 12 characters), then click Create user.

Step 5 - Connecting the local Docker environment

After you log in, the Environment Wizard opens. Click Get Started to use the local environment, which is the Docker engine Portainer is running on through the mounted socket.

Open Home and select the environment named local. The dashboard shows the number of containers, images, volumes and networks. To confirm that Portainer sees the same containers as the command line, open Containers: the portainer container should be listed as running, just like in the docker ps output from Step 2.

From here you can:

  • Deploy Compose files from Stacks > Add stack.
  • Read logs and open a shell from a container's Logs and Console buttons.
  • Remove unused images and volumes from Images and Volumes.

Step 6 - Updating Portainer

Portainer keeps all its data in the portainer_data volume, so updating means replacing the container with a new image. Pull the latest image first:

sudo docker pull portainer/portainer-ce:lts

Stop and remove the current container. Your data stays in the volume:

sudo docker stop portainer
sudo docker rm portainer

Start it again with the same command from Step 2:

sudo docker run -d \
  -p 9443:9443 \
  --name portainer \
  --restart=always \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v portainer_data:/data \
  portainer/portainer-ce:lts

Log in again and check the version shown at the bottom of the left menu.

Troubleshooting

  • The page does not load. Check the container with sudo docker ps -a --filter name=portainer and read its logs with sudo docker logs portainer. Make sure you are using https:// and port 9443, not port 9000.
  • "Your Portainer instance timed out for security purposes". The admin account was not created within 5 minutes. Run sudo docker restart portainer and create it right away.
  • Forgot the admin password. Portainer CE has no password reset in the interface. Portainer publishes a portainer/helper-reset-password image for this case; follow the password reset procedure in the official Portainer documentation.

Conclusion

Portainer CE is now running on Ubuntu 24.04 over HTTPS, connected to the local Docker engine and storing its data in a persistent volume. As next steps, deploy your first application from Stacks with a Compose file, and consider putting Portainer behind a reverse proxy with a trusted Let's Encrypt certificate, or keeping it on localhost behind an SSH tunnel.