
Portainer CE (Community Edition) is the most popular web UI for Docker management. It lets you view, start, stop, and delete containers, pull images, manage volumes and networks — all through a browser instead of the command line. It is equally useful for Docker beginners and teams managing production stacks.
How Portainer Works
Portainer CE works by mounting the Docker socket (/var/run/docker.sock) into its own container. This grants Portainer full access to the Docker API — it can create, stop, remove, and reconfigure containers exactly as if you were running commands in a terminal, but through a browser-based interface that any team member can use without needing Linux expertise.
The architecture has two main components: the Portainer Server, which is the web UI and API backend you install, and the optional Portainer Agent, which can connect to remote Docker hosts or clusters. For a single self-hosted VPS that does not use Swarm or Kubernetes, installing just the Portainer Server is sufficient.
Minimum VPS Requirements
Before installing Docker and Portainer, verify your VPS meets these requirements:
| Requirement | Minimum | Recommended |
|---|---|---|
| RAM | 512 MB (Docker + Portainer only) | 1 GB or more (including your apps) |
| CPU | 1 vCore | 2 vCores or more |
| Disk | 10 GB | 20 GB or more (for images and volumes) |
| Operating System | Ubuntu 20.04 / Debian 11 | Ubuntu 22.04 LTS or newer |
| Linux Kernel | 3.10+ | 5.x+ (supports cgroup v2) |
All AsiaGB VPS plans use KVM virtualisation with no kernel module restrictions, so Docker runs fully without the limitations found on some OpenVZ-based VPS providers.
Why Use Portainer
- Visual dashboard — See all containers with CPU/memory stats at a glance
- Log viewer — Stream container logs in real time from the browser
- Docker Compose stacks — Deploy a
docker-compose.ymldirectly from the UI - Image registry — Pull from Docker Hub or a private registry with one click
- Free CE edition — Portainer Community Edition is free with no node limit
Prerequisite: Docker Engine must be installed first. If you haven't installed it yet, run curl -fsSL https://get.docker.com | sh before proceeding.
Install Portainer CE
Step 1: Create a Persistent Volume
docker volume create portainer_data
Step 2: Run the Portainer Container
docker run -d \
-p 8000:8000 \
-p 9443:9443 \
--name portainer \
--restart=always \
-v /var/run/docker.sock:/var/run/docker.sock \
-v portainer_data:/data \
portainer/portainer-ce:latest
This runs Portainer in the background (-d), opens the HTTPS web UI on port 9443, and mounts the Docker socket so Portainer can manage Docker.
Step 3: Verify the Container Is Running
docker ps | grep portainer
Step 4: Open the Web UI
Navigate to https://YOUR_VPS_IP:9443 in your browser. On first launch you will be asked to create an admin password — use at least 12 characters.
Security note: Avoid exposing port 9443 directly to the public internet. Set up an Nginx reverse proxy with a valid TLS certificate (Let's Encrypt), or tunnel it through Cloudflare Tunnel, to avoid exposing the management UI publicly.
Nginx Reverse Proxy for Portainer
sudo nano /etc/nginx/sites-available/portainer
server {
listen 80;
server_name portainer.yourdomain.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name portainer.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/portainer.yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/portainer.yourdomain.com/privkey.pem;
location / {
proxy_pass https://localhost:9443;
proxy_ssl_verify off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
sudo ln -s /etc/nginx/sites-available/portainer /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx
Key Features You'll Use Daily
Container Management
Go to Containers to see a list of all containers with their status. You can Start, Stop, Restart, Remove, view Logs, or Exec into a shell with a single click.
Deploy a Stack (docker-compose)
Go to Stacks → Add Stack → paste your docker-compose.yml → click Deploy. Portainer pulls the required images and creates all containers as defined.
version: '3'
services:
web:
image: nginx:alpine
ports:
- "80:80"
volumes:
- ./html:/usr/share/nginx/html
Resource Stats
Click any container → Stats to see real-time CPU percentage, memory usage, network I/O, and disk I/O — helpful for diagnosing performance issues without additional monitoring tools.
Portainer CE vs Docker CLI — Side-by-Side Comparison
| Task | Docker CLI | Portainer Web UI |
|---|---|---|
| List containers | docker ps -a | Click Containers in the sidebar |
| View logs | docker logs -f container | Click container → Logs |
| Stop a container | docker stop container | Click the Stop button in the row |
| Deploy a stack | docker compose up -d | Stacks → Add Stack → paste YAML |
| Monitor CPU/RAM | docker stats | Click container → Stats (live graph) |
| Pull an image | docker pull image:tag | Images → Pull → type image name |
Portainer does not replace the CLI for every workflow, but it dramatically increases visibility and reduces mistakes caused by typos — especially valuable when multiple team members need to interact with running containers.
Securing Portainer on a Public VPS
Because Portainer has full control over the Docker daemon, securing access is critical. Follow these practices before exposing the interface:
- Never expose port 9443 directly — put Portainer behind an Nginx reverse proxy with a valid TLS certificate, or use a Cloudflare Tunnel to avoid any public port exposure
- Set a strong admin password — use at least 16 characters mixing uppercase, lowercase, digits, and symbols
- Enable two-factor authentication — Portainer supports TOTP (Google Authenticator) for admin accounts under Settings → Users
- Restrict access by IP — configure your Nginx or firewall to allow connections only from your team's IP addresses
- Create non-admin users — avoid using the admin account for daily tasks; create role-limited user accounts instead
Verify Docker Socket Permissions
# Check that the Docker socket has correct permissions
ls -la /var/run/docker.sock
# Expected output
# srw-rw---- 1 root docker 0 ... /var/run/docker.sock
# Add your user to the docker group to avoid using sudo every time
sudo usermod -aG docker $USER
newgrp docker
Backing Up and Restoring Portainer Data
All Portainer settings — users, environments, and stack configurations — are stored in the portainer_data Docker volume. Backing up this volume protects your configuration against accidental deletion or server migration:
Backup the portainer_data Volume
# Stop Portainer first to ensure data consistency
docker stop portainer
# Export the volume to a compressed archive
docker run --rm \
-v portainer_data:/data \
-v $(pwd):/backup \
alpine tar czf /backup/portainer_backup_$(date +%Y%m%d).tar.gz -C /data .
# Restart Portainer
docker start portainer
Restore the portainer_data Volume
# Create the volume if it does not exist
docker volume create portainer_data
# Restore from a backup archive
docker run --rm \
-v portainer_data:/data \
-v $(pwd):/backup \
alpine sh -c "cd /data && tar xzf /backup/portainer_backup_YYYYMMDD.tar.gz"
Tip: Schedule a weekly cron job to run the backup automatically and upload the archive to off-server storage such as object storage or a cloud drive. This protects your configuration even if the VPS itself is lost.
Update Portainer to the Latest Version
# Stop and remove the current container
docker stop portainer && docker rm portainer
# Pull the latest image
docker pull portainer/portainer-ce:latest
# Re-run (your data volume is preserved)
docker run -d \
-p 8000:8000 \
-p 9443:9443 \
--name portainer \
--restart=always \
-v /var/run/docker.sock:/var/run/docker.sock \
-v portainer_data:/data \
portainer/portainer-ce:latest
Need a VPS to Run Docker and Portainer?
Linux VPS starting at 500 THB/month with Full Root Access — run Docker, Portainer, and any container stack you need.
View VPS Plans