Skip to main content
See All Integrations

Portainer

Protect access to Portainer container administration as an upstream web application.

Standard protected service pattern

Categories
Cloud Native Tools, Upstream Applications

Overview

Portainer is a container and Kubernetes management application. Its user interface and API normally use HTTPS port 9443. Interactive terminals and console features can use WebSocket.

Portainer can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Portainer. Portainer remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Route the selected Portainer interface endpoint and test browser, API, terminal, console, and long-lived sessions. Keep agent traffic on its documented path.

Example

Platform operators reach private Portainer through Pomerium. Pomerium controls route access. Portainer keeps environment, team, role, stack, container, and cluster permissions.

Considerations

  • Preserve WebSocket upgrades and trusted-origin checks for terminal and console flows.
  • Portainer Edge agents and other agent tunnels are separate from the user interface route.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo