Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can keep Portainer’s web interface off the public internet, but the standard local installation still gives Portainer control of Docker through the host’s socket. The important distinction is between exposing the management interface over the network and granting the Portainer container access to the Docker daemon. This guide installs Portainer CE on Ubuntu 26.04, limits which ports it publishes, and explains the access controls that matter.

What “without exposing my Docker host” means

There are two separate concerns: whether an outside client can reach Portainer’s web interface, and whether Portainer itself can control the Docker host. The standard local installation mounts /var/run/docker.sock inside the Portainer container. That socket is Docker’s control interface, so someone with administrative access to Portainer can manage the daemon and containers on that host.

Restricting the web interface reduces who can reach that control plane; it does not make the socket mount unprivileged or isolate Portainer from Docker. Docker also warns that membership in the docker group grants root-level privileges. Treat Portainer administrators and anyone who can access Docker’s control socket as privileged operators. Portainer’s Linux installation guide and Docker’s post-installation guidance describe these access implications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare Docker Engine on Ubuntu 26.04

Portainer requires a working Docker installation and sudo access. Use Docker’s live Install Docker Engine on Ubuntu guide rather than a command copied from an older Ubuntu release. It currently lists Resolute 26.04 LTS, Noble 24.04 LTS, and Jammy 22.04 LTS. Its repository instructions read the Ubuntu codename from /etc/os-release; following the current instructions avoids hard-coding a previous release codename.

If applicable, remove conflicting packages before installing Docker’s official packages. Docker lists packages including docker.io, docker-compose, docker-compose-v2, docker-doc, docker-buildx, podman-docker, containerd, and runc among potential conflicts. Follow the guide’s current package and repository steps, then verify the service and run its test container as directed.

Portainer recommends Docker’s official installation method and advises against installing Docker through Snap on Ubuntu because compatibility issues may occur. Ubuntu 26.04 LTS is supported until April 2031 according to the Ubuntu 26.04 LTS release notes.

Install Portainer CE locally

Portainer’s documented Docker Run deployment stores its configuration in a named volume and mounts the Docker socket. The image tag shown below uses the LTS channel; image tags can change, so check Portainer’s current installation page for the channel and command it recommends when you install.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Ubuntu 26.04 LTS Linux Bootable USB Flash Drive (Server)
  • 🚀 Latest Ubuntu 26.04 LTS (Long-Term Support) Get the newest stable release of Ubuntu 26.04 LTS with long-term updates, security patches, and enterprise-grade reliability.
  • 💻 Boot, Install, or Run Live Use as a live USB to test without installing, or install Ubuntu alongside or replacing Windows/macOS. No technical experience required.
  • 🛠️ System Repair & Recovery Tool Perfect for troubleshooting, recovering files, fixing boot issues, or reviving slow or corrupted systems.
  • ⚡ Fast & Portable USB Drive Preloaded on a high-speed USB flash drive—no downloads or setup required. Plug in and start instantly.
  • 🔒 Secure & Privacy-Focused OS Ubuntu provides built-in security, regular updates, and no forced tracking—ideal for privacy-conscious users.
docker volume create portainer_data
docker run -d 
  --name portainer 
  --restart=always 
  -p 9443:9443 
  -v /var/run/docker.sock:/var/run/docker.sock 
  -v portainer_data:/data 
  portainer/portainer-ce:lts

This publishes the HTTPS interface on TCP 9443. It deliberately omits TCP 8000, which is used for Edge Agent features, and TCP 9000, the legacy HTTP interface. Add 8000 only if you need the relevant Edge Agent features; do not add 9000 unless you have a specific legacy HTTP requirement. Portainer documents these ports and the local deployment in its Linux installation guide.

Check that the container started:

docker ps

Open https://localhost:9443 from a browser on the host, or use the host’s trusted internal address from an authorized client. Portainer generates a self-signed certificate by default, which browsers may warn about; Portainer documents supplying a certificate during installation or later in the UI.

Restrict access to the web interface

The Docker Run example above uses -p 9443:9443, which publishes the port on the host’s network interfaces by default. It is not a private-only configuration. Choose a binding and network policy that match how you intend to administer the host.

Rank #3
EZITSOL 32GB 9-in-1 Linux Bootable USB Drive for Beginners
  • 1. 9-in-1 Linux:32GB Bootable Linux USB Flash Drive for Ubuntu 24.04 LTS, Linux Mint cinnamon 22, MX Linux xfce 23, Elementary OS 8.0, Linux Lite xfce 7.0, Manjaro kde 24(Replaced by Fedora Workstation 43), Peppermint Debian 32bit (being replaced by MX Linux 32bit) for older PC, Pop OS 22, Zorin OS core xfce 17. The versions you received might be latest than above as we update them to latest/LTS when we think necessary.
  • 2. Try or install:Before installing on your PC, you can try them one by one without touching your hard disks.
  • 3. Easy to use: These distros are easy to use and built with beginners in mind. Most of them Come with a wide range of pre-bundled software that includes office productivity suite, Web browser, instant messaging, image editing, multimedia, and email. Ensure transition to Linux World without regrets for Windows users.
  • 4. Support: Printed user guide on how to boot up and try or install Linux; please contact us for help if you have an issue. Please press "Enter" a couple of times if you see a black screen after selecting a Linux.
  • 5. Compatibility: Except for MACs,Chromebooks and ARM-based devices, works with any brand's laptop and desktop PC, legacy BIOS or UEFI booting, Requires enabling USB boot in BIOS/UEFI configuration and disabling Secure Boot is necessary for UEFI boot mode. Packing: The bootable USB drive comes in a colored PET/CPP zipper bag with instructions on how to get started. The box pictured is not included.

Local browser access only

If you will use a browser running on the Ubuntu host, bind the published port to loopback instead of all interfaces:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
-p 127.0.0.1:9443:9443

Use that in place of -p 9443:9443 when creating the container. This makes the service available at the host’s loopback address, not as a general LAN service. Verify the binding on your Docker version and host before relying on it.

Access from a private management network

If an authorized workstation must connect over the network, publish the port only on an address appropriate to that private network, and restrict reachability to intended management clients using controls verified for your host’s networking setup. Do not expose Portainer to the public internet simply to make setup easier.

Docker warns that published container ports can bypass rules configured with ufw or firewalld. A firewall rule alone is not proof that a Docker-published port is inaccessible. Validate actual reachability from a client outside the intended management network, and confirm that only the expected clients can connect. This warning is documented in Docker’s Ubuntu installation guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose between a local socket and a remote Agent

For one Docker host, the local Portainer Server with a socket mount is the straightforward option. For a separate Portainer Server managing another standalone host, Portainer documents an Agent connection. The choice changes where Docker’s control interface is reachable; neither option should be treated as a security guarantee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Deployment Control path Network port Key consideration
Local Server with Docker socket Portainer container mounts the local /var/run/docker.sock 9443 for the UI; 8000 is optional for Edge Agent features; 9000 is legacy HTTP and not needed by default Portainer administrators can control the local Docker daemon; restrict UI access and administrator accounts.
Separate Server with standalone Agent Server connects to an Agent on the Docker host TCP 9001 must be reachable from the Portainer Server Restrict 9001 to the Server’s address. The standalone Agent is a legacy option with feature limitations.

Portainer describes the standalone Agent as a legacy option that lacks Edge features and policy management. Its Server-to-Agent communication uses HTTPS, but that does not make the Agent an automatic security boundary: consider network restrictions, trust between the machines, and the privileges granted to the Agent. See Portainer’s Agent installation guidance.

Keep host-management features narrowly scoped

Portainer’s Agent host-management features can permit browsing the host filesystem when the host root is mounted at /host. Portainer says these features are disabled by default for security. Avoid enabling them unless your administrative task requires them, and account for the additional host access when deciding who may administer Portainer. See Portainer’s host setup documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.