| Property | Value |
|---|---|
| Host VM | VM-SL-12 |
| Compose path | — (managed via the Portainer UI itself; no compose dir) |
| Image | portainer/portainer-ee:latest |
| Container name(s) | portainer (server) + portainer_agent on remote hosts (VM-SL-00, VM-SL-22) |
| External URL | <https://portainer.io.blackreset.com (via Traefik on VM-SL-00 → VPN tunnel → VM-SL-12:9443)> |
| Networks | Docker bridge for the server + remote agents on host networks |
| DB / state | Internal SQLite + Docker volume portainer_data |
| Auth | Authentik OIDC (Access / Authentik / portainer); group portainer-Admins |
| Backup | PBS image-level via VM-SL-12 (covers portainer_data volume). |
Single pane of glass to inspect / start / stop / view-logs of every Docker container across VM-SL-00, VM-SL-12, VM-SL-22.
The Portainer server runs on VM-SL-12 (port 9443 HTTPS, 9000 HTTP). Remote portainer_agent containers on VM-SL-00 and VM-SL-22 expose their Docker sockets back to the server. External access via portainer.io.blackreset.com is fronted by Traefik on RZ (VM-SL-00) which proxies through the VPN tunnel to the server on VM-SL-12.
Authentik OIDC. Members of portainer-Admins (currently 2 users) get admin access.
:latest — TODO pin per No-compromises baseline.portainer-update-*); regular docker network prune recommended.Per memory/reference_portainer.md: canonical Portainer ist home-hosted unter portainer.blackreset.com (portainer.io. 301-redirected seit 2026-05-02). Agents auf jeder VM via TCP/9001. Per state_websites_migration_2026-05-01: Portainer EE 2.41.0, 14 endpoints, OIDC + LDAP, Team-Mapping aktiviert.
Host-Hinweis vm-sl-12 ist dadurch obsolet (Portainer-EE-Server läuft als SaaS-style-Instanz; Agents weiter auf jeder VM). Verifizieren ob portainer-server Container auf vm-sl-12 noch existiert oder schon migriert.