# Portainer CE is a free container UI that its own README rules out of production

> Portainer Community Edition is a Zlib licensed container management UI for Docker, Swarm, Podman, Kubernetes, and ACI, and the project is direct about who it is for: homelabs, learning environments, and personal projects. Everything that makes it usable, RBAC, GitOps, audit, SSO, and commercial support, is named as a Business Edition addition, and the community build ships with no SLA, no warranty, and no support channel at all.

**portainer/portainer** — GitHub describes it as Making Docker and Kubernetes management easy.. The repository metadata lists TypeScript as its primary language. The metadata lists the Zlib license. This article stays within the project description and details documented in the GitHub repository README.

- Repository: https://github.com/portainer/portainer
- Website: https://www.portainer.io
- Stars: 38,613 · Forks: 2,913
- Language: TypeScript
- License: Zlib
- Published: 2026-08-13 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/portainer-portainer

## CE carries an explicit clause against production use

Portainer Community Edition is a free container management UI covering Docker, Swarm, Podman, Kubernetes, and ACI, and the project attaches a direct statement of scope to it. The stated beneficiaries are homelab operators, hobbyists, students, and anyone experimenting with containers on their own hardware. CE is designed for homelabs, learning environments, personal projects, and other non-production deployments, and it is stated as not intended for, or supported in, business, production, or any other environment where uptime, security posture, or data integrity matter. The terms follow the same line: it comes without support, without warranty express or implied, and without any commitment as to fitness for a particular purpose, with no SLA, no guaranteed response to issues, and no roadmap commitment. The consequence is stated plainly too. Running CE means choosing to self-support.

## RBAC, GitOps, audit, and SSO are named as the paid additions

The division between the two editions is drawn in feature terms, and the list is short enough to be worth quoting. Portainer Business Edition builds on the same open source base and adds the features, hardening, and commercial support that production and enterprise environments require: RBAC, GitOps, edge management, audit, SSO, and more. Community Edition is the base those additions sit on, not a stripped build of Business, which is worth holding onto when you read feature tables. For a reader choosing an edition, the useful test is whether any of those five is a requirement rather than a nicety. If you need single sign-on or an audit trail, the project's own framing puts you in the wrong edition. There is also a trial-shaped offer called Take3, which gives 3 free nodes of Portainer Business for as long as the user wants them.

## The default branch is develop, not main

One detail changes how you read the repository. The default branch is develop rather than main, so a plain clone hands you the branch the team works on and not a stable line, with release artefacts coming from tags instead, 2.45.1 LTS, 2.39.8 LTS, and 2.45.0 LTS in the most recent set. The layout also shows the shape of the product. The Go server lives under api/ and pkg/, the front end under app/ with webpack and Tailwind configuration at the top level, storybook configuration in .storybook/, translations in a directory of their own, and packaging material under distribution/ and dev/. Two convenience files stand out, .env.defaults for configuration and .air.toml for live reload while working on the Go side. Two others explain the project's history: .git-blame-ignore-revs records bulk formatting commits that should not show up in blame, and a CLAUDE.md sits at the root next to CONTRIBUTING.md and SECURITY.md.

## Two toolchains, pinned hard at Node 22.22.1 and Go 1.26.6

The build is a Go server plus a TypeScript and React client, and both sides are pinned tightly. The Go module declares go 1.26.6, while the client manifest requires a specific runtime and package manager:

```json
  "engines": {
    "node": "^22.22.1"
  },
  "packageManager": "pnpm@10.26.2"
```

The client scripts show the loop a contributor actually works in: webpack-dev-server for development, webpack for a one-off build, vitest run for tests, tsc --noEmit for typechecking, and openapi-ts to generate the API client from a specification, with a format pass chained after generation. Storybook runs separately on port 6006. The Go side is pinned the same way, with the Makefile running swag and gotestsum through go run at fixed version arguments rather than trusting whatever is installed locally, and reading the golangci-lint version out of a separate version file.

## A replaced cron library carries a review note in go.mod

Dependencies are pinned with unusual commentary, and one line is worth reading in full:

```go
replace github.com/robfig/cron/v3 => github.com/robfig/cron/v3 v3.0.1 // Not actively maintained. Pinned to last known good version. Review needed when upgrading.
```

The directive is not a security pin, it is an abandonment note. The upstream project is described as not actively maintained, so the module is held at the last version known to work and explicitly flagged for review the next time anyone upgrades it. That is a piece of maintenance debt you inherit if you build from source, and it is one of the few places in the repository where the project comments on its own future rather than on its features. The rest of the module is a broad client of existing infrastructure, pulling in the Docker engine, the Docker CLI, the Compose libraries, and Kubernetes tooling rather than reimplementing any of it.

## The build-image target is the shortest path to a local image

Build orchestration lives in the Makefile, and one target is the command you want when you need a Portainer image without pulling one:

```bash
docker buildx build --load -t portainerci/portainer-ce:$(TAG) -f build/linux/Dockerfile .
```

The default goal is help rather than a build, which is a small kindness in a repository this size. More interesting is the server-deps target, which does nothing except create the dist directory, with a comment explaining that the pipeline requires the target but CE has no server deps. The rest of the chain is conventional: deps pulls server-deps and client-deps together, client-deps runs pnpm install, build-client hands webpack the configuration file named after ENV, and build-server shells out to build/build_binary.sh with a platform and architecture pair. Two housekeeping targets close it out, tidy running go mod tidy and clean emptying dist. Note that the Makefile switches webpack configuration on an ENV variable that defaults to development.

## The Go side drives Docker, Compose, and Kubernetes as a client

What the server does is visible in its imports, and it is a client of other people's infrastructure. The module depends on the Docker engine at v28.5.2 and the Docker CLI at v28.5.1, on the Compose specification library plus the Docker Compose v2 implementation, and on the containerd client, so Portainer parses and applies Compose definitions rather than inventing a format. Kubernetes support goes through the kompose library at v1.37.0, the component that translates Compose files into Kubernetes objects. Around those sit narrower pieces with obvious jobs: chisel for tunnelling out to agents, gorilla/websocket and websocketproxy for live log and exec streams, go-ldap for directory lookups, and the AWS SDK with its ECR service client for registry access. The front end mirrors the same breadth with CodeMirror, Lezer, and Radix components.

## Filing an issue creates no obligation, and the release interval is unpromised

The support section is the one to read twice, because it defines what you are not getting. Community Edition has no official support channel. Help exists through GitHub Issues and a community Slack, and the project describes any assistance found there as voluntary, best effort, and provided by other community members rather than by Portainer, adding that it is not a substitute for commercial support. Filing a bug or feature request creates no obligation on the project to respond, triage, or fix it. On cadence, CE is updated periodically with no guarantee about the interval, and the project states that Business Edition releases will be more frequent than Community Edition. The practical consequence is that an upgrade schedule, not a bug report, is what moves a community installation forward, and that anyone depending on one needs their own monitoring and their own rollback.

## Conclusion

Portainer Community Edition is a sound choice for a homelab, a lab full of students, or a single machine where you want a graphical handle on containers and compose stacks without writing commands, and the Zlib licence and the open development branch make it easy to read and fork. It is the wrong choice the moment uptime, security posture, or data integrity matter, because the project itself states it does not support that use and adds nothing but a UI over engines you already run. Before deploying it, decide which of RBAC, SSO, audit, or GitOps you actually need, since those are the additions that separate the two editions, and test the 3 free Business nodes first so you learn the difference on your own infrastructure rather than in a vendor comparison.

## FAQ

### What is Portainer used for?

Portainer is a container management interface. The Community Edition covers Docker, Swarm, Podman, Kubernetes, and ACI environments, giving you a web UI over containers you could otherwise only reach through the Docker and Compose command line tools.

### Can you use Portainer for free?

Yes. Community Edition is free and provided as-is at no cost, with no support, no warranty, and no SLA. A separate offer called Take3 gives 3 free nodes of Portainer Business Edition for as long as you want them, which is a different edition rather than a feature of CE.

### how to install portainer on docker

The repository does not carry an install command; it sends installation to the project's own documentation at docs.portainer.io/start/install-ce. If you want to build the image yourself instead, the Makefile target build-image runs a docker buildx build against build/linux/Dockerfile and tags the result portainerci/portainer-ce.

### how to use portainer ce

CE targets homelabs, learning environments, and personal projects, and the project states it is not intended for or supported in business, production, or any environment where uptime, security posture, or data integrity matter. There is no official support channel, and assistance found on GitHub Issues or the community Slack is voluntary and best effort.

### What is the difference between a Docker and a Portainer?

Docker is the container runtime and its command line, while Portainer is a management interface on top of one. The Go module depends on the Docker engine and CLI packages directly, along with the Docker Compose and Kubernetes kompose libraries, so Portainer acts as a client of those engines rather than replacing them.

## Sources

- [Official documentation](https://www.portainer.io)
- [Official README](https://github.com/portainer/portainer#readme)
- [Project repository](https://github.com/portainer/portainer)
- [Release notes](https://github.com/portainer/portainer/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/portainer-portainer
