Back to Article List

Portainer ports 9443, 9000 and 8000 explained

Portainer ports 9443, 9000 and 8000 explained

Quick answer first, because most people arrive mid-task: the Portainer default port is 9443, HTTPS, for the web UI. Port 9000 is the old HTTP interface and modern installs don't publish it. Port 8000 belongs to Edge agents and stays closed unless you use them. That's the whole map; the rest of this page is what each one means in practice, when 9000 still earns a place and which ports face the internet on a real server.

What each Portainer port does

A standard install publishes two ports and people remember a third from older tutorials:

  • 9443/TCP, the UI over HTTPS with a self-signed certificate out of the box. Every current guide, including our Portainer install walkthrough, points you here.
  • 8000/TCP, a tunnel server for Edge agents (Portainer's mechanism for managing remote machines behind NAT). No Edge agents, no reason for this port to exist publicly; it rides along in the official run command and can be dropped from it entirely.
  • 9000/TCP, the legacy HTTP UI. Portainer served plain HTTP here for years, which is why the internet's muscle memory says 9000. It still works if you publish it (-p 9000:9000), and unencrypted admin panels stopped being acceptable a while ago, so treat it as a compatibility escape hatch rather than an option.

The one case where I still publish 9000 on purpose: behind a reverse proxy on the same machine, where the proxy terminates real HTTPS and talks plain HTTP to Portainer over localhost. Proxying to 9443's self-signed HTTPS works too but needs the proxy told to skip upstream verification, and plain-HTTP-on-localhost is the simpler contract. Either way the proxy owns the public side; the pattern is the same one our Nginx reverse proxy guide builds.

Firewall rules for each kind of setup

Three scenarios cover nearly everyone. On a home LAN box, allow 9443 from your local subnet and open nothing in the router; Portainer has no business being internet-reachable from a household setup. On a VPS you admin alone, my preferred arrangement is 9443 closed in the cloud firewall and reached through an SSH tunnel (ssh -L 9443:localhost:9443 user@server), which costs one command per session and removes the login page from the internet entirely; a control panel that can start privileged containers is the most valuable target on the machine. On a VPS a small team shares, the tunnel gets old, so front it with the reverse proxy on 443, restrict by IP where the team's addresses allow it and keep 9443 and 8000 off the public interface. The panel firewall on our Portainer VPS plans handles the cloud-side half of those rules.

Ubuntu-side, the strict versions look like:

sudo ufw allow from 192.168.1.0/24 to any port 9443 proto tcp   # LAN case
sudo ufw deny 9443/tcp                                          # VPS + tunnel case

Changing the Portainer port

Port collisions happen (another panel, another app claiming 9443). The published port is yours to move in the run command or compose file; only the left side changes:

ports:
  - "9543:9443"

Portainer now answers on 9543 while the container still listens internally on 9443. Update bookmarks and any proxy upstreams, and note the same left-side-only rule applies if you ever remap 8000. There's no in-app setting for this; the mapping is Docker's job, one of the small ways Portainer stays a well-behaved container like any other.

Check which ports are live

When the UI won't load and you suspect ports, two commands settle it from the server:

docker port portainer
ss -tlnp | grep -E '9443|9000|8000'

The first prints the container's actual mappings (the truth beats whatever the compose file was supposed to say), the second shows what the host is listening on. Mappings correct but no answer from outside means firewall or security group; no mappings at all means the container isn't running, which is a restart-from-terminal situation rather than a networking one. Two commands, ninety seconds, and the port question stops being a mystery, which is about all a ports page can promise.

Your idea deserves better hosting

24/7 support 30-day money-back guarantee Cancel anytime
Abonament

VPS.S1

$5.99 Save  17 %
$4.99 Lunar
  • 2 vCPU AMD EPYC
  • 2 GB RAMMEMORIE
  • 30 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse

VPS.S3

$14.99 Save  33 %
$9.99 Lunar
  • 4 vCPU AMD EPYC
  • 6 GB RAMMEMORIE
  • 70 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse

EPYC VPS.P1

$8.99 Save  22 %
$6.99 Lunar
  • 2 vCPU AMD EPYC
  • 4 GB RAMMEMORIE
  • 40 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

EPYC VPS.P2

$16.99 Save  24 %
$12.99 Lunar
  • 2 vCPU AMD EPYC
  • 8 GB RAMMEMORIE
  • 80 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

EPYC VPS.P4

$29.99 Save  23 %
$22.99 Lunar
  • 4 vCPU AMD EPYC
  • 16 GB RAMMEMORIE
  • 160 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

EPYC VPS.P5

$39.99 Save  25 %
$29.99 Lunar
  • 8 vCPU AMD EPYC
  • 16 GB RAMMEMORIE
  • 180 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

EPYC VPS.P6

$59.99 Save  25 %
$44.99 Lunar
  • 8 vCPU AMD EPYC
  • 32 GB RAMMEMORIE
  • 200 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

EPYC VPS.P7

$69.99 Save  29 %
$49.99 Lunar
  • 16 vCPU AMD EPYC
  • 32 GB RAMMEMORIE
  • 240 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

Genoa VPS.G2

$24.99 Save  20 %
$19.99 Lunar
  • 2 vCPUAMD EPYC Genoa generația a 4-a 9xx4 cu 3,25 GHz sau similar, pe arhitectura Zen 4. AMD EPYC G4
  • 4 GB DDR5MEMORIE
  • 50 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

Genoa VPS.G4

$44.99 Save  22 %
$34.99 Lunar
  • 4 vCPUProcesor AMD EPYC cu nuclee vCPU dedicate, pe hardware de server pentru companii. AMD EPYC G4
  • 8 GB DDR5MEMORIE
  • 100 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

Genoa VPS.G6

$89.99 Save  22 %
$69.99 Lunar
  • 8 vCPUProcesor AMD EPYC cu nuclee vCPU dedicate, pe hardware de server pentru companii. AMD EPYC G4
  • 16 GB DDR5MEMORIE
  • 200 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

Genoa VPS.G7

$159.99 Save  22 %
$124.99 Lunar
  • 8 vCPUProcesor AMD EPYC cu nuclee vCPU dedicate, pe hardware de server pentru companii. AMD EPYC G4
  • 32 GB DDR5MEMORIE
  • 250 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos. incluse
  • Backup automat gratuitInclude un spațiu de backup pe care îl poți configura pentru rulare zilnică, săptămânală sau lunară.

AMD Ryzen VPS.R1

$16.99 Save  18 %
$13.99 Lunar
  • 1 CPU dedicat AMD Ryzen 9 7950X cu 4,5 GHz sau similar, pe arhitectura Zen 4. vCPU
  • 4 GB DDR5MEMORIE
  • 50 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6 incluse Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos.
  • Backup automat inclus

AMD Ryzen VPS.R2

$29.99 Save  17 %
$24.99 Lunar
  • 2 CPU dedicate AMD Ryzen 9 7950X cu 4,5 GHz sau similar, pe arhitectura Zen 4. vCPU
  • 8 GB DDR5MEMORIE
  • 100 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6 incluse Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos.
  • Backup automat inclus

AMD Ryzen VPS.R4

$109.99 Save  18 %
$89.99 Lunar
  • 8 CPU dedicate AMD Ryzen 9 7950X cu 4,5 GHz sau similar, pe arhitectura Zen 4. vCPU
  • 32 GB DDR5MEMORIE
  • 400 GB NVMeSTOCARE
  • Trafic nelimitat
  • IPv4 & IPv6 incluse Suportul IPv6 este momentan indisponibil în Franța, Finlanda sau Țările de Jos.
  • Backup automat inclus

Frequent questions

Why does my browser warn about the certificate on 9443?

Portainer generates a self-signed certificate at install, so the warning is expected and the connection is still encrypted. Replace it with a real certificate in Settings, or put a reverse proxy with Let's Encrypt in front, and the warning retires.

GPU products are in high demand at the moment. Fill the form to get notified as soon as your preferred GPU server is back in stock.