← Back to all sparks
P

Portainer

INFRA · APIS
Velocity5.0

Open-source container management platform for Docker, Kubernetes, and edge environments

Portainer replaces kube-apiserver proxy calls with native K8s APIs while closing a Docker authorization bypass that let non-admins reach the daemon directly.

kubernetescontainer-managementsecurityedge-computegitopsdevops
◆Current state
Portainer is a container management UI with parallel release tracks: the 2.39.x LTS series prioritizes stability and receives targeted security backports, while the 2.4x STS series ships new architecture. Recent releases have been heavily focused on security remediation — SSRF protection, critical Docker proxy authorization bypasses, Kubernetes namespace isolation — alongside an architectural shift to native Kubernetes API routes that no longer proxy raw kubectl calls.
◆Where it's heading
The product is systematically tightening its authorization model across both tracks: the LTS line gets critical security backports while STS lands new architecture. The shift to native Portainer-owned Kubernetes APIs (secrets, configmaps, deployments, PVCs) in 2.45.0 is the clearest directional signal — Portainer is building first-class Kubernetes management rather than wrapping kubectl-proxy. GitOps Sources also got a dedicated wizard and reusable source model earlier in the cycle.
◆Prediction
The next likely move is expanding the native Kubernetes API surface to cover more resource types, and continued Edge Compute hardening as KubeSolo single-node deployments mature through the STS cycle into LTS.

◆Recent moves

  1. 11d ago

    Portainer 2.45.1: SSRF transport hardened across all outbound operations

    This patch extends the SSRF-aware transport introduced in 2.45.0 to cover Helm chart resolution and Git HTTP/HTTPS operations, and tightens enforcement so an aliased import can no longer slip past the check. Multiple critical CVEs in the kubectl shell image are cleared, including two rated Critical (CVE-2026-63073 and CVE-2026-75803), plus nine High and eleven Medium findings.

    View source ↗
  2. 11d ago

    Portainer 2.39.8: Go toolchain CVE maintenance backport

    A dependency-only maintenance release for the 2.39 LTS stream: Go toolchain bumped from 1.25.12 to 1.25.14, clearing the same CVE batch addressed in 2.45.1. One functional fix: the updater no longer marks a container healthy before its health-check command has completed, preventing a failed upgrade from silently skipping rollback.

    View source ↗
  3. 1mo ago

    Portainer 2.45.0: native K8s API surface debuts, Docker proxy auth bypass closed

    ⚡ SPARK

    The headline architectural move is replacing direct kube-apiserver proxy calls with native Portainer-owned APIs for secrets, configmaps, deployments, and PVCs. A critical Docker proxy authorization bypass — malformed version prefixes in the URL path skipped access control entirely — and a Kubernetes shell flaw where caller-supplied query params could override pod targets were both closed in the same release.

    View source ↗
  4. 1mo ago

    Portainer 2.39.7: Critical Docker proxy auth bypass backported to LTS

    A targeted security backport of the Docker proxy authorization bypass fix and broadened bind-mount restrictions from 2.45.0 into the 2.39 LTS stream, for operators unwilling to move to the 2.45 line. Two distinct authorization control gaps are addressed with no other changes — a narrowly scoped patch.

    View source ↗
  5. 1mo ago

    Portainer 2.39.6: SSRF protection added to LTS, Swarm path traversal fixed

    The 2.39.6 LTS patch backports the configurable SSRF allow-list (off/audit/enforce modes) from the STS track — a real feature arriving on the stable line, not just a bug fix. A path traversal in the Swarm compose deployer where config/secret file paths could escape the project root is also closed, along with multiple CVE dependency bumps.

    View source ↗
  6. 2mo ago

    Portainer 2.44.0: Workflow details screen, GPU visibility, BuildKit upgrade

    STS 2.44.0 adds a workflow details screen and persistent source/workflow/artifact state tracking, making the GitOps pipeline inspectable for the first time. GPU visibility in Environment Details and a BuildKit upgrade to v0.31.2 (with SLSA v1.0 attestations replacing v0.2) round out the feature work. A wide range of bug fixes address stack deployment failures, dark mode issues, and RBAC edge cases.

    View source ↗