Portainer Industries
Industrial App Portal

An app store for the factory floor, governed by IT.

A controlled, centrally managed catalog of approved containerized applications that site teams can deploy safely, without needing to know that Kubernetes, Docker or Podman are involved.

In development, not yet generally available

The Industrial App Portal is in development and is not yet generally available. The capabilities described on this page are the intended scope rather than shipping behavior, so treat them as the direction of the product and not as a specification to design against. Talk to the industrial team about early access.

The operator experience

The people on the floor should not have to learn the infrastructure.

Your IT team controls deployments, policies, and fleet governance through Portainer's operator control plane, and the people on the plant floor, at remote sites, and in the field do not need to see any of that; they need a purpose-built experience for their job. The Industrial App Portal is that interface, built for OT operators, technicians, and automation engineers, with infrastructure abstracted entirely so that they interact only with concepts that match their operational world.

Every action taken through the portal remains governed by the policies and access controls set by IT in the operator control plane, which means an operator can only do what they are permitted to do; the alternative, which is what most sites do today, is an engineer with shell access on a production device making an undocumented change that nobody can later attribute.

Industrial App Portal catalog as presented to an OT operator
The catalog: approved applications, presented as applications.
Industrial App Portal deployment view showing site targeting
Deployment targeting, constrained by policy already set centrally.
Capabilities

What the portal does.

Approved application marketplace for operations

Publish validated containerized applications, covering MES components, gateways, vision systems, telemetry services and vendor software, that sites can then deploy safely.

Central governance, local deployment

Platform teams control which applications and which versions are available, while site teams deploy without needing container or Kubernetes expertise.

Version control and safe updates

Roll out updates consistently across sites, with the ability to stage, test, and control promotion into production environments.

Reduced vendor and site-level risk

Eliminate ad-hoc installs, USB-based updates, and unmanaged third-party software deployments on operational systems.

Designed for disconnected environments

Supports air-gapped and low-bandwidth locations using synchronized catalogs and controlled release workflows.

Fleet health at a glance

A unified view of which devices are online, which applications are running, which deployments are current, and which devices have failed health checks, filterable by group, site, hardware type or application version.

Industrial App Portal architecture and placement
The portal sits between the application publisher and the fleet, so neither side needs bespoke delivery tooling.
For independent software vendors

A delivery channel that does not require building device management.

An ISV builds a strong industrial edge application, containerizes it, and then faces the question of how to actually get it running and keep it running across a customer's fleet of hundreds or thousands of edge devices; building a custom device management platform is a multi-year distraction from the core product, and asking the customer to manage it themselves produces a support ticket every time something needs updating. The Industrial App Portal gives ISVs a standard, governed delivery channel into customer-managed fleets, without either party needing to build anything bespoke.

The commercial shape of that matters as much as the technical shape. The ISV publishes to the catalog with versioned configuration and controls the release cadence; the customer's operations team decides when and where to accept the update; and the ISV support team can be scoped to read-only log access on the deployed application without any access to the customer's wider infrastructure configuration.

Publish once

Applications are published as versioned catalog entries, as Docker Compose stacks for Docker and Podman devices or Helm charts for Kubernetes and KubeSolo devices, complete with environment variables, volume mounts, port mappings and resource limits.

Customer controls acceptance

The operations team chooses an immediate push to all devices, a staged rollout to a percentage of the fleet, or manual approval per device group; devices offline at publication receive the update on reconnection.

Rollback is one action

Reverting to the previous version is a single action in the portal, and Portainer reverts the deployment on all affected devices rather than requiring a per-device intervention.

Common questions

Questions we get about the portal.

Is the Industrial App Portal part of Portainer Business Edition?

The Industrial App Portal is an add-on product that extends Portainer's governance model to application delivery at the OT edge. Licensing and packaging are handled by the industrial team, so confirm the current commercial terms with your account contact.

Do operators need to understand Docker Compose or Helm?

No. The configuration complexity lives in the catalog entry rather than in the deployment workflow, so the operations team selects the application, sets any site-specific variables, and deploys to a group.

How does targeting work across a mixed fleet?

Applications deploy to all devices in the fleet, to a named group such as every device in a given plant or every device of a given hardware type, or to individually selected devices. Targeting is defined once in Portainer's edge group configuration and applied consistently, and a device added to a group later automatically receives the applications assigned to that group.

What happens to a site that is offline when a new version is published?

The instruction queues and is delivered when the site reconnects, with no manual intervention required at the device to synchronize state after the connectivity gap.

Next step

Ready to govern your industrial edge?

Start free with up to 3 nodes, or talk to our industrial team about your OT deployment.