A controlled, centrally managed catalog of approved containerized applications that site teams can deploy safely, without needing to know that Kubernetes, Docker or Podman are involved.
The Industrial App Portal is in development and is not yet generally available. The capabilities described on this page are the intended scope rather than shipping behavior, so treat them as the direction of the product and not as a specification to design against. Talk to the industrial team about early access.
Your IT team controls deployments, policies, and fleet governance through Portainer's operator control plane, and the people on the plant floor, at remote sites, and in the field do not need to see any of that; they need a purpose-built experience for their job. The Industrial App Portal is that interface, built for OT operators, technicians, and automation engineers, with infrastructure abstracted entirely so that they interact only with concepts that match their operational world.
Every action taken through the portal remains governed by the policies and access controls set by IT in the operator control plane, which means an operator can only do what they are permitted to do; the alternative, which is what most sites do today, is an engineer with shell access on a production device making an undocumented change that nobody can later attribute.
Publish validated containerized applications, covering MES components, gateways, vision systems, telemetry services and vendor software, that sites can then deploy safely.
Platform teams control which applications and which versions are available, while site teams deploy without needing container or Kubernetes expertise.
Roll out updates consistently across sites, with the ability to stage, test, and control promotion into production environments.
Eliminate ad-hoc installs, USB-based updates, and unmanaged third-party software deployments on operational systems.
Supports air-gapped and low-bandwidth locations using synchronized catalogs and controlled release workflows.
A unified view of which devices are online, which applications are running, which deployments are current, and which devices have failed health checks, filterable by group, site, hardware type or application version.
An ISV builds a strong industrial edge application, containerizes it, and then faces the question of how to actually get it running and keep it running across a customer's fleet of hundreds or thousands of edge devices; building a custom device management platform is a multi-year distraction from the core product, and asking the customer to manage it themselves produces a support ticket every time something needs updating. The Industrial App Portal gives ISVs a standard, governed delivery channel into customer-managed fleets, without either party needing to build anything bespoke.
The commercial shape of that matters as much as the technical shape. The ISV publishes to the catalog with versioned configuration and controls the release cadence; the customer's operations team decides when and where to accept the update; and the ISV support team can be scoped to read-only log access on the deployed application without any access to the customer's wider infrastructure configuration.
Applications are published as versioned catalog entries, as Docker Compose stacks for Docker and Podman devices or Helm charts for Kubernetes and KubeSolo devices, complete with environment variables, volume mounts, port mappings and resource limits.
The operations team chooses an immediate push to all devices, a staged rollout to a percentage of the fleet, or manual approval per device group; devices offline at publication receive the update on reconnection.
Reverting to the previous version is a single action in the portal, and Portainer reverts the deployment on all affected devices rather than requiring a per-device intervention.
The Industrial App Portal is an add-on product that extends Portainer's governance model to application delivery at the OT edge. Licensing and packaging are handled by the industrial team, so confirm the current commercial terms with your account contact.
No. The configuration complexity lives in the catalog entry rather than in the deployment workflow, so the operations team selects the application, sets any site-specific variables, and deploys to a group.
Applications deploy to all devices in the fleet, to a named group such as every device in a given plant or every device of a given hardware type, or to individually selected devices. Targeting is defined once in Portainer's edge group configuration and applied consistently, and a device added to a group later automatically receives the applications assigned to that group.
The instruction queues and is delivered when the site reconnects, with no manual intervention required at the device to synchronize state after the connectivity gap.
Start free with up to 3 nodes, or talk to our industrial team about your OT deployment.