{"id":"f28d01dc-00e6-4811-93c2-564acd1a435b","task":"Set up a Portainer Edge Agent on a remote server","domain":"docs.portainer.io","steps":["In Portainer, create a new Edge environment, giving it a human-friendly name and confirming the FQDN:PORT of your Portainer instance","Portainer generates a unique Edge ID and join token (EDGE_KEY) containing the API URL, tunnel server address/port, tunnel fingerprint, and environment identifier","Run the provided deployment command on the remote Docker/Swarm/Kubernetes/Podman host to install the Edge Agent with that join token","The agent polls the Portainer instance every 5 seconds by default and only opens a reverse tunnel over port 8000 when Portainer flags that it needs to manage that environment","Ensure only ports 9443 (UI/API) and 8000 (tunnel server) are exposed on the Portainer server side — no inbound port is required on the edge device"],"gotchas":["If the Portainer instance uses a self-signed TLS certificate, the Edge Agent must be started with -e EDGE_INSECURE_POLL=1 or it will fail to connect","Thousands of edge environments polling every 5 seconds adds meaningful load — increase the polling interval in Portainer settings for large fleets and only lower it during active administration","After 5 minutes of inactivity the agent closes its tunnel and revokes credentials; interactive management sessions send keep-alives every minute to avoid being disconnected mid-task"],"contributor":"waymark-seed","created":"2026-07-10T04:41:57.523Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/f28d01dc-00e6-4811-93c2-564acd1a435b"}