With the release of version 2.38 STS, Portainer has launched a new capability that we are calling Fleet Governance Policies. With this new feature, Portainer helps you configure your container clusters and secure them in a standardized manner: across regions, cloud providers, and diverse development environments.
With the release of version 2.38 STS, Portainer has launched a new capability that we are calling Fleet Governance Policies. With this new feature, Portainer helps you configure your container clusters and secure them in a standardized manner: across regions, cloud providers, and diverse development environments.
ContextFirst, containers standardized how we package and distribute applications. Then container orchestrators, such as Kubernetes, standardized how we launch replica sets of containers across diverse pools of compute capacity. But now IT organizations must tackle Kubernetes sprawl. Most IT technical organizations are now running tens, or even hundreds of Kubernetes control planes. There are a few reasons why:
Because of these factors, it's not uncommon for the largest IT companies to end up with thousands of clusters. How do they manage all these clusters?
Governing Kubernetes sprawlThere are two stages to governing Kubernetes sprawl. The first stage is typically accomplished by creating an official infrastructure as code template, then mandating that engineering teams deploy their Kubernetes clusters using this pre-vetted template. This approach scales fairly well at first, especially if you have an internal developer portal that allows teams to easily provision the template with minimum effort. But there are still two major issues:
Because of these issues, enterprise Kubernetes adopters realize they need to move on to stage two of governance. That's where Portainer Fleet Governance comes into the picture.
Portainer uses a hub and spoke model in which each Kubernetes cluster runs a lightweight Portainer agent that connects back to the central Portainer server. The Portainer server collects info about all your Kubernetes environments, but it also acts as a command and control center. Portainer Fleet Governance is built on top of this powerful capability. As a Portainer admin you can use the Portainer server interface to install policies on any environment that is running an agent connected to your Portainer server. In the case of our "Security Constraints" policy, attaching this policy to an environment automatically installs OPA Gatekeeper, as well as Gatekeeper rules to implement security constraints that you control in Portainer interface.

When you update a policy, the changes automatically propagate to all connected environments that have that policy attached. This means that if you need to upgrade OPA Gatekeeper, or change a gatekeeper rule, you can make a change in one place - in your Portainer Server UI - and your entire fleet receives the update.
Additionally, environments that are running the Portainer agent use a polling process to check back with the Portainer server and remediate drift from the intended state. So even if an important security policy is manually removed from the environment, the agent will detect this and reinstall the policy automatically.
Portainer’s Fleet Governance is a solution to the problem of Kubernetes sprawl. It gives administrators a way to install consistent settings and policies across an entire fleet, update these settings and policies retroactively, and automatically remediate drift from the intended setting and policy state.
Comparison to existing solutionsThere are some existing approaches in the Kubernetes ecosystem that attempt to address parts of this problem space, but most of them fall short once you zoom out to fleet scale.
Portainer Fleet Governance is designed for the reality of modern Kubernetes sprawl. It centralizes intent, distributes enforcement, and continuously reconciles reality back to policy. For organizations that operate Kubernetes at scale, across teams and environments, it closes a gap that existing tools leave open.
Where Portainer is going nextPortainer Fleet Governance is the foundation for a roadmap of future effort that we have planned in this space. There are more solutions that we want to provide for fleet operators:
At Portainer, we strongly believe that container orchestration should be stress free. Although some sprawl and complexity is inevitable, there is no reason this needs to result in chaos. If you have the right tool in your hands, you will be empowered to solve your problems with finesse. We believe that Portainer is that tool. We are proud to offer you Fleet Governance Policies, and we are excited to hear your feedback and suggestions on what we can do to better enable your container orchestration needs.
Infrastructure Moves Fast. Stay Ahead.
Subscribe to our monthly newsletter
Nathan is a Product Steward at Portainer, with over a decade of experience building and operating container platforms in production, across Amazon Elastic Container Service and Kubernetes. He's excited by all things having to do with container orchestration, and solving real world problems with automated systems that cut through the chaos.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Portainer 2.39 LTS is now available! | 5 | 7 | 26-02-2026 |
| 2 | 2026 Fleet Device Management: Guide for IoT & Edge Teams | 5 | 7 | 25-05-2026 |
| 3 | Portainer: The Essential Tool for Docker Swarm Users Facing a Kubernetes Future | 5 | 7 | 20-02-2026 |
| 4 | Industrial IoT Security: Protect Edge Workloads at Scale | 5 | 7 | 23-03-2026 |
| 5 | Edge Device Management Guide for DevOps Teams in 2026 | 5 | 7 | 26-03-2026 |
| 6 | Which Kubernetes distros does Portainer work with? | 5 | 7 | 17-03-2026 |
| 7 | Kubernetes Platform Support: Reduce Operational Risk at Scale | 5 | 7 | 25-03-2026 |
| 8 | The enterprise vibe coding problem, and what we built to solve it | 2 | 6 | 16-06-2026 |
| 9 | Why we rebranded Portainer | 5 | 7 | 05-03-2026 |
| 10 | sysutils/cfengine - 3.28.0 | 0 | 5 | 13-07-2026 |