

Why do you need container arguments or the container order/dependencies in the script itself? Is this a set-up that doesn’t use compose files? Genuine question/curiosity. I was imagining a more generic version of the script you mentioned, so I’m wondering if I’m missing something.

You can run rootless Podman with Portainer, I do too. Or used to, before ditching Portainer.
Can you elaborate on the ways a home lab is less secure if it runs a container management GUI? I’m open to learning more about it. What additional permissions does a GUI inherently require?
Most companies I worked at used OpenShift in production, and I do not think it was considered an attack vector more than any other components of the ecosystem were. I would be surprised if this was a major factor when it came to security incidents.
I don’t think that container privilege escalation vulnerabilities are correlated to the use of a GUI. To me, it is not a significant (or otherwise unique) risk. Even less so when we’re talking about a home lab that is only accessible via a VPN.
Now, is it unnecessary? Sure, but then so is running Jellyfin or lighting a scented candle.