docker run -d -p 8000:8000 -p 9000:9000 --name portainer --restart=always -v /var/run/docker.sock:/var/run/docker.sock -v portainer_data:/data portainer/portainer-ce:lts

Why does everyone want to keep them on HTTPS, even though they should never be seen on the internet?

To keep you from forgetting how to setup portainer