An MIT-licensed wiki of shelves, books, chapters and pages for documentation and runbooks, run in Switzerland, the EU or your own datacentre with sign-in from your directory. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.
- Licence
- MIT
- Runs on
- Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
- Upgrades
- Pinned, tested against your configuration, applied in your window
- Upstream
- www.bookstackapp.com
Running BookStack in production: what it takes
Pin and deploy on MariaDB
A BookStack release we have run, on its own MariaDB, with images and attachments on a volume in local_secure mode so nothing is served to someone who has not signed in.
Connect sign-in and roles
OpenID Connect to Keycloak or Entra ID, or SAML2 or LDAP where that is what you have, with directory groups synced to BookStack roles instead of granted by hand.
Close the outbound calls
By default BookStack fetches avatars from Gravatar and loads the diagrams.net editor from the public site. We switch those off or point them inside your network, so the wiki calls no third party you did not choose.
Back up pages, uploads and APP_KEY together
The database, the uploads and the .env file are taken at the same moment and go offsite daily, encrypted. Once a month we restore all three into a scratch instance, sign in and open a page with images.
Stay close to the latest release
BookStack patches only its latest release, so we stay close to it. The Pilae Agent tests each upgrade and its database migrations on a copy, waits for your approval, applies it in your window and records it in the console.
What BookStack is, and who runs it
Self-hosted BookStack for documentation and runbooks
BookStack is a wiki for documentation that has to be found again. Content sits in four levels: shelves hold books, books hold chapters and pages, and pages hold the text. People write in a WYSIWYG editor or in Markdown, draw diagrams inline with diagrams.net, and every save keeps a revision that can be compared and restored. It fits IT runbooks, policies, procedures and manuals: the Confluence spaces most organisations actually read.
Next to Outline it is the plainer choice. Nobody co-edits a page in real time, and the structure is fixed rather than free-form. It is a PHP application on MariaDB, a stack most operations teams have run before. Our migration service moves Confluence spaces or SharePoint wikis into it.
BookStack in production: MariaDB, private uploads and sign-in
Each instance gets its own machine and its own MariaDB, on your hardware or in
a Pilae Cloud region you pick from 12, six of them in Switzerland and the EU,
and answers only on your private network. Images and attachments stay on a
volume in local_secure mode, because the default serves images to anyone with the link and the
S3 option makes them public in the bucket. The stricter mode, which checks page permissions for
every image, is marked experimental upstream, and we turn it on only after testing it against your
content. Sign-in goes through Keycloak or your own identity provider such as
Entra ID, with directory groups mapped to roles.
Backups run daily, encrypted, to an offsite location in your chosen country, and
are restored into a scratch instance every month. For BookStack that means the database, the
uploads and the .env file together, because the .env holds the APP_KEY that decrypts
multi-factor secrets. Probes check the instance every 60 seconds and alert an engineer.
BookStack licence, releases and support
The project is led and primarily maintained by its creator, Dan Brown, and is funded by donations, sponsorships and support plans. A feature release ships every couple of months and only the latest is patched, so we keep deployments close to it rather than holding a version for a year. The Pilae Agent runs each one against a copy of your wiki before you approve it for your window. The price of running it for you is on request. Talk to us about the wiki you want to move.
BookStack system requirements
Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.
- CPU and memory
- 2 vCPU · 4 GBBookStack documents no minimum. This is our starting size with MariaDB beside it. Serving images through the application, which private uploads require, costs more than serving them as static files.
- Runtime
- PHP 8.2+BookStack is a Laravel application. The project publishes no official container image, only community ones, so we pin the image we deploy and check what changed in it before every upgrade.
- Database
- MySQL 8.0+ or MariaDB 10.6+The only databases BookStack supports. There is no PostgreSQL option. Each instance gets its own MariaDB, backed up at the same moment as the uploads.
- Uploads
- STORAGE_TYPE=local_secureImages and attachments on a volume, served only to signed-in users. The default serves images to anyone who has the link, and S3 storage makes them public in the bucket.
- Sign-in
- OIDC, SAML2 or LDAPAll three are free and sync directory groups to BookStack roles. One method is active at a time, and it replaces email-and-password login.
Migrating from Confluence to BookStack
BookStack has no Confluence importer, and its own site says so. The route is a space export from Confluence, as HTML or XML, loaded through the BookStack REST API by a community tool or by a script kept in your repository. Page text, headings, tables, images and attachments come across. Blog posts are not in the Confluence HTML export, and on Confluence Cloud neither are comments. Revision history starts again at the import. Two things take the effort. The first is structure: BookStack has four fixed levels (shelf, book, chapter, page), so a Confluence tree nested six deep is reshaped to fit before anything is imported. The second is macros such as Jira issue lists, which have no BookStack equivalent and become plain content or links.
Inventory the spaces
Every space with its owner, page count, last edit and the macros it relies on. Spaces nobody has touched in a year are exported and archived rather than migrated.
Map the tree onto four levels
Each space becomes a shelf or a book, and pages nested deeper than a chapter are folded into their parents or split into books of their own. Owners sign off the map before the import.
Import into staging through the API
Space exports are loaded into a staging BookStack through its REST API, internal links and images are repointed, and owners check their sections against Confluence.
Set permissions, then freeze Confluence
Roles come from your directory groups. Shelf permissions do not cascade to books in BookStack, so they are copied down explicitly. Confluence goes read-only on the day of the switch.
What a BookStack restore needs
mariadb/bookstackcontent, users, roles · 3.2 GB
- entity_page_datacurrent text of every page
- page_revisionshistory, 100 per page by default
- mfa_valuesencrypted with APP_KEY
- search_termsrebuilt by bookstack:regenerate-search
.envconfiguration
- APP_KEYmust be the original
- APP_URLmust match the hostname served
storage/uploadslocal_secure · 46 GB
- imagesserved to signed-in users only
- filespage attachments
- themesempty unless customised
- s3://acme-backups/bookstackoffsite, daily, encrypted
What Pilae is responsible for
A pinned version
A version we have run, not whatever latest resolves to that day.
A runbook
What it depends on, how it fails, what to do about it. In your repository.
A restore drill
Backups restored on a schedule. A backup nobody has restored is a file.
A patch window
Security updates in a window you agreed, with a rollback ready.
Someone watching
Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.
- Where it runs
- zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
- Who holds the credentials
- You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
- If you leave
- The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.
What drives the price of running BookStack
Pricing is on request: a fixed price for onboarding, then a monthly price for BookStack, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.
- Instance size
- The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
- High availability
- One machine with tested restores, or a replicated setup that keeps serving when a node fails.
- Storage and backups
- How much data it holds, how long backups are kept, and point-in-time recovery for its database.
- Plan and support
- Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
- Region
- Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
- Sign-on and integrations
- Single sign-on, directory sync, mail relays and the other systems the app has to reach.
BookStack: common questions
Is BookStack open source?
Can BookStack import our Confluence spaces?
How does BookStack compare with Outline?
Can people sign in with Entra ID or Keycloak?
Where do our pages and files live?
Also in collaboration and identity
Keycloak
Single sign-on for everything else you run, with your own directory as the source of truth and no per-seat bill between you and it.
Replaces Okta, Microsoft Entra ID
Nextcloud
Files, calendars and shared documents for the whole organisation, on storage you can point at in a room you control.
Replaces Google Drive, Dropbox, SharePoint
Collabora Online
In-browser editing of Word, Excel and PowerPoint files beside Nextcloud, on your own hardware or in the Pilae region you choose, so no document passes through someone else's cloud.
Replaces Microsoft 365 for the web, Google Docs
Bring us your BookStack. We will tell you what it takes.
Thirty minutes on the deployment you already have, or the one you are about to start.