Managed BookStack hosting

Collaboration and identityOn-prem or sovereign site

An MIT-licensed wiki of shelves, books, chapters and pages for documentation and runbooks, run in Switzerland, the EU or your own datacentre with sign-in from your directory. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about BookStack

Licence
MIT
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
www.bookstackapp.com

Running BookStack in production: what it takes

  1. Pin and deploy on MariaDB

    A BookStack release we have run, on its own MariaDB, with images and attachments on a volume in local_secure mode so nothing is served to someone who has not signed in.

  2. Connect sign-in and roles

    OpenID Connect to Keycloak or Entra ID, or SAML2 or LDAP where that is what you have, with directory groups synced to BookStack roles instead of granted by hand.

  3. Close the outbound calls

    By default BookStack fetches avatars from Gravatar and loads the diagrams.net editor from the public site. We switch those off or point them inside your network, so the wiki calls no third party you did not choose.

  4. Back up pages, uploads and APP_KEY together

    The database, the uploads and the .env file are taken at the same moment and go offsite daily, encrypted. Once a month we restore all three into a scratch instance, sign in and open a page with images.

  5. Stay close to the latest release

    BookStack patches only its latest release, so we stay close to it. The Pilae Agent tests each upgrade and its database migrations on a copy, waits for your approval, applies it in your window and records it in the console.

What BookStack is, and who runs it

Self-hosted BookStack for documentation and runbooks

BookStack is a wiki for documentation that has to be found again. Content sits in four levels: shelves hold books, books hold chapters and pages, and pages hold the text. People write in a WYSIWYG editor or in Markdown, draw diagrams inline with diagrams.net, and every save keeps a revision that can be compared and restored. It fits IT runbooks, policies, procedures and manuals: the Confluence spaces most organisations actually read.

Next to Outline it is the plainer choice. Nobody co-edits a page in real time, and the structure is fixed rather than free-form. It is a PHP application on MariaDB, a stack most operations teams have run before. Our migration service moves Confluence spaces or SharePoint wikis into it.

BookStack in production: MariaDB, private uploads and sign-in

Each instance gets its own machine and its own MariaDB, on your hardware or in a Pilae Cloud region you pick from 12, six of them in Switzerland and the EU, and answers only on your private network. Images and attachments stay on a volume in local_secure mode, because the default serves images to anyone with the link and the S3 option makes them public in the bucket. The stricter mode, which checks page permissions for every image, is marked experimental upstream, and we turn it on only after testing it against your content. Sign-in goes through Keycloak or your own identity provider such as Entra ID, with directory groups mapped to roles.

Backups run daily, encrypted, to an offsite location in your chosen country, and are restored into a scratch instance every month. For BookStack that means the database, the uploads and the .env file together, because the .env holds the APP_KEY that decrypts multi-factor secrets. Probes check the instance every 60 seconds and alert an engineer.

BookStack licence, releases and support

The project is led and primarily maintained by its creator, Dan Brown, and is funded by donations, sponsorships and support plans. A feature release ships every couple of months and only the latest is patched, so we keep deployments close to it rather than holding a version for a year. The Pilae Agent runs each one against a copy of your wiki before you approve it for your window. The price of running it for you is on request. Talk to us about the wiki you want to move.

BookStack is MIT-licensed and has one edition with no paid features: SAML2, OpenID Connect and LDAP sign-in, group sync, multi-factor authentication and the API are all in it. BookStack is a registered trade mark of Daniel Brown, and the project asks anyone hosting it for others to keep instances up to date, not to imply an official affiliation, and not to send infrastructure questions to its community support. We operate it on those terms: Pilae is not affiliated with the BookStack project, and support questions come to us. If you also want the project's own support plan, it is bought from HTTP Functions Ltd in your name.

BookStack system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
2 vCPU · 4 GBBookStack documents no minimum. This is our starting size with MariaDB beside it. Serving images through the application, which private uploads require, costs more than serving them as static files.
Runtime
PHP 8.2+BookStack is a Laravel application. The project publishes no official container image, only community ones, so we pin the image we deploy and check what changed in it before every upgrade.
Database
MySQL 8.0+ or MariaDB 10.6+The only databases BookStack supports. There is no PostgreSQL option. Each instance gets its own MariaDB, backed up at the same moment as the uploads.
Uploads
STORAGE_TYPE=local_secureImages and attachments on a volume, served only to signed-in users. The default serves images to anyone who has the link, and S3 storage makes them public in the bucket.
Sign-in
OIDC, SAML2 or LDAPAll three are free and sync directory groups to BookStack roles. One method is active at a time, and it replaces email-and-password login.

Migrating from Confluence to BookStack

BookStack has no Confluence importer, and its own site says so. The route is a space export from Confluence, as HTML or XML, loaded through the BookStack REST API by a community tool or by a script kept in your repository. Page text, headings, tables, images and attachments come across. Blog posts are not in the Confluence HTML export, and on Confluence Cloud neither are comments. Revision history starts again at the import. Two things take the effort. The first is structure: BookStack has four fixed levels (shelf, book, chapter, page), so a Confluence tree nested six deep is reshaped to fit before anything is imported. The second is macros such as Jira issue lists, which have no BookStack equivalent and become plain content or links.

  1. Inventory the spaces

    Every space with its owner, page count, last edit and the macros it relies on. Spaces nobody has touched in a year are exported and archived rather than migrated.

  2. Map the tree onto four levels

    Each space becomes a shelf or a book, and pages nested deeper than a chapter are folded into their parents or split into books of their own. Owners sign off the map before the import.

  3. Import into staging through the API

    Space exports are loaded into a staging BookStack through its REST API, internal links and images are repointed, and owners check their sections against Confluence.

  4. Set permissions, then freeze Confluence

    Roles come from your directory groups. Shelf permissions do not cascade to books in BookStack, so they are copied down explicitly. Confluence goes read-only on the day of the switch.

What a BookStack restore needs

  • mariadb/bookstackcontent, users, roles · 3.2 GB
    • entity_page_datacurrent text of every page
    • page_revisionshistory, 100 per page by default
    • mfa_valuesencrypted with APP_KEY
    • search_termsrebuilt by bookstack:regenerate-search
  • .envconfiguration
    • APP_KEYmust be the original
    • APP_URLmust match the hostname served
  • storage/uploadslocal_secure · 46 GB
    • imagesserved to signed-in users only
    • filespage attachments
  • themesempty unless customised
  • s3://acme-backups/bookstackoffsite, daily, encrypted
The database, the uploads and the .env file, taken at the same moment. A dump on its own brings back pages that point at missing images, and without the original APP_KEY the encrypted multi-factor secrets stop working. The monthly drill restores all three and opens a page with images.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running BookStack

Pricing is on request: a fixed price for onboarding, then a monthly price for BookStack, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

BookStack: common questions

Is BookStack open source?

Yes. BookStack is MIT-licensed and comes in one edition. SAML2, OpenID Connect and LDAP sign-in, group sync, multi-factor authentication and the API are all in it. The project sells support plans, not features.

Can BookStack import our Confluence spaces?

Not directly. BookStack has no Confluence importer, so each space is exported from Confluence as HTML or XML and loaded through the BookStack REST API. Revision history starts again at the import, which is why Confluence stays read-only, with its history, until you close it.

How does BookStack compare with Outline?

The main difference is co-editing. Outline lets several people edit one page at the same time. BookStack does not: it warns that someone else has started editing a page rather than merging their changes. BookStack also has a fixed shelf, book, chapter and page structure, and it is MIT-licensed, where Outline is source-available under the Business Source License. Teams writing reference documentation rarely miss co-editing. Teams drafting together all day usually prefer Outline.

Can people sign in with Entra ID or Keycloak?

Yes, through OpenID Connect, or through SAML2 or LDAP if that is what your directory offers. Each method syncs directory groups to BookStack roles. Only one is active at a time and it replaces email-and-password login, so someone disabled in the directory loses the wiki with everything else.

Where do our pages and files live?

Page text in MariaDB and images and attachments on a volume beside it, both on one dedicated machine: yours, or ours in the Pilae region you picked, in ISO 27001-certified datacentres. Backups are encrypted and kept offsite in the country you chose.

Also in collaboration and identity

Back to apps

Bring us your BookStack. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.