−25%

on annual Windows plans, until 31 Oct. See plans

EQVPS

VPS for BookStack: a self-hosted team wiki

Run BookStack on a VPS as your team's documentation wiki: Docker setup with MariaDB, HTTPS on your domain, first login, backups and sizing.

Team documentation tends to die in one of two ways: scattered across chat threads nobody can search, or buried in a wiki so clunky that nobody updates it. BookStack is the rare self-hosted wiki that people actually use. Content lives on shelves, in books, in chapters and pages — a structure everyone understands without training. And it barely needs any server.

Why BookStack

It's not the right tool for everything. Developer docs that should change together with code belong in the repository, not in a wiki.

What it needs

BookStack is light. For most teams, Micro-IP — 1 vCPU, 2 GB, $10/month — is more than enough. The dedicated IP is what lets colleagues reach it over HTTPS on your domain. Disk grows with uploaded screenshots and PDFs, not with page count.

Install with Docker Compose

We'll use the widely used LinuxServer.io images. First generate an application key:

docker run -it --rm --entrypoint /bin/bash lscr.io/linuxserver/bookstack:latest appkey

Copy the base64:... value it prints. Then create docker-compose.yml:

services:
  bookstack:
    image: lscr.io/linuxserver/bookstack:latest
    environment:
      - PUID=1000
      - PGID=1000
      - APP_URL=https://wiki.example.com
      - APP_KEY=base64:paste-your-key-here
      - DB_HOST=db
      - DB_PORT=3306
      - DB_DATABASE=bookstack
      - DB_USERNAME=bookstack
      - DB_PASSWORD=change-me
    volumes:
      - ./bookstack:/config
    ports:
      - 127.0.0.1:6875:80
    depends_on:
      - db
    restart: unless-stopped
  db:
    image: lscr.io/linuxserver/mariadb:latest
    environment:
      - PUID=1000
      - PGID=1000
      - MYSQL_ROOT_PASSWORD=change-me-too
      - MYSQL_DATABASE=bookstack
      - MYSQL_USER=bookstack
      - MYSQL_PASSWORD=change-me
    volumes:
      - ./db:/config
    restart: unless-stopped
docker compose up -d
docker compose logs -f bookstack

APP_URL must match the address people will use, including https://. Get it wrong and images and links break in odd ways. More on Compose in our stack deployment guide.

HTTPS and first login

Point a subdomain at the server (how), put nginx in front of 127.0.0.1:6875, and add a certificate with certbot — the reverse proxy guide walks through it.

Then log in with the default account: admin@admin.com / password. Change the email and password right away, before you share the link. Everyone else gets their own account or signs in through your identity provider.

Backups

Two things to protect: the database and the uploads inside ./bookstack. A nightly job like this covers the database:

docker compose exec -T db mysqldump -u bookstack -pchange-me bookstack > /var/backups/bookstack.sql

Then back up /var/backups and the compose folder off-site — our restic guide does exactly that. Managed Backups add daily whole-server restore points on top.

Upkeep

Updating is docker compose pull && docker compose up -d. BookStack runs its database migrations on start. Read the release notes before major versions; they're short and clear.

If your team also wants a place for tickets and code, a self-hosted Git server sits nicely next to it on the same kind of plan.

Ready to deploy? Pay with crypto, no KYC — live in about a minute.

Deploy now →

FAQ

How much server does BookStack need?

Very little. BookStack is a PHP app with a MariaDB database; a team of a few dozen people runs comfortably on 1 vCPU and 2 GB of RAM. Disk use comes mostly from uploaded images and attachments.

What's the default login?

admin@admin.com with the password 'password'. Log in and change both immediately — before you share the URL with anyone.

Can it use our existing company login?

Yes. BookStack supports LDAP, SAML2 and OpenID Connect, so people can sign in with the identity provider you already use.

Does it need a dedicated IP?

For a team, yes. Your colleagues open it in a browser on HTTPS, which needs inbound port 443 on your own IP. For a personal notebook, an SSH tunnel on a NAT plan works too.

How do I back it up?

Dump the database and copy the uploads folder, which lives inside the mounted config volume. Our restic guide automates both into encrypted off-site snapshots.

Comments

No comments yet. Be the first.

Leave a comment

Comments are moderated before they appear.