Architecture and migration
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

WZ-IT plans, installs and operates BookStack as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: BookStack (Dan Brown (BookStack project)). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

BookStack is an intuitive, self-hosted platform for organizing and storing information. The software was designed to organize documentation, knowledge, and instructions in a structured, easily navigable form - similar to a book with chapters and pages.
As an independent service provider, we support the installation, configuration and operation of BookStack as a central knowledge base for companies and teams.
We install, host and operate BookStack for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We provide 24/7 monitoring, backups and maintenance for your BookStack instance. Human response times and support coverage follow the selected service level.
BookStack is released under the MIT licence and has no traditional vendor licence fee for the upstream software. Infrastructure, setup, integration and operations are separate services.
The page editor offers a simple WYSIWYG interface, and all content is divided into three logical groups: Books, Chapters, and Pages - a structure that everyone immediately understands.
All content is fully searchable. You can search at the book level or across all books, chapters, and pages, and link directly to any paragraph to keep your documentation connected.
Numerous configuration options allow adaptation to your requirements: Change names, logo, registration options, and decide whether the system should be publicly or privately accessible.
The page editor features an integrated diagrams.net drawing function, enabling the quick and easy creation of diagrams directly within your documentation.
BookStack users can set their preferred language. Thanks to community contributions, numerous languages are available, including English, German, French, Spanish, Italian, Japanese, Dutch, Polish, Russian, and many more.
If you prefer to write in Markdown, BookStack offers a specialized editor with live preview while creating your documentation.
In addition to standard email/password login, social providers such as GitHub, Google, Slack, AzureAD, and more can be used. For enterprise environments, Okta, SAML2, and LDAP options are available.
MFA is integrated and can be enforced at role level. TOTP and backup codes complement the other technical and organisational controls.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
BookStack is a powerful wiki, but enterprise requirements demand deeper integration. We extend BookStack for your workflow.
Full CRUD access to books, chapters and pages. We build automations: Documentation generated from code repos or synced with external systems.
Page changes trigger workflows: Slack notifications, approval processes, automatic translations.
As a Laravel app, BookStack is highly extensible. Custom authentication providers, additional editor functions, special export formats.
How we implement BookStack development in practice.
Employees should log in with the central identity provider, not separate BookStack accounts.
SAML/OIDC integration with automatic group assignment based on AD groups. Permissions managed centrally.
Employees can't find information in the wiki even though it's documented. Search isn't intuitive.
LLM integration using BookStack content as context. Natural language questions answered with wiki passages.
Customer documentation must be exported as PDF in corporate design, not standard BookStack layout.
Custom PDF generator with LaTeX or Puppeteer that includes corporate fonts, header/footer and watermarks.
We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
SSO, secure access, internal systems and existing security components are integrated appropriately.
Updates, backups, technical monitoring and response paths follow a transparent operational scope.
APIs, automation and custom extensions can be delivered beyond basic deployment.
The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.
Collaboration platforms connect communication, files, identities and integrations. We treat them as a complete system rather than a single container.
Browser, desktop and mobile clients access shared workspaces through agreed roles.
TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.
Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.
Workspaces, communication, sharing and roles are configured and operated in a controlled way.
Messages, content, uploads, search, retention and backups.
Notifications, calls, TURN or further services depending on the feature set.
SSO, provisioning, bots, webhooks and connected business systems.
The diagram is a resilient target model. Its implementation depends on edition, data flows, load, availability objectives and existing infrastructure.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom BookStack architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard BookStack application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€7.99 excl. VAT per additional 100 GB per month, including daily encrypted offsite backup with 7-day retention. Billing is based on provisioned capacity, not actual usage.
We also implement custom backup schedules and retention periods. For example: daily backups retained for 30 days and one monthly backup retained for 12 months. Scope, storage requirements and additional costs are agreed separately.
+€299 excluding VAT per workload and month
Standard hosting runs on a single instance without high availability. Availability for custom architectures is agreed separately.
Zero downtime on request
Distributed operation with several instances, a database cluster and rolling updates, so that a node failure causes no interruption. Only for applications suited to it; design and price after technical assessment.
This page covers installation and the agreed platform operations for BookStack. Custom code, the access layer and special confidentiality requirements remain clearly separated responsibilities that can be added when needed.
Maintain the application
Keep custom extensions, interfaces and dependencies controlled, updated and supportable.
from €699.90 excl. VAT / month
View serviceSecure access
Add identity-based access and private network paths as a separate operational layer.
from €349.90 excl. VAT / month
View serviceOperate confidentially
For professional secrecy holders, define contractual, access and infrastructure requirements in a dedicated operating model.
from €499.90 excl. VAT / month
View serviceThree relevant adjacent paths instead of a long list of further products.
All prices are net and exclude statutory VAT. The offers are addressed to businesses.
View the overall systemEnquiry
Briefly describe the current state and objective for BookStack. We assess infrastructure, integration, and ongoing operations.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures BookStack, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

Everything about the wiki platform, operations and our services
Topics
BookStack is a free, open-source wiki platform based on PHP/Laravel, specifically developed for self-hosted knowledge management. Content is structured into shelves, books, chapters, and pages - a logical hierarchy that's easy to understand for non-technical users. BookStack is MIT-licensed, multilingual, and usable for teams of any size.
Typical use cases are IT documentation, process manuals, project knowledge, onboarding guides, or internal knowledge bases. Due to its intuitive interface, full-text search, and clear structure, BookStack is suitable for smaller teams as well as larger organizations that want a self-hosted, privacy-friendly wiki.
Traditional wikis often work only with 'pages' and categories. BookStack uses a book metaphor (Shelves → Books → Chapters → Pages) and offers a modern, WYSIWYG-oriented interface with optional Markdown, revision management, and image/file handling. This significantly lowers the entry barrier for business departments.
Both are possible. Via roles & permissions, you can determine whether the instance is only usable internally or whether certain content is publicly readable (guest role). There's a global 'Allow public viewing' option and fine-grained permission management at shelf/book/page level.
The standard is a WYSIWYG editor with live preview and comfortable formatting. Additionally, there's a dedicated Markdown editor for text-heavy workflows. Via the integrated diagrams.net connection, diagrams can be created and maintained directly in the editor.
Yes. Content in shelves, books, chapters, and pages is fully searchable, including various navigation and filter options. This makes BookStack very well suited as a central knowledge base, even with larger documentation collections.
Permissions are controlled via roles assigned to specific users. Roles define which actions (read, write, export, admin, etc.) are allowed. Additionally, there are object permissions on shelves/books/chapters/pages ('Everyone else', role-based rights) that are finely controllable and inherited.
Yes. Images are managed as media, files as 'Attachments' that can be attached to pages and linked in content. Access to attachments is tied to read permission of the associated page; downloads are thus automatically protected by the permission system.
Uploads can be stored locally (incl. 'Local secure'/'secure restricted') or e.g. in S3-compatible storage. Access is controlled via BookStack permissions; optionally, filenames can be hardened with random strings ('Enable higher security image uploads'). WZ-IT complements this with server hardening, TLS, backups, and monitoring.
Yes. Users can enable MFA; supported are TOTP-based apps (e.g., Google/Microsoft Authenticator) as well as backup codes. MFA secrets are stored encrypted and can be made mandatory at role level. WZ-IT recommends MFA especially for admin and power user roles.
BookStack supports LDAP, SAML 2.0, OpenID Connect, and various social/enterprise providers (e.g., AzureAD, Okta). This makes it easy to integrate into existing identity providers (Keycloak, Authentik, Azure AD, etc.). WZ-IT handles the complete SSO integration on request.
Yes. There are integrated login options for providers like Google, GitHub, Slack, AzureAD, Okta, GitLab, Discord, and more. You can control whether users are automatically registered and/or email addresses automatically confirmed.
Typical are: hardening of the Linux stack, current PHP/database versions, TLS/TLS termination via reverse proxy, restrictive file permissions, logging & monitoring, securing uploads, and sensible role/permission concepts. Additionally - as needed - VPN/zero-trust access, SSO/MFA, backup strategy, and coordinated deletion/retention rules.
Officially supported are MySQL ≥ 5.7 and MariaDB ≥ 10.2 as relational databases for all content and metadata. BookStack uses a single database per instance. WZ-IT plans the DB architecture (backups, possibly replication) according to your requirements.
For small to medium teams, a lean VM or small server usually suffices; the official demo runs e.g. with 1 CPU and 512 MB RAM. What matters is user count, concurrent access, and upload volume. WZ-IT does sizing (CPU/RAM/storage) with you based on real usage scenarios.
Typical: Requirements & architecture workshop, selection of operating variant (managed hosting or BYOI), installation (Linux, webserver, DB, PHP), security (TLS, hardening), configuration (branding, roles, email), backup/monitoring concept and documentation. Optionally followed by training and a support/maintenance contract, including SLAs.
Yes. We handle operations, updates, backups, monitoring and maintenance on infrastructure in Germany or the EU, or in your cloud or on-premises environment. 24/7 monitoring is separate from support coverage; response times, phone callbacks and backup scope follow the agreed service level.
In settings, you can customize name, logo, and registration options, plus you can override views, texts, icons, and CSS via the theme system. WZ-IT assists with setting up a CI-compliant look & feel (logo, colors, login/start page, possibly custom HTML head).
Yes. There's an official 'Subdirectory Setup' guide for Apache and Nginx. Important are a correctly set APP_URL in .env and appropriate rewrite/proxy rules. WZ-IT sets up subdirectory or subdomain setups including TLS for you.
Multiple instances on one server are easily possible as long as each installation uses its own database and directory. 'Multi-tenant' operation from a single installation is currently not officially supported. WZ-IT plans sensible separations with you (e.g., per business unit or security zone).
Approach: clean foundation (current PHP, OPcache, caching/sessions properly configured), optimized DB parameters, right storage choice for uploads, and monitoring bottlenecks. With growing load, app and DB layers can be separated and possibly horizontally scaled. WZ-IT accompanies capacity planning and performance tuning.
Before each update, database and upload directories should be backed up. The PHP/Composer version must also match the respective release. A staging system for tests and reading the 'Updating' notes for breaking changes is sensible. WZ-IT handles updates on request as a recurring maintenance service.
At minimum, regular (e.g., daily) database backups and file backups of uploads should be made, preferably versioned and offsite. The official docs describe which directories are relevant. WZ-IT defines intervals, retention times, and encryption with you - plus monitoring of backup jobs.
Yes. We perform regular restore tests (test restores to staging) and can develop a disaster recovery concept with you - such as restart in a second zone/region or on different infrastructure. This clarifies how quickly you can be operational again with BookStack in an emergency.
BookStack can export books, chapters, and pages as HTML, PDF, and plain text, provided the role has the 'Export content' right. This is suitable for handouts, audits, or archiving. For mass exports or integrations, the REST API can be used.
Yes. A REST API with token authentication is available. API rights are tied to a special role permission ('Access system API'), i.e., access respects the normal permissions system. WZ-IT integrates BookStack e.g. with portals, search solutions, or internal tools.
BookStack offers webhooks that send HTTP POST requests to external systems on events (e.g., Discord, Teams, HomeAssistant, n8n). This enables workflows like notifications, syncs, or triggers in third-party systems. WZ-IT helps with conception and implementation.
Emails are sent via a configured SMTP server. This includes user invitations, password resets, and optional notifications. WZ-IT handles connection to your mail gateway (incl. TLS, authentication) as needed and tests mail flows during commissioning.
There are export/import functions (e.g., 'Portable ZIP'), plus content can be imported via REST API or manually from Office/Markdown. A typical path: structure mapping, pilot migration of one area, then successive transfer of the most important content. WZ-IT supports with mapping, scripts, and cutover plan.
Pragmatic: Provide a small VM/server, install BookStack per official guide, basic configuration (branding, language, email), create 1-2 example books and test with a pilot team. WZ-IT handles installation, basic configuration, and training on request - or provides a hosted test instance.
Yes, if you value self-hosting, transparency, and cost control. BookStack offers a clear, reduced feature set for documentation and knowledge - without the marketplace ecosystem like Confluence, but MIT-licensed and easy to operate. WZ-IT supports you with evaluation, incl. proof-of-concept and migration plan.
Notion is a SaaS service with very flexible content, but without self-hosting. BookStack is clearly designed as a self-hosted documentation platform: traceable data model, clean export/API options, and full infrastructure control. For privacy-critical scenarios (e.g., EU-only), BookStack is often the more suitable choice.
When the focus is on file storage, office collaboration, or audit-proof document workflows, solutions like Nextcloud or DMS systems are better suited. BookStack excels at structured, text-centric documentation where knowledge should be linked and searchable. WZ-IT combines BookStack and Nextcloud in an overall solution if needed.
BookStack is a solid Confluence alternative as a self-hosted wiki with clear structure, if you can live with a more focused feature set. Typical: gather requirements, set up test instance, structure mapping, pilot migration, then staged move. WZ-IT accompanies conception, migration (API/export), and operations.
BookStack is comparatively resource-efficient; even the public demo runs on 1 CPU/512 MB RAM. For 50-100 users, we typically recommend a dedicated VM with sufficient RAM/CPU and reserved storage for uploads & backups. Exact sizes and operating costs we clarify in a sizing & infrastructure workshop.
SaaS wikis minimize operational effort but are less flexible regarding data location, integrations, and cost structure. BookStack requires own hosting but offers full control, open-source license, and good integration capability. If you want to outsource operations, WZ-IT can provide BookStack as a managed service.
BookStack can be part of a privacy-focused architecture. Relevant controls include data location, roles and permissions, MFA/SSO, logging, encryption, backups, retention and deletion policies. WZ-IT implements the agreed technical controls; legal assessment remains with the controller and its privacy advisers.
Technically it's mostly a content project: define structure, transfer important documents into page content (copy & paste, possibly Markdown conversion), upload supplementary files as attachments. For larger volumes, scripts or API-based imports can help. WZ-IT supports with structure design, migration scripts, and training of editors.
Typical: BookStack authenticates via Keycloak (OIDC or SAML2, group sync), Nextcloud remains the file/collab platform. BookStack references Nextcloud files or embeds selected documents as attachments. WZ-IT designs an architecture with you featuring shared roles, SSO, and unified permission model.
27.08.2026
Anyone selecting an enterprise wiki finds four serious open-source candidates and plenty of comparisons written mostly by vendors of competing products. One such comparison currently...
28.10.2025
Introduction Many companies are currently still using Atlassian Confluence as a knowledge management and documentation platform. With the end of support for the on-premises version...
08.10.2025
1. Introduction: Why Knowledge Management Needs to be Rethought Knowledge management is a key success factor in modern companies. From internal IT runbooks to project...
06.09.2025
More and more companies in the healthcare sector - including patient care, nursing services and psychiatric facilities - are asking us for solutions for better...
These solutions are often used together with BookStack
These solutions offer similar functionalities and can be evaluated together
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.