WZ-IT Logo
ChirpStack

ChirpStack Installation

Professional installation on your infrastructure – on-premise, cloud or hybrid

On-Premise

In your data center

Cloud Installation

AWS, Azure, Hetzner & more

Security Setup

VPN, SSO, Hardening

Professional Installation Services

Professional installation where you need it

On-Premise Installation

Installation on your own hardware in your data center or server room

Installation on bare-metal, VM or Docker
Optimal performance configuration
Integration with existing Active Directory/LDAP
SSL certificate & reverse proxy
Backup strategy & monitoring
Security hardening following best practices
Documentation & training

Cloud Installation

Installation on your cloud infrastructure at AWS, Azure, Google Cloud or Hetzner

Installation on AWS, Azure, GCP, Hetzner
Terraform/IaC setup (optional)
Kubernetes or Docker Compose
Auto-scaling configuration
Load balancer & CDN integration
CloudWatch/monitoring setup
Cost optimization & best practices

Enterprise Setup

High-availability setup with comprehensive security and compliance features

High-availability cluster setup
VPN access (e.g. WireGuard, NetBird, Tailscale)
SSO integration (e.g. Keycloak, Authentik, Azure AD)
Multi-factor authentication (MFA)
Audit logging & compliance
Disaster recovery plan
Custom security policies
Dedicated contact person

Security & Secure Access

Secure access and access control for your installation

VPN Access

WireGuard, NetBird or Tailscale

SSO Integration

Keycloak, Authentik, Azure AD

Multi-Factor Auth

TOTP, WebAuthn, YubiKey

Firewall & Hardening

Fail2Ban, Rate Limiting, IP Whitelisting

Secure Access via VPN

We set up secure VPN access to your installation – ideal for remote work and external employees.

  • Zero-Trust Network Access (ZTNA)
  • Encrypted connections
  • Easy client setup for all devices
  • Centralized access management

Supported VPN Solutions:

WireGuard
NetBird
Tailscale
Headscale
OpenVPN
Cloudflare Tunnel

Perfect for These Use Cases

LoRaWAN Network Server

Complete LoRaWAN network server for IoT gateways and sensors with device management

Smart City & Infrastructure

City-wide IoT networks for parking management, waste disposal and environmental monitoring

Industrial IoT (IIoT)

Industrial sensor networks for machine data, predictive maintenance and production monitoring

Agriculture & Farming

Smart agriculture with soil, weather and plant sensors across large areas

Building Management

Building automation with temperature, humidity and energy sensors

Asset Tracking

GPS tracking and location monitoring for vehicles, containers and valuables

What's Included in the Service

Full-service installation with no hidden costs

✓ Complete installation & configuration
✓ SSL certificate & reverse proxy setup
✓ Backup strategy & disaster recovery
✓ Performance optimization & tuning
✓ Security hardening following OWASP
✓ Monitoring & logging setup
✓ Documentation & best practices
✓ Administrator training (remote)
✓ 30 days email support included
✓ Dedicated contact person
✓ Optional integration: LDAP/AD, SSO, MFA
✓ Update strategy & patch management setup

Why WZ-IT for Your Installation?

Expertise that moves you forward

Installation Expertise

We have successfully implemented dozens of enterprise installations and know all best practices.

Security First

Comprehensive security hardening following OWASP, including VPN access, firewall configuration and audit logging.

Open-Source Philosophy

We rely on open-source software and avoid vendor lock-in – you retain full control over your data.

Multi-Cloud Expertise

Whether AWS, Azure, Google Cloud, Hetzner or on-premise – we install where you need it.

Personal Support

You get a dedicated contact person who supports you during and after installation.

No Vendor Lock-in

Your installation runs on your infrastructure – you are always independent and can continue operating the solution yourself.

Interested in ChirpStack?

Good choice – we'll help you get started or with operations.

1/2 – Interest50%

Response within 24h – no spam, no sales pressure.

Frequently Asked Questions about ChirpStack Installation

Technical details on infrastructure, components and operations

Themen

Installation & Components

We set up the ChirpStack LoRaWAN Network Server including typical core dependencies: ChirpStack, PostgreSQL (persistence), Redis (cache/queue), and in many setups an MQTT broker (e.g., Mosquitto) and the ChirpStack Gateway Bridge component for gateway connectivity.

Both: We install ChirpStack on-prem, in your cloud, or on dedicated hardware. We often also build a private network (VPN/Private Link) between gateways/locations and the ChirpStack environment.

This depends heavily on gateway count, device count, uplink frequency, and payload size. As a rule of thumb: For an initial production setup, we plan separate resources for database (IO/storage), MQTT, and ChirpStack services.

Primarily persistent are: PostgreSQL (configuration, devices, events, metadata), MQTT depending on configuration, and ChirpStack configuration (config files, secrets). We ensure clean persistence via volumes/managed disks.

Infrastructure & Networking

In practice: yes, almost always, because MQTT in the ChirpStack ecosystem is the central messaging layer between components/Gateway Bridge and server (and is also used for integrations).

All three variants are possible: With you (on-prem / in your cloud), with us (managed hosting), or as managed MQTT. What matters is: access control, TLS, credential handling, and clear data flow documentation.

Yes. In the reference setup, 'EU868' is preconfigured, other regions can be cleanly switched. Important here is the region/topic configuration (e.g., topic prefix per region).

ChirpStack typically separates traffic via region prefixes (e.g., eu868, us915_0…). If gateways/forwarders use the wrong prefix, traffic ends up in the wrong context or isn't processed correctly.

Yes – this is often the clean enterprise approach: Gateways/locations send via VPN/Private Network to the ChirpStack infrastructure. This reduces attack surface and provides controllable data flows.

Typical baseline: TLS at external endpoints (reverse proxy/LB), strict firewalling, secret management (no secrets in repo), role/admin concept, separate admin access, logging/monitoring with defined scope.

In quickstart, the UI is locally accessible at http://localhost:8080; in production environments, there's typically a reverse proxy / load balancer with TLS and access controls in front.

Gateways & Protocols

Typical variants: Semtech UDP Packet Forwarder on UDP port 1700 (very common) or Semtech Basics Station by default on port 3001. Which variant you use depends on the gateway (vendor/firmware).

Both are possible: Gateways send via UDP/Basics Station to a Gateway Bridge instance. Alternatively, some setups use MQTT-based forwarders that publish to your MQTT broker (e.g., port 1883).

Yes. We support gateway onboarding end-to-end: provisioning, forwarder variant setup (UDP/Basics Station), connection tests, and documentation of parameters for your operations.

Operations & Scaling

Almost always: PostgreSQL (I/O, backups, restore times), Redis (performance/queueing), MQTT broker (availability/throughput). We design the infrastructure so these components have robust defaults.

At minimum: regular PostgreSQL backups (point-in-time/incremental), defined retention + offsite/second location, regular restore tests. Optional: config backups/secrets and long-term event storage.

We define an update process with: staging/test (if available), maintenance window + communication, rollback options (snapshots/backups). This keeps operations plannable and low-risk.

Yes – but 'HA' here usually means: redundant services, robust DB setup, and clean failover concept. Which HA level makes sense depends on the use case and budget.

Scaling typically happens through: separate resources for DB/MQTT/services, horizontal scaling of stateless components, clean network and storage performance (DB IOPS!).

We offer: installation & secure baseline, operations/monitoring/incident handling, backups/restore tests, updates/maintenance, support for gateways, sensor onboarding, MQTT and data pipeline. In short: We handle infrastructure & operations, you use the IoT data.

Learn More About ChirpStack

Discover all features, use cases and managed hosting options for ChirpStack

Go to ChirpStack Overview

Industry-leading companies rely on us

  • Keymate
  • SolidProof
  • Rekorder
  • Führerscheinmacher
  • ARGE
  • NextGym
  • Paritel
  • EVADXB
  • Boese VA
  • Maho Management
  • Aphy
  • Negosh
  • Millenium
  • Yonju
  • Mr. Clipart

What do our customers say?

Aleksandr Shuliko

Aleksandr Shuliko

CTO, EVA Real Estate, UAE

EVA Real Estate
"I recently worked with Timo and the WZ-IT team, and honestly, it turned out to be one of the best tech decisions I have made for my business. Right from the start, Timo took the time to walk me through every step in a simple and calm way. No matter how many questions I had, he never rushed me. The results speak for themselves. With WZ-IT, we reduced our monthly expenses from $1,300 down to $250. This was a huge win for us."
Sonja Aßer

Sonja Aßer

Data Manager, ARGE, Germany

ARGE
"With Timo and Robin, you're not only on the safe side technically - you also get the best human support! Whether it's quick help in everyday life or complex IT solutions: the guys from WZ-IT think along with you, act quickly and speak a language you understand. The collaboration is uncomplicated, reliable and always on an equal footing. That makes IT fun - and above all: it works! Big thank you to the team! (translated) "
Pascal Hakkers
"WZ-IT manages our Proxmox cluster reliably and professionally. The team handles continuous monitoring and regular updates for us and responds very quickly to any issues or inquiries. They also configure new nodes, systems, and applications that we need to add to our cluster. With WZ-IT's proactive support, our cluster and the business-critical applications running on it remain stable, and high availability is consistently ensured. We value the professional collaboration and the noticeable relief it brings to our daily operations."

Pascal Hakkers

CEO, Aphy B.V., Netherlands

Aphy
"

Timo and Robin from WZ-IT set up a RocketChat server for us - and I couldn't be more satisfied! From the initial consultation to the final implementation, everything was absolutely professional, efficient, and to my complete satisfaction. I particularly appreciate the clear communication, transparent pricing, and the comprehensive expertise that both bring to the table. Even after the setup, they take care of the maintenance, which frees up my time enormously and allows me to focus on other important areas of my business - with the good feeling that our IT is in the best hands. I can recommend WZ-IT without reservation and look forward to continuing our collaboration! (translated)

Sebastian Maier
Sebastian Maier
CEO Yonju GmbH
Yonju
"

We have had very good experiences with Mr. Wevelsiep and WZ-IT. The consultation was professional, clearly understandable, and at fair prices. The team not only implemented our requirements but also thought along and proactively. Instead of just processing individual tasks, they provided us with well-founded explanations that strengthened our own understanding. WZ-IT took a lot of pressure off us with their structured approach - that was exactly what we needed and is the reason why we keep coming back. (translated)

Matthias Zimmermann
Matthias Zimmermann
CEO Annota GmbH
Annota
"

Robin and Timo provided excellent support during our migration from AWS to Hetzner! We received truly competent advice and will gladly return to their services in the future. (translated)

S
Simon Deutsch
CEO WiseWhile UG
"

WZ-IT set up our Jitsi Meet Server anew - professional, fast, and reliable. (translated)

Mails Nielsen
Mails Nielsen
CEO SolidProof (FutureVisions Deutschland UG)
SolidProof

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea – we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Trusted by leading companies

  • Keymate
  • SolidProof
  • Rekorder
  • Führerscheinmacher
  • ARGE
  • NextGym
  • Paritel
  • EVADXB
  • Boese VA
  • Maho Management
  • Aphy
  • Negosh
  • Millenium
  • Yonju
  • Mr. Clipart
Timo Wevelsiep & Robin Zins - CEOs of WZ-IT

Timo Wevelsiep & Robin Zins

CEOs of WZ-IT

1/3 – Topic Selection33%

What is your inquiry about?

Select one or more areas where we can support you.