Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (v26.05.4-ls283, 2026-09-14), podman (11.8.8-r0-ls230, 2026-09-14); Proxmox VM: docker (v26.05.4-ls283, 2026-09-14), podman (11.8.8-r0-ls230, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
bookstack:
image: "lscr.io/linuxserver/bookstack:latest"
container_name: njorddeploy-bookstack
restart: unless-stopped
environment:
- PUID=1000
- PGID=1000
- "APP_KEY=base64:J8e0Kz+z56fG0B/1Y76LqQ+2n9NqK48x/5H9mH7vV4A="
- DB_HOST=bookstack_db
- DB_PORT=3306
- DB_USERNAME=bookstack
- DB_PASSWORD=bookstackpassword
- DB_DATABASE=bookstackapp
ports:
- "8115:80"
volumes:
- "./data/bookstack/config:/config"
depends_on:
- bookstack_db
networks:
- njorddeploy_net
bookstack_db:
image: linuxserver/mariadb:latest
container_name: njorddeploy-bookstack-db
restart: unless-stopped
environment:
- PUID=1000
- PGID=1000
- MYSQL_ROOT_PASSWORD=mariadbrootpassword
- MYSQL_DATABASE=bookstackapp
- MYSQL_USER=bookstack
- MYSQL_PASSWORD=bookstackpassword
volumes:
- "./data/bookstack/db:/config"
networks:
- njorddeploy_net
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
BOOKSTACK_WEB_PORT |
8115 |
BookStack web interface port. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.