MediaWiki is the open source wiki engine behind Wikipedia, and it works just as well for an internal knowledge base or a public documentation wiki. In this tutorial you will install MediaWiki 1.43 LTS on Ubuntu 24.04 with Apache, PHP 8.3 and MariaDB, serve it over HTTPS with a Let's Encrypt certificate, enable the most useful bundled extensions and set up a daily backup job.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 2 GB of RAM and 10 GB of free disk space.
  • A non-root user with sudo privileges.
  • A domain or subdomain (this guide uses your_domain) with a DNS A record pointing to your_server_ip.
  • Ports 80 and 443 reachable from the internet.

Step 1 - Installing Apache, PHP and MariaDB

MediaWiki 1.43 runs on PHP 8.1 or newer, so the PHP 8.3 packages shipped with Ubuntu 24.04 work without extra repositories. Besides the core PHP module you need the extensions MediaWiki uses for the database (mysql), text handling (mbstring, intl, xml), thumbnails (gd) and object caching (apcu).

sudo apt update
sudo apt install apache2 mariadb-server php libapache2-mod-php php-mysql php-xml php-mbstring php-intl php-gd php-curl php-apcu

Check that PHP and the required modules are loaded:

php -v
php -m | grep -E 'apcu|intl|mbstring|mysqli|xml'
PHP 8.3.6 (cli) (built: ...) (NTS)
...
apcu
intl
mbstring
mysqli
xml

Allow HTTP and HTTPS through the firewall. The Apache Full profile opens ports 80 and 443:

sudo ufw allow OpenSSH
sudo ufw allow 'Apache Full'
sudo ufw enable

Step 2 - Creating the database

MariaDB on Ubuntu authenticates the root account through the Unix socket, so you can open a shell with sudo and no password. First run the hardening script to remove the anonymous user and the test database (answer n to switching to unix_socket authentication, since it is already in use, and Y to the rest):

sudo mariadb-secure-installation

Open the MariaDB shell:

sudo mariadb

Create a database and a dedicated user for the wiki. Replace your_db_password with a strong password and keep it for Step 5:

CREATE DATABASE wikidb CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'wikiuser'@'localhost' IDENTIFIED BY 'your_db_password';
GRANT ALL PRIVILEGES ON wikidb.* TO 'wikiuser'@'localhost';
FLUSH PRIVILEGES;
EXIT;

Confirm the new user can log in:

mariadb -u wikiuser -p -e 'SHOW DATABASES;'
+--------------------+
| Database           |
+--------------------+
| information_schema |
| wikidb             |
+--------------------+

Step 3 - Downloading MediaWiki

Download the latest 1.43 release from the official release server. Check the MediaWiki download page for the current point release and adjust the version number in the commands if a newer one is available:

cd /tmp
wget https://releases.wikimedia.org/mediawiki/1.43/mediawiki-1.43.1.tar.gz

Extract it into /var/www and give the directory a version-independent name:

sudo tar --no-same-owner -xzf mediawiki-1.43.1.tar.gz -C /var/www/
sudo mv /var/www/mediawiki-1.43.1 /var/www/mediawiki

The code stays owned by root so the web server cannot modify it. Only the upload and cache directories need to be writable by Apache, which runs as www-data:

sudo chown -R www-data:www-data /var/www/mediawiki/images /var/www/mediawiki/cache

Step 4 - Configuring Apache and HTTPS

Create a virtual host for the wiki:

sudo nano /etc/apache2/sites-available/mediawiki.conf

Paste the following block, replacing your_domain:

<VirtualHost *:80>
    ServerName your_domain
    DocumentRoot /var/www/mediawiki

    <Directory /var/www/mediawiki>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>

    # Uploaded files must never be executed as PHP
    <Directory /var/www/mediawiki/images>
        php_admin_flag engine off
    </Directory>

    ErrorLog ${APACHE_LOG_DIR}/mediawiki_error.log
    CustomLog ${APACHE_LOG_DIR}/mediawiki_access.log combined
</VirtualHost>

AllowOverride All lets the .htaccess files that MediaWiki ships in directories such as cache/, includes/ and maintenance/ block direct access to them. Enable the site, disable the default one and check the syntax:

sudo a2ensite mediawiki.conf
sudo a2dissite 000-default.conf
sudo apache2ctl configtest
Syntax OK

Reload Apache:

sudo systemctl reload apache2

Now install Certbot with its Apache plugin and request a certificate. Certbot creates the HTTPS virtual host and a redirect from HTTP for you:

sudo apt install certbot python3-certbot-apache
sudo certbot --apache -d your_domain

Renewal runs automatically through a systemd timer. Test it once:

sudo certbot renew --dry-run

Step 5 - Running the MediaWiki installer

MediaWiki includes a command-line installer that creates the database tables, the administrator account and the LocalSettings.php configuration file in one run. Replace the placeholders: your_db_password from Step 2, your_admin_password for the wiki administrator (at least 10 characters and not a common password), and the wiki name.

cd /var/www/mediawiki
sudo php maintenance/run.php install \
  --dbtype=mysql --dbserver=localhost \
  --dbname=wikidb --dbuser=wikiuser --dbpass='your_db_password' \
  --server="https://your_domain" --scriptpath="" --lang=en \
  --pass='your_admin_password' \
  "Your Wiki Name" "Admin"
...
Creating administrator user account.. done
...
MediaWiki has been successfully installed. You can now visit <https://your_domain> to view your wiki.

LocalSettings.php contains the database password, so restrict it to root and the web server group:

sudo chown root:www-data /var/www/mediawiki/LocalSettings.php
sudo chmod 640 /var/www/mediawiki/LocalSettings.php

Open https://your_domain in a browser. You should see the Main Page and be able to log in as Admin. You can also query the API from the server:

curl -s "https://your_domain/api.php?action=query&meta=siteinfo&format=json" | head -c 200
{"batchcomplete":"","query":{"general":{"mainpage":"Main Page","base":"https://your_domain/index.php/Main_Page","sitename":"Your Wiki Name",...

Step 6 - Enabling extensions and uploads

The MediaWiki tarball already bundles popular extensions such as VisualEditor, ParserFunctions, Cite and WikiEditor; they only need to be loaded. Open the configuration file:

sudo nano /var/www/mediawiki/LocalSettings.php

Add these lines at the end of the file:

# Bundled extensions
wfLoadExtension( 'ParserFunctions' );
wfLoadExtension( 'Cite' );
wfLoadExtension( 'WikiEditor' );
wfLoadExtension( 'VisualEditor' );

# File uploads
$wgEnableUploads = true;
$wgFileExtensions[] = 'pdf';

VisualEditor uses the Parsoid service that ships with MediaWiki, so no separate daemon is needed on a single server.

By default PHP limits uploads to 2 MB. Raise the limit for Apache's PHP module with a small override file instead of editing php.ini:

sudo nano /etc/php/8.3/apache2/conf.d/99-mediawiki.ini
upload_max_filesize = 50M
post_max_size = 50M
memory_limit = 256M

Restart Apache so PHP reads the new values:

sudo systemctl restart apache2

Visit https://your_domain/index.php/Special:Version. The four extensions should be listed under Installed extensions, and Special:Upload should now show an upload form when you are logged in.

Step 7 - Restricting who can edit

A fresh wiki lets anyone read, create an account and edit pages. For an internal knowledge base you usually want accounts to be created by an administrator only. Add the following to LocalSettings.php:

# Only logged-in users can edit; only admins create accounts
$wgGroupPermissions['*']['edit'] = false;
$wgGroupPermissions['*']['createaccount'] = false;

To make the wiki completely private, also block anonymous reading while keeping the login page accessible:

$wgGroupPermissions['*']['read'] = false;
$wgWhitelistRead = [ 'Special:UserLogin' ];

Open the wiki in a private browser window to confirm that the Edit tab is gone (or that you are redirected to the login page if you made it private). Administrators create new accounts from Special:CreateAccount.

Step 8 - Scheduling daily backups

A MediaWiki backup consists of the database, LocalSettings.php and the images/ directory. Create a backup script:

sudo nano /usr/local/sbin/mediawiki-backup
#!/usr/bin/env bash
set -euo pipefail
umask 077

BACKUP_DIR=/var/backups/mediawiki
WIKI_DIR=/var/www/mediawiki
STAMP=$(date +%F-%H%M)

mkdir -p "$BACKUP_DIR"

# Runs as root, so MariaDB authenticates through the Unix socket
mariadb-dump --single-transaction --default-character-set=binary wikidb \
  | gzip > "$BACKUP_DIR/wikidb-$STAMP.sql.gz"

tar -czf "$BACKUP_DIR/files-$STAMP.tar.gz" -C "$WIKI_DIR" LocalSettings.php images

# Keep two weeks of backups
find "$BACKUP_DIR" -type f -mtime +14 -delete

Make it executable and run it once:

sudo chmod 700 /usr/local/sbin/mediawiki-backup
sudo /usr/local/sbin/mediawiki-backup
sudo ls -lh /var/backups/mediawiki
-rw------- 1 root root 1.2M Sep 25 10:12 files-2026-09-25-1012.tar.gz
-rw------- 1 root root 310K Sep 25 10:12 wikidb-2026-09-25-1012.sql.gz

Schedule it every night at 02:30 with a cron file:

echo '30 2 * * * root /usr/local/sbin/mediawiki-backup' | sudo tee /etc/cron.d/mediawiki-backup

Copy the backup directory to another server or to object storage as well; a backup that lives only on the same disk does not protect you from losing the server.

Troubleshooting

  • The browser shows "LocalSettings.php not found": the installer did not finish or the file is in the wrong place. It must be at /var/www/mediawiki/LocalSettings.php and readable by www-data.
  • Uploads fail with "Could not create directory": the images/ directory is not writable by Apache. Run sudo chown -R www-data:www-data /var/www/mediawiki/images.
  • Blank page or HTTP 500: check sudo tail -n 50 /var/log/apache2/mediawiki_error.log. For more detail, temporarily add $wgShowExceptionDetails = true; to LocalSettings.php and remove it once fixed.
  • After upgrading MediaWiki the wiki shows database errors: run the schema updater with cd /var/www/mediawiki && sudo php maintenance/run.php update --quick.

Conclusion

You now have MediaWiki 1.43 LTS running on Ubuntu 24.04 behind Apache with HTTPS, with VisualEditor enabled, controlled editing permissions and nightly backups. From here you can configure short URLs such as /wiki/Page_Name, connect an SMTP server through $wgSMTP so users receive password reset emails, or add extensions from the MediaWiki extension directory as your wiki grows.