# How do I run large Jitsi meetings with visitors and moderation?

> Visitors watch a Jitsi conference through WebRTC while extra Prosody instances distribute audience signaling. Docker stable-11248 includes visitor settings but requires a custom topology, not just ENABLE_VISITORS=1. Lobby controls admission; message moderation deletes sent chat messages and does not provide a message approval queue. [S5][S8][S9][S12]

Source: https://jitsi.help/guides/jitsi-large-meetings-visitors-lobby/
Updated: October 6, 2026
Publisher: Jitsi Help (https://jitsi.help/)

## Who this is for

You run a panel, class or town hall with many viewers and fewer speakers. `stable-11248`, released 2026-09-14, is still the newest Docker release checked on 2026-10-06. [S1][S20]

## How it works

Visitors receive conference media without joining the main room as ordinary publishing participants. Main participants use the main Prosody instance. Additional visitor Prosody instances distribute audience signaling; multiple videobridges supply media capacity. Adding bridges alone does not build this signaling topology. [S3][S8][S20]

Upstream's example discusses 10,000 participants, around 50 bridges on machines with at least eight cores, and 2,000 viewers per visitor node. These are sizing guidance, not a supported capacity guarantee. The reference is marked work in progress. Docker's current default is much lower: 250 occupants per visitor room. Load-test your actual layout. [S6][S8]

Lobby holds people before admission. Audio/video moderation controls permission to publish media. Message moderation supports deleting sent messages. These are separate features; none turns ordinary room chat into a queue awaiting approval. [S5][S12][S14][S15]

## Before you start

- Have a working HTTPS meeting at `meet.example.com`, valid DNS and certificates. Standard public ports are TCP 80 and 443 and UDP 10000 for media. Restrict internal XMPP connections to the required servers. [S2][S3]
- Keep the Compose files and Jitsi images from the same release. Establish moderator authentication before testing admission or moderation. [S2]
- Budget extra Prosody instances, browser proxy routes, server-to-server XMPP routing and sufficient bridges. Stock Docker Compose starts no visitor Prosody instances. [S4][S8][S9]
- Rehearse joins, promotion, departures and prolonged load, including known disconnect and memory problems. [S16][S17]

## Steps

1. **Docker stable-11248: enable ordinary meeting moderation first.** In your existing `.env`, set the following. Lobby and AV moderation already default to enabled; a moderator still activates the relevant room controls. [S2][S5]

   ```ini
   ENABLE_LOBBY=1
   ENABLE_AV_MODERATION=1
   ENABLE_MESSAGE_MODERATION=1
   ```

   `ENABLE_MESSAGE_MODERATION` defaults to enabled in the Prosody template, but this release's Compose file does not forward it. To make the setting controllable, merge this fragment into `compose.override.yaml`. Preserve any existing overrides. [S4][S5][S21]

   ```yaml
   services:
     prosody:
       environment:
         ENABLE_MESSAGE_MODERATION: ${ENABLE_MESSAGE_MODERATION:-1}
   ```

   Recreate Prosody during maintenance. Use the same file list subsequently. [S21]

   ```bash
   docker compose -f docker-compose.yml -f compose.override.yaml config --quiet
   docker compose -f docker-compose.yml -f compose.override.yaml up -d prosody
   ```

2. **Docker stable-11248: prepare visitors before enabling them.** Provision separate Prosody services with `PROSODY_MODE=visitors` and a unique `PROSODY_VISITOR_INDEX`. Configure Jicofo connections, authentication, main/visitor S2S routes and browser BOSH/WebSocket proxying. The upstream package reference describes these moving parts, but there is no complete released Docker visitor recipe. [S6][S8][S9]

   Only after that topology works, set:

   ```ini
   ENABLE_VISITORS=1
   VISITORS_MAX_PARTICIPANTS=30
   VISITORS_MAX_VISITORS_PER_NODE=250
   ```

   These use an example speaker threshold and Docker's visitor-room default. `VISITORS_XMPP_SERVER` takes comma-separated `host[:port]` entries for your configured nodes, starting at `v0`. Validate C2S and S2S ports separately. Stock Compose omits `VISITORS_XMPP_PORT` and `JICOFO_VISITORS_REQUIRE_MUC_CONFIG` from Jicofo's environment. Custom deployments must forward settings they use. [S4][S6][S7]

3. **Docker stable-11248: choose promotion policy.** Visitors request participation with **Raise your hand**; moderators use **Admit**, **Reject** or **Admit all**. Promotion allows joining the main meeting and publishing media. Docker renders `auto_allow_visitor_promotion = true`, so approval is not required by default. There is no corresponding Docker environment switch. [S5][S10][S11][S13]

   For moderator approval, adapt the server configuration to `auto_allow_visitor_promotion = false` and configure the documented conference-request HTTP route. The package reference also requires `conferenceRequestUrl` in the browser configuration. Test this custom arrangement before the event. [S8][S10]

4. **Debian/Ubuntu packages, Jitsi Meet 11248: use the package topology reference.** It creates numbered Prosody instances, including `/etc/prosody-v1/prosody.cfg.lua`, and requires manual main-Prosody and Nginx wiring. Review its helper before running it: it uses shell tracing while handling the existing Jicofo password. Do not run it blindly on production. [S8][S25]

   For configured visitor nodes with `hocon` installed, activate with: [S8]

   ```bash
   sudo hocon -f /etc/jitsi/jicofo/jicofo.conf set "jicofo.visitors.enabled" true
   sudo hocon -f /etc/jitsi/jicofo/jicofo.conf set "jicofo.visitors.max-participants" 30
   sudo service prosody restart
   sudo service jicofo restart
   sudo service nginx restart
   ```

   The package example includes lobby and AV moderation. For sent-message deletion, add `"muc_message_moderation";` to the existing `modules_enabled` lists of the main and breakout MUC components in `/etc/prosody/conf.avail/meet.example.com.cfg.lua`, then check and restart Prosody. Visitor MUCs need it for local history too. Docker `.env` variables do not configure packages. [S12][S15][S22]

   ```bash
   sudo prosodyctl check config
   sudo service prosody restart
   ```

5. **Both installation types, 11248: restrict group chat separately.** Docker loads `filter_messages` with `PROSODY_ENABLE_FILTER_MESSAGES=1`; packages need `"filter_messages";` in the main and breakout MUC module lists. [S5][S24]

   Docker: append `config.showChatPermissionsModeratorSetting = true;` to `${CONFIG}/web/custom-config.js`, owned by UID 1000, then recreate `web`. Packages: set `showChatPermissionsModeratorSetting: true,` in `/etc/jitsi/meet/meet.example.com-config.js`. The moderator checkbox is hidden when room metadata reports `allownersEnabled`. [S2][S15][S21][S24]

   The moderator opens **Settings**, **Moderator** and selects **Disable chat for non-moderators**. This sets `groupChatRestricted` for that room. [S13][S24]

   When `groupChatRestricted` is true, the server requires `send-groupchat` permission. Built-in defaults grant non-token moderators access. A JWT containing features must explicitly grant it, even for a moderator. Test allowed and denied senders before the event. [S24]

## Configuration reference

Defaults below apply to Docker `stable-11248`, unless marked otherwise. [S4][S5][S6][S7]

| Setting | Where | Default | Purpose |
|---|---|---|---|
| `ENABLE_VISITORS` | Docker `.env` | `0` | Enables visitor support, not extra services. [S6][S7] |
| `VISITORS_MAX_PARTICIPANTS` | Docker `.env` | Unset, Jicofo uses `50` | Main-participant threshold. [S7] |
| `VISITORS_MAX_VISITORS_PER_NODE` | Docker `.env` | `250` | Jicofo selection threshold and visitor MUC occupant cap. [S6][S7] |
| `VISITORS_XMPP_SERVER` | Docker `.env` | Empty | Comma-separated configured visitor servers. [S6][S7] |
| `VISITORS_XMPP_DOMAIN` | Docker `.env` | `meet.jitsi` | Visitor domain base. [S6][S7] |
| `VISITORS_XMPP_AUTH_DOMAIN` | Jicofo environment | `auth.meet.jitsi` | Visitor authentication domain. [S7] |
| `PROSODY_VISITORS_MUC_PREFIX` | Docker `.env` | `muc` | Visitor room domain prefix. [S6][S7] |
| `VISITORS_XMPP_PORT` | Docker environment | `52220` plus index | Template fallback, verify forwarding and routing. [S4][S6][S7] |
| `JICOFO_VISITORS_REQUIRE_MUC_CONFIG` | Jicofo environment | `0` | Requires room visitor flag when enabled. [S7] |
| `PROSODY_MODE` | Each Prosody service | `client` | Use `visitors` on separate visitor nodes. [S6] |
| `PROSODY_VISITOR_INDEX` | Visitor service | `0` | Number used in its XMPP domain. [S6] |
| `ENABLE_LOBBY` | Docker `.env` | `true` | Loads lobby support. [S5] |
| `ENABLE_AV_MODERATION` | Docker `.env` | `true` | Loads AV moderation support. [S5] |
| `ENABLE_MESSAGE_MODERATION` | Prosody environment | `true` | Sent-message deletion; Compose forwarding required. [S4][S5] |
| `PROSODY_ENABLE_FILTER_MESSAGES` | Docker `.env` | `false` | Loads server chat restriction. [S5] |
| `auto_allow_visitor_promotion` | Visitors component | Docker `true`, module `false` | Automatic versus approved promotion. [S5][S10] |
| `conferenceRequestUrl` | Browser `config.js` | Unset | HTTP conference/promotion requests. [S8][S24] |
| `showChatPermissionsModeratorSetting` | Browser `config.js` | Unset, control hidden | Shows chat permission control. [S24] |
| `groupChatRestricted` | Room permissions metadata | Unset | Activates restricted group chat. [S24] |
| `allownersEnabled` | Room metadata | Deployment-dependent | Hides chat permission control when true. [S24] |
| `send-groupchat` | JWT context features | Absent means denied when restricted | Allows the sender to post. [S24] |
| `jicofo.visitors.enabled` | Package `jicofo.conf` | `false` | Activates configured visitor topology. [S7] |
| `jicofo.visitors.max-participants` | Package `jicofo.conf` | `50` | Threshold used by package activation step. [S7] |

## Common mistakes

- **Turning on lobby after visitors arrive:** the 11248 client refuses this. Browser console text is exactly `Ignoring enable lobby request because there are visitors in the call already.` Plan admission before opening the audience. [S14]
- **Treating demotion as harmless:** #2103 reports everyone disconnecting when a moderator makes a participant a visitor. It was closed for inactivity, not a confirmed fix; its custom stack PR was not merged. Cause remains unconfirmed, not fixed as of 2026-10-06. [S16]
- **Assuming stable-11248 fixes memory growth:** #2411 reports an expired non-visitor endpoint retained in speech activity, followed by `java.lang.OutOfMemoryError: Java heap space`. Proposed PR #2461 is open and unmerged. Stable-11248 retains the original code, not fixed as of 2026-10-06. [S17][S18][S19]
- **Using limits as capacity proof:** Jicofo selection is soft; Prosody enforces an occupant cap. Measure before raising either. [S6][S7]

## Verify

**Docker stable-11248:** confirm selected images and rendered message moderation without printing passwords. [S4][S21][S23][S26]

```bash
docker compose -f docker-compose.yml -f compose.override.yaml config --images
docker compose -f docker-compose.yml -f compose.override.yaml exec -T prosody grep -oF '"muc_message_moderation";' /run/prosody/config/conf.d/jitsi-meet.cfg.lua
```

All Jitsi image tags should end in `:stable-11248`. With default breakout support, the second command returns exactly two lines, one per configured MUC: [S4][S5]

```text
"muc_message_moderation";
"muc_message_moderation";
```

This proves rendered configuration. On both 11248 installation types, join as moderator and attendee. Enable lobby before visitors join, approve the attendee and delete a test message. Another browser should display **Deleted by a moderator.** Test visitor admission above the example threshold, then request promotion under your chosen policy. Repeat departures during prolonged load. [S7][S10][S11][S13][S14]

## If it still fails

For Docker 11248, collect service logs. Include your custom visitor services separately; their names depend on your deployment. [S21]

```bash
docker compose -f docker-compose.yml -f compose.override.yaml logs --tail 100 prosody jicofo jvb web
```

Visitor Prosody startup should report `Prosody visitor mode, using alternate config`. Promotion rejection can contain `Visitor needs to be allowed by a moderator`. Restricted chat can return `Sending group messages not allowed`. Investigate the relevant topology or permission, not an assumed participant limit. [S10][S24][S26]

For packages, inspect `/var/log/prosody/prosody.log` and `/var/log/jitsi/jicofo.log`. Check visitor S2S connections, browser proxy requests and promotion routing. For growing bridge memory, preserve logs and heap evidence for #2411; extra heap does not establish that retention is fixed. [S3][S8][S17]

## FAQ

### Does ENABLE_VISITORS=1 support thousands of viewers?

It enables configuration support. Extra Prosody nodes, proxy routes and bridge capacity are still required; no fixed capacity follows from the switch. [S8][S9]

### Can moderators promote visitors to speakers?

Yes, current code supports requests and approval. Docker defaults to automatic promotion, so moderator approval requires adapting the server policy. [S5][S10][S11]

### Should I use visitors or live streaming?

Choose visitors for conference-like latency and possible promotion. Choose a Jibri stream to a streaming service for a mainly passive audience, with that service handling distribution. [S20]

### Does message moderation approve every message first?

No. It supports deletion after sending. Restricted chat is a separate feature with explicit sender permission checks. [S12][S24]

## Sources

[S1] [stable-11248 release](https://github.com/jitsi/docker-jitsi-meet/releases/tag/stable-11248), 2026-09-14; release note, latest checked 2026-10-06.

[S2] [Docker handbook](https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-docker), checked 2026-10-06; official doc.

[S3] [Scalable setup](https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-scalable), checked 2026-10-06; official doc.

[S4] [11248 Compose](https://github.com/jitsi/docker-jitsi-meet/blob/stable-11248/docker-compose.yml), 2026-09-14; source code.

[S5] [11248 main Prosody template](https://github.com/jitsi/docker-jitsi-meet/blob/stable-11248/prosody/rootfs/defaults/conf.d/jitsi-meet.cfg.lua), 2026-09-14; source code. [PR #2318](https://github.com/jitsi/docker-jitsi-meet/pull/2318), 2026-09-04; maintainer change.

[S6] [Visitor template](https://github.com/jitsi/docker-jitsi-meet/blob/stable-11248/prosody/rootfs/defaults/conf.d/visitors.cfg.lua) and [global template](https://github.com/jitsi/docker-jitsi-meet/blob/stable-11248/prosody/rootfs/defaults/prosody.cfg.lua), 2026-09-14; source code.

[S7] [Docker Jicofo template](https://github.com/jitsi/docker-jitsi-meet/blob/stable-11248/jicofo/rootfs/defaults/jicofo.conf) and [11248 reference](https://github.com/jitsi/jicofo/blob/stable/jitsi-meet_11248/jicofo/src/main/resources/reference.conf), 2026-09-14; source code.

[S8] [Extra-large conference reference](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/resources/extra-large-conference/README.md), 11248, checked 2026-10-06; official repository doc.

[S9] [Maintainer on missing Docker visitor setup](https://github.com/jitsi/docker-jitsi-meet/issues/2183#issuecomment-3597088416), 2025-12-01; maintainer comment.

[S10] [Visitors component](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/resources/prosody-plugins/mod_visitors_component.lua), checked 2026-10-06; source code.

[S11] [Visitor actions](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/react/features/visitors/actions.ts) and [approval UI](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/react/features/participants-pane/components/web/VisitorsItem.tsx), checked 2026-10-06; source code.

[S12] [Message moderation module](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/resources/prosody-plugins/mod_muc_message_moderation.lua), checked 2026-10-06; source code.

[S13] [Message menu](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/react/features/chat/components/web/MessageMenu.tsx) and [labels](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/lang/main.json), checked 2026-10-06; source code.

[S14] [Lobby actions](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/react/features/lobby/actions.any.ts), checked 2026-10-06; source code.

[S15] [Package example](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/doc/debian/jitsi-meet-prosody/prosody.cfg.lua-jvb.example), [Prosody installer](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/debian/jitsi-meet-prosody.postinst) and [web installer](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/debian/jitsi-meet-web-config.postinst), checked 2026-10-06; source code.

[S16] [Disconnect report #2103](https://github.com/jitsi/docker-jitsi-meet/issues/2103), 2025-05-29, and [custom PR #2086](https://github.com/jitsi/docker-jitsi-meet/pull/2086); community report, status checked 2026-10-06.

[S17] [Bridge retention/OOM #2411](https://github.com/jitsi/jitsi-videobridge/issues/2411), 2026-05-13; community report, open on 2026-10-06.

[S18] [Proposed fix #2461](https://github.com/jitsi/jitsi-videobridge/pull/2461), 2026-10-05; source code proposal, unmerged on 2026-10-06.

[S19] [11248 endpoint expiry](https://github.com/jitsi/jitsi-videobridge/blob/stable/jitsi-meet_11248/jvb/src/main/java/org/jitsi/videobridge/Conference.java#L981-L1005), checked 2026-10-06; source code.

[S20] [Large-audience architecture](https://jitsi.org/blog/low-latency-conference-streaming-to-very-large-audiences/), 2022-11-10; official engineering article.

[S21] Docker [merge](https://docs.docker.com/compose/how-tos/multiple-compose-files/merge/), [up](https://docs.docker.com/reference/cli/docker/compose/up/), [config](https://docs.docker.com/reference/cli/docker/compose/config/), [exec](https://docs.docker.com/reference/cli/docker/compose/exec/) and [logs](https://docs.docker.com/reference/cli/docker/compose/logs/), checked 2026-10-06; official docs.

[S22] [prosodyctl](https://prosody.im/doc/prosodyctl), 2026-02-09; official doc.

[S23] [grep manual](https://manpages.debian.org/trixie/grep/grep.1.en.html), checked 2026-10-06; official package documentation.

[S24] [Chat filter](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/resources/prosody-plugins/mod_filter_messages.lua), [permissions](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/resources/prosody-plugins/mod_jitsi_permissions.lua), [config](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/config.js), [moderator settings](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/react/features/settings/functions.any.ts) and [metadata action](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/react/features/settings/actions.web.ts), checked 2026-10-06; source code.

[S25] [Package setup helper](https://github.com/jitsi/jitsi-meet/blob/stable/jitsi-meet_11248/resources/extra-large-conference/pre-configure.sh), checked 2026-10-06; source code.

[S26] [Docker Prosody startup](https://github.com/jitsi/docker-jitsi-meet/blob/stable-11248/prosody/rootfs/etc/s6-overlay/scripts/config), 2026-09-14; source code.

## Open questions

- A complete custom Docker visitor topology and the package reference need testing on a real server; this guide does not claim a tested production recipe.
- Individual visitor chat permissions across S2S forwarding need runtime verification. [S24]
- #2103 supplies no confirmed disconnect cause or fix. #2461 has not shipped; the separate memory observations in #2411 remain unresolved. [S16][S17][S18]
- The reference's old opening says promotion is unavailable, while its later instructions and current code implement it. Capacity for your codec mix, network and deployment requires measurement. [S8][S11]

---

Jitsi Help is an independent service. It is not affiliated with, endorsed by or sponsored by 8x8, Inc. or the Jitsi project. Jitsi and Jitsi Meet are trademarks of 8x8, Inc., used here only to describe the software we host and support.
