Who this is for
You run a panel, class or town hall with many viewers and fewer speakers. stable-11248, released 2026-09-14, is still the newest Docker release checked on 2026-10-06. [S1][S20]
How it works
Visitors receive conference media without joining the main room as ordinary publishing participants. Main participants use the main Prosody instance. Additional visitor Prosody instances distribute audience signaling; multiple videobridges supply media capacity. Adding bridges alone does not build this signaling topology. [S3][S8][S20]
Upstream’s example discusses 10,000 participants, around 50 bridges on machines with at least eight cores, and 2,000 viewers per visitor node. These are sizing guidance, not a supported capacity guarantee. The reference is marked work in progress. Docker’s current default is much lower: 250 occupants per visitor room. Load-test your actual layout. [S6][S8]
Lobby holds people before admission. Audio/video moderation controls permission to publish media. Message moderation supports deleting sent messages. These are separate features; none turns ordinary room chat into a queue awaiting approval. [S5][S12][S14][S15]
Before you start
- Have a working HTTPS meeting at
meet.example.com, valid DNS and certificates. Standard public ports are TCP 80 and 443 and UDP 10000 for media. Restrict internal XMPP connections to the required servers. [S2][S3] - Keep the Compose files and Jitsi images from the same release. Establish moderator authentication before testing admission or moderation. [S2]
- Budget extra Prosody instances, browser proxy routes, server-to-server XMPP routing and sufficient bridges. Stock Docker Compose starts no visitor Prosody instances. [S4][S8][S9]
- Rehearse joins, promotion, departures and prolonged load, including known disconnect and memory problems. [S16][S17]
Steps
-
Docker stable-11248: enable ordinary meeting moderation first. In your existing
.env, set the following. Lobby and AV moderation already default to enabled; a moderator still activates the relevant room controls. [S2][S5]ConfigENABLE_LOBBY=1 ENABLE_AV_MODERATION=1 ENABLE_MESSAGE_MODERATION=1ENABLE_MESSAGE_MODERATIONdefaults to enabled in the Prosody template, but this release’s Compose file does not forward it. To make the setting controllable, merge this fragment intocompose.override.yaml. Preserve any existing overrides. [S4][S5][S21]YAMLservices: prosody: environment: ENABLE_MESSAGE_MODERATION: ${ENABLE_MESSAGE_MODERATION:-1}Recreate Prosody during maintenance. Use the same file list subsequently. [S21]
Terminaldocker compose -f docker-compose.yml -f compose.override.yaml config --quiet docker compose -f docker-compose.yml -f compose.override.yaml up -d prosody -
Docker stable-11248: prepare visitors before enabling them. Provision separate Prosody services with
PROSODY_MODE=visitorsand a uniquePROSODY_VISITOR_INDEX. Configure Jicofo connections, authentication, main/visitor S2S routes and browser BOSH/WebSocket proxying. The upstream package reference describes these moving parts, but there is no complete released Docker visitor recipe. [S6][S8][S9]Only after that topology works, set:
ConfigENABLE_VISITORS=1 VISITORS_MAX_PARTICIPANTS=30 VISITORS_MAX_VISITORS_PER_NODE=250These use an example speaker threshold and Docker’s visitor-room default.
VISITORS_XMPP_SERVERtakes comma-separatedhost[:port]entries for your configured nodes, starting atv0. Validate C2S and S2S ports separately. Stock Compose omitsVISITORS_XMPP_PORTandJICOFO_VISITORS_REQUIRE_MUC_CONFIGfrom Jicofo’s environment. Custom deployments must forward settings they use. [S4][S6][S7] -
Docker stable-11248: choose promotion policy. Visitors request participation with Raise your hand; moderators use Admit, Reject or Admit all. Promotion allows joining the main meeting and publishing media. Docker renders
auto_allow_visitor_promotion = true, so approval is not required by default. There is no corresponding Docker environment switch. [S5][S10][S11][S13]For moderator approval, adapt the server configuration to
auto_allow_visitor_promotion = falseand configure the documented conference-request HTTP route. The package reference also requiresconferenceRequestUrlin the browser configuration. Test this custom arrangement before the event. [S8][S10] -
Debian/Ubuntu packages, Jitsi Meet 11248: use the package topology reference. It creates numbered Prosody instances, including
/etc/prosody-v1/prosody.cfg.lua, and requires manual main-Prosody and Nginx wiring. Review its helper before running it: it uses shell tracing while handling the existing Jicofo password. Do not run it blindly on production. [S8][S25]For configured visitor nodes with
hoconinstalled, activate with: [S8]Terminalsudo hocon -f /etc/jitsi/jicofo/jicofo.conf set "jicofo.visitors.enabled" true sudo hocon -f /etc/jitsi/jicofo/jicofo.conf set "jicofo.visitors.max-participants" 30 sudo service prosody restart sudo service jicofo restart sudo service nginx restartThe package example includes lobby and AV moderation. For sent-message deletion, add
"muc_message_moderation";to the existingmodules_enabledlists of the main and breakout MUC components in/etc/prosody/conf.avail/meet.example.com.cfg.lua, then check and restart Prosody. Visitor MUCs need it for local history too. Docker.envvariables do not configure packages. [S12][S15][S22]Terminalsudo prosodyctl check config sudo service prosody restart -
Both installation types, 11248: restrict group chat separately. Docker loads
filter_messageswithPROSODY_ENABLE_FILTER_MESSAGES=1; packages need"filter_messages";in the main and breakout MUC module lists. [S5][S24]Docker: append
config.showChatPermissionsModeratorSetting = true;to${CONFIG}/web/custom-config.js, owned by UID 1000, then recreateweb. Packages: setshowChatPermissionsModeratorSetting: true,in/etc/jitsi/meet/meet.example.com-config.js. The moderator checkbox is hidden when room metadata reportsallownersEnabled. [S2][S15][S21][S24]The moderator opens Settings, Moderator and selects Disable chat for non-moderators. This sets
groupChatRestrictedfor that room. [S13][S24]When
groupChatRestrictedis true, the server requiressend-groupchatpermission. Built-in defaults grant non-token moderators access. A JWT containing features must explicitly grant it, even for a moderator. Test allowed and denied senders before the event. [S24]
Configuration reference
Defaults below apply to Docker stable-11248, unless marked otherwise. [S4][S5][S6][S7]
| Setting | Where | Default | Purpose |
|---|---|---|---|
ENABLE_VISITORS |
Docker .env |
0 |
Enables visitor support, not extra services. [S6][S7] |
VISITORS_MAX_PARTICIPANTS |
Docker .env |
Unset, Jicofo uses 50 |
Main-participant threshold. [S7] |
VISITORS_MAX_VISITORS_PER_NODE |
Docker .env |
250 |
Jicofo selection threshold and visitor MUC occupant cap. [S6][S7] |
VISITORS_XMPP_SERVER |
Docker .env |
Empty | Comma-separated configured visitor servers. [S6][S7] |
VISITORS_XMPP_DOMAIN |
Docker .env |
meet.jitsi |
Visitor domain base. [S6][S7] |
VISITORS_XMPP_AUTH_DOMAIN |
Jicofo environment | auth.meet.jitsi |
Visitor authentication domain. [S7] |
PROSODY_VISITORS_MUC_PREFIX |
Docker .env |
muc |
Visitor room domain prefix. [S6][S7] |
VISITORS_XMPP_PORT |
Docker environment | 52220 plus index |
Template fallback, verify forwarding and routing. [S4][S6][S7] |
JICOFO_VISITORS_REQUIRE_MUC_CONFIG |
Jicofo environment | 0 |
Requires room visitor flag when enabled. [S7] |
PROSODY_MODE |
Each Prosody service | client |
Use visitors on separate visitor nodes. [S6] |
PROSODY_VISITOR_INDEX |
Visitor service | 0 |
Number used in its XMPP domain. [S6] |
ENABLE_LOBBY |
Docker .env |
true |
Loads lobby support. [S5] |
ENABLE_AV_MODERATION |
Docker .env |
true |
Loads AV moderation support. [S5] |
ENABLE_MESSAGE_MODERATION |
Prosody environment | true |
Sent-message deletion; Compose forwarding required. [S4][S5] |
PROSODY_ENABLE_FILTER_MESSAGES |
Docker .env |
false |
Loads server chat restriction. [S5] |
auto_allow_visitor_promotion |
Visitors component | Docker true, module false |
Automatic versus approved promotion. [S5][S10] |
conferenceRequestUrl |
Browser config.js |
Unset | HTTP conference/promotion requests. [S8][S24] |
showChatPermissionsModeratorSetting |
Browser config.js |
Unset, control hidden | Shows chat permission control. [S24] |
groupChatRestricted |
Room permissions metadata | Unset | Activates restricted group chat. [S24] |
allownersEnabled |
Room metadata | Deployment-dependent | Hides chat permission control when true. [S24] |
send-groupchat |
JWT context features | Absent means denied when restricted | Allows the sender to post. [S24] |
jicofo.visitors.enabled |
Package jicofo.conf |
false |
Activates configured visitor topology. [S7] |
jicofo.visitors.max-participants |
Package jicofo.conf |
50 |
Threshold used by package activation step. [S7] |
Common mistakes
- Turning on lobby after visitors arrive: the 11248 client refuses this. Browser console text is exactly
Ignoring enable lobby request because there are visitors in the call already.Plan admission before opening the audience. [S14] - Treating demotion as harmless: #2103 reports everyone disconnecting when a moderator makes a participant a visitor. It was closed for inactivity, not a confirmed fix; its custom stack PR was not merged. Cause remains unconfirmed, not fixed as of 2026-10-06. [S16]
- Assuming stable-11248 fixes memory growth: #2411 reports an expired non-visitor endpoint retained in speech activity, followed by
java.lang.OutOfMemoryError: Java heap space. Proposed PR #2461 is open and unmerged. Stable-11248 retains the original code, not fixed as of 2026-10-06. [S17][S18][S19] - Using limits as capacity proof: Jicofo selection is soft; Prosody enforces an occupant cap. Measure before raising either. [S6][S7]
Verify
Docker stable-11248: confirm selected images and rendered message moderation without printing passwords. [S4][S21][S23][S26]
docker compose -f docker-compose.yml -f compose.override.yaml config --images
docker compose -f docker-compose.yml -f compose.override.yaml exec -T prosody grep -oF '"muc_message_moderation";' /run/prosody/config/conf.d/jitsi-meet.cfg.luaAll Jitsi image tags should end in :stable-11248. With default breakout support, the second command returns exactly two lines, one per configured MUC: [S4][S5]
"muc_message_moderation";
"muc_message_moderation";This proves rendered configuration. On both 11248 installation types, join as moderator and attendee. Enable lobby before visitors join, approve the attendee and delete a test message. Another browser should display Deleted by a moderator. Test visitor admission above the example threshold, then request promotion under your chosen policy. Repeat departures during prolonged load. [S7][S10][S11][S13][S14]
If it still fails
For Docker 11248, collect service logs. Include your custom visitor services separately; their names depend on your deployment. [S21]
docker compose -f docker-compose.yml -f compose.override.yaml logs --tail 100 prosody jicofo jvb webVisitor Prosody startup should report Prosody visitor mode, using alternate config. Promotion rejection can contain Visitor needs to be allowed by a moderator. Restricted chat can return Sending group messages not allowed. Investigate the relevant topology or permission, not an assumed participant limit. [S10][S24][S26]
For packages, inspect /var/log/prosody/prosody.log and /var/log/jitsi/jicofo.log. Check visitor S2S connections, browser proxy requests and promotion routing. For growing bridge memory, preserve logs and heap evidence for #2411; extra heap does not establish that retention is fixed. [S3][S8][S17]
FAQ
Does ENABLE_VISITORS=1 support thousands of viewers?
It enables configuration support. Extra Prosody nodes, proxy routes and bridge capacity are still required; no fixed capacity follows from the switch. [S8][S9]
Can moderators promote visitors to speakers?
Yes, current code supports requests and approval. Docker defaults to automatic promotion, so moderator approval requires adapting the server policy. [S5][S10][S11]
Should I use visitors or live streaming?
Choose visitors for conference-like latency and possible promotion. Choose a Jibri stream to a streaming service for a mainly passive audience, with that service handling distribution. [S20]
Does message moderation approve every message first?
No. It supports deletion after sending. Restricted chat is a separate feature with explicit sender permission checks. [S12][S24]
Sources
[S1] stable-11248 release, 2026-09-14; release note, latest checked 2026-10-06.
[S2] Docker handbook, checked 2026-10-06; official doc.
[S3] Scalable setup, checked 2026-10-06; official doc.
[S4] 11248 Compose, 2026-09-14; source code.
[S5] 11248 main Prosody template, 2026-09-14; source code. PR #2318, 2026-09-04; maintainer change.
[S6] Visitor template and global template, 2026-09-14; source code.
[S7] Docker Jicofo template and 11248 reference, 2026-09-14; source code.
[S8] Extra-large conference reference, 11248, checked 2026-10-06; official repository doc.
[S9] Maintainer on missing Docker visitor setup, 2025-12-01; maintainer comment.
[S10] Visitors component, checked 2026-10-06; source code.
[S11] Visitor actions and approval UI, checked 2026-10-06; source code.
[S12] Message moderation module, checked 2026-10-06; source code.
[S13] Message menu and labels, checked 2026-10-06; source code.
[S14] Lobby actions, checked 2026-10-06; source code.
[S15] Package example, Prosody installer and web installer, checked 2026-10-06; source code.
[S16] Disconnect report #2103, 2025-05-29, and custom PR #2086; community report, status checked 2026-10-06.
[S17] Bridge retention/OOM #2411, 2026-05-13; community report, open on 2026-10-06.
[S18] Proposed fix #2461, 2026-10-05; source code proposal, unmerged on 2026-10-06.
[S19] 11248 endpoint expiry, checked 2026-10-06; source code.
[S20] Large-audience architecture, 2022-11-10; official engineering article.
[S21] Docker merge, up, config, exec and logs, checked 2026-10-06; official docs.
[S22] prosodyctl, 2026-02-09; official doc.
[S23] grep manual, checked 2026-10-06; official package documentation.
[S24] Chat filter, permissions, config, moderator settings and metadata action, checked 2026-10-06; source code.
[S25] Package setup helper, checked 2026-10-06; source code.
[S26] Docker Prosody startup, 2026-09-14; source code.
Open questions
- A complete custom Docker visitor topology and the package reference need testing on a real server; this guide does not claim a tested production recipe.
- Individual visitor chat permissions across S2S forwarding need runtime verification. [S24]
- #2103 supplies no confirmed disconnect cause or fix. #2461 has not shipped; the separate memory observations in #2411 remain unresolved. [S16][S17][S18]
- The reference’s old opening says promotion is unavailable, while its later instructions and current code implement it. Capacity for your codec mix, network and deployment requires measurement. [S8][S11]