How do I run large Jitsi meetings with visitors and moderation?

Short answer

Visitors watch a Jitsi conference through WebRTC while extra Prosody instances distribute audience signaling. Docker stable-11248 includes visitor settings but requires a custom topology, not just ENABLE_VISITORS=1. Lobby controls admission; message moderation deletes sent chat messages and does not provide a message approval queue. [S5][S8][S9][S12]

Who this is for

You run a panel, class or town hall with many viewers and fewer speakers. stable-11248, released 2026-09-14, is still the newest Docker release checked on 2026-10-06. [S1][S20]

How it works

Visitors receive conference media without joining the main room as ordinary publishing participants. Main participants use the main Prosody instance. Additional visitor Prosody instances distribute audience signaling; multiple videobridges supply media capacity. Adding bridges alone does not build this signaling topology. [S3][S8][S20]

Upstream’s example discusses 10,000 participants, around 50 bridges on machines with at least eight cores, and 2,000 viewers per visitor node. These are sizing guidance, not a supported capacity guarantee. The reference is marked work in progress. Docker’s current default is much lower: 250 occupants per visitor room. Load-test your actual layout. [S6][S8]

Lobby holds people before admission. Audio/video moderation controls permission to publish media. Message moderation supports deleting sent messages. These are separate features; none turns ordinary room chat into a queue awaiting approval. [S5][S12][S14][S15]

Before you start

  • Have a working HTTPS meeting at meet.example.com, valid DNS and certificates. Standard public ports are TCP 80 and 443 and UDP 10000 for media. Restrict internal XMPP connections to the required servers. [S2][S3]
  • Keep the Compose files and Jitsi images from the same release. Establish moderator authentication before testing admission or moderation. [S2]
  • Budget extra Prosody instances, browser proxy routes, server-to-server XMPP routing and sufficient bridges. Stock Docker Compose starts no visitor Prosody instances. [S4][S8][S9]
  • Rehearse joins, promotion, departures and prolonged load, including known disconnect and memory problems. [S16][S17]

Steps

  1. Docker stable-11248: enable ordinary meeting moderation first. In your existing .env, set the following. Lobby and AV moderation already default to enabled; a moderator still activates the relevant room controls. [S2][S5]

    Config
    ENABLE_LOBBY=1
    ENABLE_AV_MODERATION=1
    ENABLE_MESSAGE_MODERATION=1

    ENABLE_MESSAGE_MODERATION defaults to enabled in the Prosody template, but this release’s Compose file does not forward it. To make the setting controllable, merge this fragment into compose.override.yaml. Preserve any existing overrides. [S4][S5][S21]

    YAML
    services:
      prosody:
        environment:
          ENABLE_MESSAGE_MODERATION: ${ENABLE_MESSAGE_MODERATION:-1}

    Recreate Prosody during maintenance. Use the same file list subsequently. [S21]

    Terminal
    docker compose -f docker-compose.yml -f compose.override.yaml config --quiet
    docker compose -f docker-compose.yml -f compose.override.yaml up -d prosody
  2. Docker stable-11248: prepare visitors before enabling them. Provision separate Prosody services with PROSODY_MODE=visitors and a unique PROSODY_VISITOR_INDEX. Configure Jicofo connections, authentication, main/visitor S2S routes and browser BOSH/WebSocket proxying. The upstream package reference describes these moving parts, but there is no complete released Docker visitor recipe. [S6][S8][S9]

    Only after that topology works, set:

    Config
    ENABLE_VISITORS=1
    VISITORS_MAX_PARTICIPANTS=30
    VISITORS_MAX_VISITORS_PER_NODE=250

    These use an example speaker threshold and Docker’s visitor-room default. VISITORS_XMPP_SERVER takes comma-separated host[:port] entries for your configured nodes, starting at v0. Validate C2S and S2S ports separately. Stock Compose omits VISITORS_XMPP_PORT and JICOFO_VISITORS_REQUIRE_MUC_CONFIG from Jicofo’s environment. Custom deployments must forward settings they use. [S4][S6][S7]

  3. Docker stable-11248: choose promotion policy. Visitors request participation with Raise your hand; moderators use Admit, Reject or Admit all. Promotion allows joining the main meeting and publishing media. Docker renders auto_allow_visitor_promotion = true, so approval is not required by default. There is no corresponding Docker environment switch. [S5][S10][S11][S13]

    For moderator approval, adapt the server configuration to auto_allow_visitor_promotion = false and configure the documented conference-request HTTP route. The package reference also requires conferenceRequestUrl in the browser configuration. Test this custom arrangement before the event. [S8][S10]

  4. Debian/Ubuntu packages, Jitsi Meet 11248: use the package topology reference. It creates numbered Prosody instances, including /etc/prosody-v1/prosody.cfg.lua, and requires manual main-Prosody and Nginx wiring. Review its helper before running it: it uses shell tracing while handling the existing Jicofo password. Do not run it blindly on production. [S8][S25]

    For configured visitor nodes with hocon installed, activate with: [S8]

    Terminal
    sudo hocon -f /etc/jitsi/jicofo/jicofo.conf set "jicofo.visitors.enabled" true
    sudo hocon -f /etc/jitsi/jicofo/jicofo.conf set "jicofo.visitors.max-participants" 30
    sudo service prosody restart
    sudo service jicofo restart
    sudo service nginx restart

    The package example includes lobby and AV moderation. For sent-message deletion, add "muc_message_moderation"; to the existing modules_enabled lists of the main and breakout MUC components in /etc/prosody/conf.avail/meet.example.com.cfg.lua, then check and restart Prosody. Visitor MUCs need it for local history too. Docker .env variables do not configure packages. [S12][S15][S22]

    Terminal
    sudo prosodyctl check config
    sudo service prosody restart
  5. Both installation types, 11248: restrict group chat separately. Docker loads filter_messages with PROSODY_ENABLE_FILTER_MESSAGES=1; packages need "filter_messages"; in the main and breakout MUC module lists. [S5][S24]

    Docker: append config.showChatPermissionsModeratorSetting = true; to ${CONFIG}/web/custom-config.js, owned by UID 1000, then recreate web. Packages: set showChatPermissionsModeratorSetting: true, in /etc/jitsi/meet/meet.example.com-config.js. The moderator checkbox is hidden when room metadata reports allownersEnabled. [S2][S15][S21][S24]

    The moderator opens Settings, Moderator and selects Disable chat for non-moderators. This sets groupChatRestricted for that room. [S13][S24]

    When groupChatRestricted is true, the server requires send-groupchat permission. Built-in defaults grant non-token moderators access. A JWT containing features must explicitly grant it, even for a moderator. Test allowed and denied senders before the event. [S24]

Configuration reference

Defaults below apply to Docker stable-11248, unless marked otherwise. [S4][S5][S6][S7]

Setting Where Default Purpose
ENABLE_VISITORS Docker .env 0 Enables visitor support, not extra services. [S6][S7]
VISITORS_MAX_PARTICIPANTS Docker .env Unset, Jicofo uses 50 Main-participant threshold. [S7]
VISITORS_MAX_VISITORS_PER_NODE Docker .env 250 Jicofo selection threshold and visitor MUC occupant cap. [S6][S7]
VISITORS_XMPP_SERVER Docker .env Empty Comma-separated configured visitor servers. [S6][S7]
VISITORS_XMPP_DOMAIN Docker .env meet.jitsi Visitor domain base. [S6][S7]
VISITORS_XMPP_AUTH_DOMAIN Jicofo environment auth.meet.jitsi Visitor authentication domain. [S7]
PROSODY_VISITORS_MUC_PREFIX Docker .env muc Visitor room domain prefix. [S6][S7]
VISITORS_XMPP_PORT Docker environment 52220 plus index Template fallback, verify forwarding and routing. [S4][S6][S7]
JICOFO_VISITORS_REQUIRE_MUC_CONFIG Jicofo environment 0 Requires room visitor flag when enabled. [S7]
PROSODY_MODE Each Prosody service client Use visitors on separate visitor nodes. [S6]
PROSODY_VISITOR_INDEX Visitor service 0 Number used in its XMPP domain. [S6]
ENABLE_LOBBY Docker .env true Loads lobby support. [S5]
ENABLE_AV_MODERATION Docker .env true Loads AV moderation support. [S5]
ENABLE_MESSAGE_MODERATION Prosody environment true Sent-message deletion; Compose forwarding required. [S4][S5]
PROSODY_ENABLE_FILTER_MESSAGES Docker .env false Loads server chat restriction. [S5]
auto_allow_visitor_promotion Visitors component Docker true, module false Automatic versus approved promotion. [S5][S10]
conferenceRequestUrl Browser config.js Unset HTTP conference/promotion requests. [S8][S24]
showChatPermissionsModeratorSetting Browser config.js Unset, control hidden Shows chat permission control. [S24]
groupChatRestricted Room permissions metadata Unset Activates restricted group chat. [S24]
allownersEnabled Room metadata Deployment-dependent Hides chat permission control when true. [S24]
send-groupchat JWT context features Absent means denied when restricted Allows the sender to post. [S24]
jicofo.visitors.enabled Package jicofo.conf false Activates configured visitor topology. [S7]
jicofo.visitors.max-participants Package jicofo.conf 50 Threshold used by package activation step. [S7]

Common mistakes

  • Turning on lobby after visitors arrive: the 11248 client refuses this. Browser console text is exactly Ignoring enable lobby request because there are visitors in the call already. Plan admission before opening the audience. [S14]
  • Treating demotion as harmless: #2103 reports everyone disconnecting when a moderator makes a participant a visitor. It was closed for inactivity, not a confirmed fix; its custom stack PR was not merged. Cause remains unconfirmed, not fixed as of 2026-10-06. [S16]
  • Assuming stable-11248 fixes memory growth: #2411 reports an expired non-visitor endpoint retained in speech activity, followed by java.lang.OutOfMemoryError: Java heap space. Proposed PR #2461 is open and unmerged. Stable-11248 retains the original code, not fixed as of 2026-10-06. [S17][S18][S19]
  • Using limits as capacity proof: Jicofo selection is soft; Prosody enforces an occupant cap. Measure before raising either. [S6][S7]

Verify

Docker stable-11248: confirm selected images and rendered message moderation without printing passwords. [S4][S21][S23][S26]

Terminal
docker compose -f docker-compose.yml -f compose.override.yaml config --images
docker compose -f docker-compose.yml -f compose.override.yaml exec -T prosody grep -oF '"muc_message_moderation";' /run/prosody/config/conf.d/jitsi-meet.cfg.lua

All Jitsi image tags should end in :stable-11248. With default breakout support, the second command returns exactly two lines, one per configured MUC: [S4][S5]

Text
"muc_message_moderation";
"muc_message_moderation";

This proves rendered configuration. On both 11248 installation types, join as moderator and attendee. Enable lobby before visitors join, approve the attendee and delete a test message. Another browser should display Deleted by a moderator. Test visitor admission above the example threshold, then request promotion under your chosen policy. Repeat departures during prolonged load. [S7][S10][S11][S13][S14]

If it still fails

For Docker 11248, collect service logs. Include your custom visitor services separately; their names depend on your deployment. [S21]

Terminal
docker compose -f docker-compose.yml -f compose.override.yaml logs --tail 100 prosody jicofo jvb web

Visitor Prosody startup should report Prosody visitor mode, using alternate config. Promotion rejection can contain Visitor needs to be allowed by a moderator. Restricted chat can return Sending group messages not allowed. Investigate the relevant topology or permission, not an assumed participant limit. [S10][S24][S26]

For packages, inspect /var/log/prosody/prosody.log and /var/log/jitsi/jicofo.log. Check visitor S2S connections, browser proxy requests and promotion routing. For growing bridge memory, preserve logs and heap evidence for #2411; extra heap does not establish that retention is fixed. [S3][S8][S17]

FAQ

Does ENABLE_VISITORS=1 support thousands of viewers?

It enables configuration support. Extra Prosody nodes, proxy routes and bridge capacity are still required; no fixed capacity follows from the switch. [S8][S9]

Can moderators promote visitors to speakers?

Yes, current code supports requests and approval. Docker defaults to automatic promotion, so moderator approval requires adapting the server policy. [S5][S10][S11]

Should I use visitors or live streaming?

Choose visitors for conference-like latency and possible promotion. Choose a Jibri stream to a streaming service for a mainly passive audience, with that service handling distribution. [S20]

Does message moderation approve every message first?

No. It supports deletion after sending. Restricted chat is a separate feature with explicit sender permission checks. [S12][S24]

Sources

[S1] stable-11248 release, 2026-09-14; release note, latest checked 2026-10-06.

[S2] Docker handbook, checked 2026-10-06; official doc.

[S3] Scalable setup, checked 2026-10-06; official doc.

[S4] 11248 Compose, 2026-09-14; source code.

[S5] 11248 main Prosody template, 2026-09-14; source code. PR #2318, 2026-09-04; maintainer change.

[S6] Visitor template and global template, 2026-09-14; source code.

[S7] Docker Jicofo template and 11248 reference, 2026-09-14; source code.

[S8] Extra-large conference reference, 11248, checked 2026-10-06; official repository doc.

[S9] Maintainer on missing Docker visitor setup, 2025-12-01; maintainer comment.

[S10] Visitors component, checked 2026-10-06; source code.

[S11] Visitor actions and approval UI, checked 2026-10-06; source code.

[S12] Message moderation module, checked 2026-10-06; source code.

[S13] Message menu and labels, checked 2026-10-06; source code.

[S14] Lobby actions, checked 2026-10-06; source code.

[S15] Package example, Prosody installer and web installer, checked 2026-10-06; source code.

[S16] Disconnect report #2103, 2025-05-29, and custom PR #2086; community report, status checked 2026-10-06.

[S17] Bridge retention/OOM #2411, 2026-05-13; community report, open on 2026-10-06.

[S18] Proposed fix #2461, 2026-10-05; source code proposal, unmerged on 2026-10-06.

[S19] 11248 endpoint expiry, checked 2026-10-06; source code.

[S20] Large-audience architecture, 2022-11-10; official engineering article.

[S21] Docker merge, up, config, exec and logs, checked 2026-10-06; official docs.

[S22] prosodyctl, 2026-02-09; official doc.

[S23] grep manual, checked 2026-10-06; official package documentation.

[S24] Chat filter, permissions, config, moderator settings and metadata action, checked 2026-10-06; source code.

[S25] Package setup helper, checked 2026-10-06; source code.

[S26] Docker Prosody startup, 2026-09-14; source code.

Open questions

  • A complete custom Docker visitor topology and the package reference need testing on a real server; this guide does not claim a tested production recipe.
  • Individual visitor chat permissions across S2S forwarding need runtime verification. [S24]
  • #2103 supplies no confirmed disconnect cause or fix. #2461 has not shipped; the separate memory observations in #2411 remain unresolved. [S16][S17][S18]
  • The reference’s old opening says promotion is unavailable, while its later instructions and current code implement it. Capacity for your codec mix, network and deployment requires measurement. [S8][S11]
Recently updated