Symptoms
You upgraded docker-jitsi-meet to stable-11146 or newer and tried to add a user for a secure domain setup. prosodyctl stops with this message:
**************************
Prosody was unable to find the configuration file:
/etc/prosody//config/prosody.cfg.lua
A sample config file is included in the Prosody download called prosody.cfg.lua.dist
Copy or rename it to /etc/prosody//config/prosody.cfg.lua and edit as necessary.Other signs you are looking at the same thing:
/etc/prosodydoes not exist inside the Prosody container.~/.jitsi-meet-cfg/prosody/configon the host is empty, where older releases keptprosody.cfg.lua.- Meetings work without login, but you cannot create the moderator accounts that
ENABLE_AUTH=1needs.
It affects the Docker images from stable-11146 to stable-11248, the latest release as of 2026-10-05. Debian and Ubuntu package installs are not affected.
Cause
stable-11146 made every container rootless with a read-only filesystem. The Prosody container no longer writes its config next to your mounted files. At every start it:
- copies everything in
/config(your hostprosody/configfolder) into/run/prosody/config, - renders
prosody.cfg.luaandconf.dfrom templates into/run/prosody/config, - starts Prosody with
--config /run/prosody/config/prosody.cfg.lua.
/run is an in-memory folder inside the container, so the generated config never appears on the host. The Prosody service knows where to look, but a prosodyctl you type by hand does not. It falls back to a default path that does not exist in the new image, and prints the error above.
The Jitsi Docker guide still showed the old commands for the first days after the release. A Jitsi maintainer confirmed the fix in issue #2302, and the Docker guide was corrected on 2026-08-10. The handbook’s older secure domain page has not been updated: it still tells Docker users to run prosodyctl --config /config/prosody.cfg.lua, and that file no longer exists in the new images.
Fix
1. Pass the config path to every prosodyctl command
From the docker-jitsi-meet folder on the host:
docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua register alice meet.jitsi 'a-strong-password'Replace alice and the password with your own. Every prosodyctl command in the new images needs the same --config flag. To remove a user:
docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua unregister alice meet.jitsi2. Use your XMPP domain, not the auth domain
Register users on meet.jitsi, or on the value of XMPP_DOMAIN if you changed it in .env. That is the domain the handbook uses for internal authentication. Users registered on auth.meet.jitsi are created without errors, but people report that logging in with them fails (issue #2302, issue #2316). If you made accounts there, unregister them and create them again on meet.jitsi.
For authentication itself, .env needs at least:
ENABLE_AUTH=1
AUTH_TYPE=internalThe secure domain guide covers guests and moderators in full.
3. If the Prosody container will not start at all
That is a different problem with the same upgrade: the new storage folder is missing or not writable by the container user (uid 1000). The Prosody log then shows one of these:
FATAL ERROR: required directory '/var/lib/prosody' is missing.
FATAL ERROR: directory '/var/lib/prosody' is not writable by the container user (uid 1000).Create the folders the handbook lists for upgrades from older releases, then start again:
mkdir -p ~/.jitsi-meet-cfg/storage/{jibri,prosody,transcripts,web}
mkdir -p ~/.jitsi-meet-cfg/tmp/{web-crontabs,web-load-test}
chmod 777 ~/.jitsi-meet-cfg/storage/{jibri,prosody,transcripts,web}
chmod 777 ~/.jitsi-meet-cfg/tmp/{web-crontabs,web-load-test}
docker compose up -dIf your CONFIG in .env is not ~/.jitsi-meet-cfg, use your own path. The full upgrade is in Upgrade docker-jitsi-meet to the rootless releases.
4. Your old accounts
On its first start, the new image copies accounts from the old prosody/config/data folder into the new data folder, as long as the new one is still empty. Where the accounts end up depends on the release:
| Release | Data folder in the container | On the host |
|---|---|---|
| stable-11146, stable-11146-1 | /var/lib/prosody |
${CONFIG}/storage/prosody |
| stable-11146-2 and newer | /var/lib/prosody/data |
${CONFIG}/storage/prosody/data |
Debian and Ubuntu packages
Package installs keep their config in /etc/prosody, so prosodyctl works without --config. Register users on your public domain:
sudo prosodyctl register alice meet.example.com 'a-strong-password'Verify
Create a user, then list the accounts on stable-11146-2 and newer:
docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua register alice meet.jitsi 'a-strong-password'
docker compose exec prosody find /var/lib/prosody/data/meet%2ejitsi/accounts -type f -name '*.dat'The account file proves it worked:
/var/lib/prosody/data/meet%2ejitsi/accounts/alice.datThe register command itself may print a line such as User account created: alice@meet.jitsi, or nothing at all. Then open https://meet.example.com, start a meeting, and log in as alice when asked.
If it still fails
- Read the Prosody log:
docker compose logs --tail=100 prosody. Look forFATAL ERRORlines about folders. - Check the generated config exists:
docker compose exec prosody ls /run/prosody/configshould listprosody.cfg.luaandconf.d. - Check all images come from the same release with
docker compose images. Mixing old and new images breaks in unpredictable ways. - The user exists but login still fails: check
ENABLE_AUTH=1,AUTH_TYPE=internaland the domain you registered on, then restart the stack. - Accounts you had before the upgrade are missing: the new data folder already held files on the first start, so nothing was copied. Copy the old
prosody/config/datacontents into the folder from the table above, keep uid 1000 ownership, and restart Prosody.
What we have not confirmed yet
We checked everything above against the stable-11248 Prosody scripts and templates, the Jitsi handbook and maintainer comments on 2026-10-05. We have not yet run every step on a real upgraded server. These points are still open:
- The exact output of
registeron stable-11248. The handbook says it prints nothing; a maintainer’s example shows an info line. - Why the fallback path is printed as
/etc/prosody//config/prosody.cfg.lua, with a double slash. - Whether accounts that were registered on
auth.meet.jitsibefore the upgrade still work after it.
Sources
- docker-jitsi-meet issue #2302 Prosody unable to find config file after updating to stable-11146-1, 2026-08-08 to 2026-08-22, community report with maintainer answers (saghul, emrahcom)
- Jitsi handbook, Self-Hosting Guide: Docker (internal authentication, updating from a release older than stable-11146), checked 2026-10-05, official doc
- Jitsi handbook commit 25ef943 fix(docker): correct the prosodyctl config and account data paths, 2026-08-10, official doc change
- docker-jitsi-meet prosody/rootfs/etc/s6-overlay/scripts/config at stable-11248, source code
- docker-jitsi-meet prosody/rootfs/etc/s6-overlay/scripts/prosody at stable-11248 (starts Prosody with –config), source code
- docker-jitsi-meet base/rootfs/usr/bin/check-writable at stable-11248 (folder error messages), source code
- docker-jitsi-meet docker-compose.yml at stable-11248 (Prosody volumes and tmpfs), source code
- docker-jitsi-meet release stable-11146 (rootless containers, PR #2258), 2026-08-03, release note
- docker-jitsi-meet release stable-11146-2 (PR #2304 create the Prosody data folder at runtime), 2026-08-17, release note
- docker-jitsi-meet issue #2316 Secure-domain login fails when auth domain differs from XMPP_DOMAIN, 2026-09, community report
- Jitsi handbook, Secure domain setup (Debian packages), official doc
Need a hand?
If users still cannot log in after this, contact our engineers with your .env without secrets and the output of docker compose logs --tail=100 prosody. Our support plans cover upgrades to the rootless releases.