Prosody "unable to find the configuration file" after a Jitsi Docker upgrade

Short answer

Since stable-11146 the Prosody container builds its config in /run/prosody/config/prosody.cfg.lua every time it starts, so a bare prosodyctl looks in an old default path and prints this error. Prosody itself is running fine. Run prosodyctl with --config /run/prosody/config/prosody.cfg.lua, and register users against your XMPP domain, meet.jitsi by default. An empty prosody/config folder on the host is normal now.

Symptoms

You upgraded docker-jitsi-meet to stable-11146 or newer and tried to add a user for a secure domain setup. prosodyctl stops with this message:

Text
**************************
Prosody was unable to find the configuration file:
/etc/prosody//config/prosody.cfg.lua

A sample config file is included in the Prosody download called prosody.cfg.lua.dist
Copy or rename it to /etc/prosody//config/prosody.cfg.lua and edit as necessary.

Other signs you are looking at the same thing:

  • /etc/prosody does not exist inside the Prosody container.
  • ~/.jitsi-meet-cfg/prosody/config on the host is empty, where older releases kept prosody.cfg.lua.
  • Meetings work without login, but you cannot create the moderator accounts that ENABLE_AUTH=1 needs.

It affects the Docker images from stable-11146 to stable-11248, the latest release as of 2026-10-05. Debian and Ubuntu package installs are not affected.

Cause

stable-11146 made every container rootless with a read-only filesystem. The Prosody container no longer writes its config next to your mounted files. At every start it:

  1. copies everything in /config (your host prosody/config folder) into /run/prosody/config,
  2. renders prosody.cfg.lua and conf.d from templates into /run/prosody/config,
  3. starts Prosody with --config /run/prosody/config/prosody.cfg.lua.

/run is an in-memory folder inside the container, so the generated config never appears on the host. The Prosody service knows where to look, but a prosodyctl you type by hand does not. It falls back to a default path that does not exist in the new image, and prints the error above.

The Jitsi Docker guide still showed the old commands for the first days after the release. A Jitsi maintainer confirmed the fix in issue #2302, and the Docker guide was corrected on 2026-08-10. The handbook’s older secure domain page has not been updated: it still tells Docker users to run prosodyctl --config /config/prosody.cfg.lua, and that file no longer exists in the new images.

Fix

1. Pass the config path to every prosodyctl command

From the docker-jitsi-meet folder on the host:

Terminal
docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua register alice meet.jitsi 'a-strong-password'

Replace alice and the password with your own. Every prosodyctl command in the new images needs the same --config flag. To remove a user:

Terminal
docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua unregister alice meet.jitsi

2. Use your XMPP domain, not the auth domain

Register users on meet.jitsi, or on the value of XMPP_DOMAIN if you changed it in .env. That is the domain the handbook uses for internal authentication. Users registered on auth.meet.jitsi are created without errors, but people report that logging in with them fails (issue #2302, issue #2316). If you made accounts there, unregister them and create them again on meet.jitsi.

For authentication itself, .env needs at least:

Config
ENABLE_AUTH=1
AUTH_TYPE=internal

The secure domain guide covers guests and moderators in full.

3. If the Prosody container will not start at all

That is a different problem with the same upgrade: the new storage folder is missing or not writable by the container user (uid 1000). The Prosody log then shows one of these:

Text
FATAL ERROR: required directory '/var/lib/prosody' is missing.
FATAL ERROR: directory '/var/lib/prosody' is not writable by the container user (uid 1000).

Create the folders the handbook lists for upgrades from older releases, then start again:

Terminal
mkdir -p ~/.jitsi-meet-cfg/storage/{jibri,prosody,transcripts,web}
mkdir -p ~/.jitsi-meet-cfg/tmp/{web-crontabs,web-load-test}
chmod 777 ~/.jitsi-meet-cfg/storage/{jibri,prosody,transcripts,web}
chmod 777 ~/.jitsi-meet-cfg/tmp/{web-crontabs,web-load-test}
docker compose up -d

If your CONFIG in .env is not ~/.jitsi-meet-cfg, use your own path. The full upgrade is in Upgrade docker-jitsi-meet to the rootless releases.

4. Your old accounts

On its first start, the new image copies accounts from the old prosody/config/data folder into the new data folder, as long as the new one is still empty. Where the accounts end up depends on the release:

Release Data folder in the container On the host
stable-11146, stable-11146-1 /var/lib/prosody ${CONFIG}/storage/prosody
stable-11146-2 and newer /var/lib/prosody/data ${CONFIG}/storage/prosody/data

Debian and Ubuntu packages

Package installs keep their config in /etc/prosody, so prosodyctl works without --config. Register users on your public domain:

Terminal
sudo prosodyctl register alice meet.example.com 'a-strong-password'

Verify

Create a user, then list the accounts on stable-11146-2 and newer:

Terminal
docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua register alice meet.jitsi 'a-strong-password'
docker compose exec prosody find /var/lib/prosody/data/meet%2ejitsi/accounts -type f -name '*.dat'

The account file proves it worked:

Text
/var/lib/prosody/data/meet%2ejitsi/accounts/alice.dat

The register command itself may print a line such as User account created: alice@meet.jitsi, or nothing at all. Then open https://meet.example.com, start a meeting, and log in as alice when asked.

If it still fails

  • Read the Prosody log: docker compose logs --tail=100 prosody. Look for FATAL ERROR lines about folders.
  • Check the generated config exists: docker compose exec prosody ls /run/prosody/config should list prosody.cfg.lua and conf.d.
  • Check all images come from the same release with docker compose images. Mixing old and new images breaks in unpredictable ways.
  • The user exists but login still fails: check ENABLE_AUTH=1, AUTH_TYPE=internal and the domain you registered on, then restart the stack.
  • Accounts you had before the upgrade are missing: the new data folder already held files on the first start, so nothing was copied. Copy the old prosody/config/data contents into the folder from the table above, keep uid 1000 ownership, and restart Prosody.

What we have not confirmed yet

We checked everything above against the stable-11248 Prosody scripts and templates, the Jitsi handbook and maintainer comments on 2026-10-05. We have not yet run every step on a real upgraded server. These points are still open:

  • The exact output of register on stable-11248. The handbook says it prints nothing; a maintainer’s example shows an info line.
  • Why the fallback path is printed as /etc/prosody//config/prosody.cfg.lua, with a double slash.
  • Whether accounts that were registered on auth.meet.jitsi before the upgrade still work after it.

Sources

Need a hand?

If users still cannot log in after this, contact our engineers with your .env without secrets and the output of docker compose logs --tail=100 prosody. Our support plans cover upgrades to the rootless releases.

Collect debug info

These commands gather what an engineer needs to diagnose a Jitsi server. Copy them, run them, and keep the output.

Terminal
# Run on the server, from your docker-jitsi-meet folder

# 1. Every service should be "running" (or "healthy")
docker compose ps

# 2. Which images and release tags are running
docker compose images

# 3. Recent logs from the core services
docker compose logs --tail=200 web prosody jicofo jvb

# 4. The settings most fixes depend on
grep -E '^(PUBLIC_URL|JVB_ADVERTISE_IPS|ENABLE_LETSENCRYPT|ENABLE_AUTH|AUTH_TYPE)=' .env

# 5. Is anything listening for media on UDP 10000?
sudo ss -ulnp | grep 10000

Installed with the Debian packages instead of Docker? Read the service logs with:

Terminal
sudo journalctl -u prosody -u jicofo -u jitsi-videobridge2 --since "1 hour ago"

Remove passwords, secrets and tokens before you share any output.

Send the output to an engineer

Frequently asked questions

Is my Prosody broken if prosodyctl shows this error?

No. The Prosody service starts with the right config file. Only prosodyctl commands typed without --config look in the wrong place.

Why is the prosody/config folder on my host empty?

Since stable-11146 it is an input folder. Prosody copies anything you put there into /run/prosody/config at start and writes the generated config there, never back to the host.

Should I register users on meet.jitsi or auth.meet.jitsi?

On meet.jitsi, or whatever XMPP_DOMAIN is set to. That is what the Jitsi handbook uses for internal authentication. Users report that accounts created on auth.meet.jitsi do not work for meeting logins.

Did I lose my users when I upgraded?

Normally not. On the first start of the new image, Prosody copies accounts from the old prosody/config/data folder into the new storage folder, if the new one is still empty.

Stuck, or would rather not do this by hand?

Deploy it in one click

A private Jitsi server in your own AWS account with SSL, your domain and optional recording, transcription and JWT. Free 15 minute trial.

Start free trial

Talk to a Jitsi engineer

Setup, fixes, branding, recording, scaling. Tell us what is happening and we reply with a plan and a quote.

Get expert help

Related

Recently updated