Why do JVB and Jicofo disconnect from Prosody after upgrading?

Short answer

Issue #2336 has no confirmed root cause or universal fix as of 2026-10-05. [S1] Maintainers asked for matching Compose files, the new configuration directories and a specific image release instead of the moving stable tag. [S2] Align those first, then investigate Prosody authentication and limits using its actual logs; neither passwords nor rate limits were established as this report's cause. [S2][S5][S6]

Symptoms

Issue #2336 reports these lines after upgrading stable-11031 to stable-11248. Failed negotiation does not prove the Java processes exited. [S1]

JVB: [S1]

Text
jvb-1  | org.jivesoftware.smack.XMPPException$StreamErrorException: undefined-condition You can read more about the meaning of this stream error at http://xmpp.org/rfcs/rfc6120.html#streams-error-conditions
jvb-1  | <stream:error><undefined-condition xmlns='urn:ietf:params:xml:ns:xmpp-streams'/><text>No stream features to proceed with</text></stream:error>

Jicofo: [S1]

Text
jicofo-1  | org.jivesoftware.smack.XMPPException$StreamErrorException: undefined-condition You can read more about the meaning of this stream error at http://xmpp.org/rfcs/rfc6120.html#streams-error-conditions
jicofo-1  | <stream:error><undefined-condition xmlns='urn:ietf:params:xml:ns:xmpp-streams'/><text>No stream features to proceed with</text></stream:error>

Prosody logs were not supplied in #2336. These warning bodies come from a separate stable-7577 report, not confirmed stable-11248 output: [S3]

Text
No available SASL mechanisms, verify that the configured authentication module 'token' is loaded and configured correctly
No stream features to offer on secure session. Check authentication settings.

Cause

The root cause remains unknown. The report uses JITSI_IMAGE_VERSION=stable; a maintainer asked to remove it so the release Compose file controls the version. A moving tag makes the tested build uncertain, but the thread does not prove mixed images caused this failure. [S2]

For stable-11248, distinguish these candidates: [S2][S5][S6]

Candidate Evidence and limitation
Stale configuration or mounts Maintainers asked about the new directories. Runtime config is regenerated, but copied input files and extra conf.d files can persist. Do not assume deleting the whole volume is required. [S2][S5]
Mixed releases Confirm Compose defaults, overrides and created containers. stable is not a specific release pin. [S2][S7]
Authentication Prosody and clients use JVB_AUTH_PASSWORD and JICOFO_AUTH_PASSWORD. Missing values have explicit startup errors. Wrong credentials or an unavailable auth mechanism require their own evidence. [S5][S6]
Prosody limits Bandwidth limits and optional login/session rate limits are different mechanisms. No limiter error was shown in #2336. [S5][S8]

PR #2309 adds ::1 to the rate-limit whitelist and is included in stable-11248. It is already present in that release, not a later fix for #2336. PROSODY_ENABLE_RATE_LIMITS defaults to 0 in the site template. Do not attribute every stream error to this limiter. [S4][S5]

Fix

Docker: stable-11248 diagnostic procedure

  1. Capture all three services together. Run from your deployment project, using your normal Compose overlays: [S7]

    Terminal
    docker compose logs --since 10m --tail 200 prosody jicofo jvb
    docker compose images
    docker compose config --images

    Keep the earlier Prosody messages preceding the disconnect. Image lists do not expose service passwords; full rendered configuration can, so avoid publishing it unredacted. [S7]

  2. Align files and images. Download the stable-11248 release archive and merge its Compose files with your local changes. Comment out JITSI_IMAGE_VERSION=stable as the maintainer requested, or explicitly select JITSI_IMAGE_VERSION=stable-11248. Inspect service-level image overrides too. stable-11248 remains the latest release checked on 2026-10-05. [S2][S4][S7]

    Expected core image references from docker compose config --images, order may differ: [S7]

    Text
    ghcr.io/jitsi/web:stable-11248
    ghcr.io/jitsi/prosody:stable-11248
    ghcr.io/jitsi/jicofo:stable-11248
    ghcr.io/jitsi/jvb:stable-11248
  3. Check the migrated directories. For upgrades from before stable-11146, create the handbook directories under your actual CONFIG path. Default path, ~/.jitsi-meet-cfg: [S9]

    Terminal
    mkdir -p ~/.jitsi-meet-cfg/{web,prosody/config,prosody/prosody-plugins-custom,jicofo,jvb,jigasi,jibri,transcriber}
    mkdir -p ~/.jitsi-meet-cfg/storage/{jibri,prosody,transcripts,web}
    mkdir -p ~/.jitsi-meet-cfg/tmp/{web-crontabs,web-load-test}
    sudo chown -R 1000:1000 ~/.jitsi-meet-cfg/storage ~/.jitsi-meet-cfg/tmp

    Writable storage must be accessible to UID 1000. Prosody accounts now live under ${CONFIG}/storage/prosody, mounted at /var/lib/prosody; old accounts are copied only when that destination is empty. Preserve both account stores during diagnosis. [S5][S9]

  4. Check configuration and authentication. Inspect the generated files locally, not an old host-side generated file: [S5][S6]

    Terminal
    docker compose exec prosody ls -l /config /run/prosody/config/conf.d
    docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua check config

    Review extra input configuration against the new template. The internal auth host, normally auth.meet.jitsi, uses authentication = "internal_hashed". Check that the JVB/Jicofo auth domain matches it. Preserve the existing service secrets in .env; verify each matches the corresponding client’s configuration and Prosody account. Do not rotate all passwords as an unexplained repair. [S5][S6]

    Missing passwords produce these exact Prosody startup messages: [S5]

    Text
    FATAL ERROR: Jicofo auth password must be set
    FATAL ERROR: JVB auth password must be set
  5. Inspect limits only when supported by logs. Review PROSODY_C2S_LIMIT, PROSODY_DISABLE_C2S_LIMIT, PROSODY_ENABLE_RATE_LIMITS and any local whitelist changes. Check the generated configuration against stable-11248, including ::1. No proven replacement limit value or blanket disabling workaround exists for #2336. [S4][S5][S8]

  6. Apply the corrections in a maintenance window. Validate, pull and recreate the stack: [S7]

    Terminal
    docker compose config -q
    docker compose pull
    docker compose up -d --force-recreate
    docker compose images

    In the last command, every core service’s TAG should be stable-11248. This checks created containers, whereas config --images checks intended configuration. [S7]

Debian/Ubuntu packages

For the package layout reviewed at release 11248, Docker image selectors and rootless volume migration do not apply. The package installer uses /etc/prosody/conf.avail/meet.example.com.cfg.lua for that domain. Inspect its auth host and modules, and correlate Prosody logs with the clients. [S10]

Terminal
sudo prosodyctl check config
sudo tail -n 200 /var/log/prosody/prosody.log

The log path is Prosody’s documented file-logging example; confirm your configured sink before using it. Validate local changes before restarting through your system’s service manager. No Debian/Ubuntu package fix version was established by #2336. [S1][S11]

Verify

For stable-11248 Docker, repeat the image checks, then read fresh logs: [S7]

Terminal
docker compose logs --since 5m prosody jicofo jvb

On successful service-account creation, the upstream registration script emits: [S6]

Text
[register-setup] Focus user registered successfully
[register-setup] JVB user registered successfully

These prove that registration commands succeeded, not that clients authenticated and stayed connected. Existing accounts can produce different registration output. Confirm no recurring stream failures and test a meeting at https://meet.example.com with three participants, which exercises the bridge. There is no universal success line established by #2336. [S1][S6][S12]

If it still fails

For stable-11248 Docker, temporarily set LOG_LEVEL=debug in .env, recreate Prosody and gather correlated logs. Restore the previous level afterwards. The template sends that level to the console. [S5][S7]

Provide image tags, redacted environment settings, mount locations and the earliest Prosody warning. State whether failure precedes authentication or follows a successful connection. These candidates need evidence before being called causes. [S1][S2][S5]

FAQ

Is stable-11248 definitely broken?

The upgrade failure is reported, but no general release defect was established. #2336 is open as of 2026-10-05. [S1]

Does the ::1 whitelist fix solve this?

It is already included in stable-11248. The thread does not link its failure to that limiter. [S4]

Should I delete the config volume?

No such fix was confirmed. Review copied configuration while preserving Prosody accounts and other persistent state. [S5][S9]

Does undefined-condition mean a wrong password?

Not by itself. The accompanying text and Prosody’s preceding messages are needed; an older report showed unavailable authentication mechanisms. [S1][S3]

Sources

[S1] Issue #2336, opened 2026-10-01, checked 2026-10-05, community report, still open.

[S2] Maintainer discussion, 2026-10-01, maintainer comments on Compose, directories and image selection.

[S3] Issue #1358, 2022-08-08, community report on stable-7577, historical Prosody warnings.

[S4] stable-11248 notes, latest release API, and PR #2309, August/September 2026, checked 2026-10-05, release note and source code.

[S5] stable-11248 Prosody startup, global template, site template, checked 2026-10-05, source code.

[S6] stable-11248 registration, JVB, Jicofo, checked 2026-10-05, source code.

[S7] stable-11248 Compose; Docker CLI config, images, logs, exec, pull, up, checked 2026-10-05, source code and official doc.

[S8] Prosody mod_limits, checked 2026-10-05, official doc.

[S9] Docker handbook, updating, and Coreutils manual, checked 2026-10-05, official doc.

[S10] Package Prosody installer, release 11248, checked 2026-10-05, source code.

[S11] Prosody checks and logging, checked 2026-10-05, official doc.

[S12] Jitsi Meet config.js, release 11248, checked 2026-10-05, source code, three-participant bridge switching.

Open questions

No confirmed root cause, Prosody log excerpt or successful repair was posted in #2336 by 2026-10-05. Mixed images, stale input, limits and passwords remain checks, not proven explanations. Source-reviewed; not tested on a live Jitsi server. [S1][S2]

Collect debug info

These commands gather what an engineer needs to diagnose a Jitsi server. Copy them, run them, and keep the output.

Terminal
# Run on the server, from your docker-jitsi-meet folder

# 1. Every service should be "running" (or "healthy")
docker compose ps

# 2. Which images and release tags are running
docker compose images

# 3. Recent logs from the core services
docker compose logs --tail=200 web prosody jicofo jvb

# 4. The settings most fixes depend on
grep -E '^(PUBLIC_URL|JVB_ADVERTISE_IPS|ENABLE_LETSENCRYPT|ENABLE_AUTH|AUTH_TYPE)=' .env

# 5. Is anything listening for media on UDP 10000?
sudo ss -ulnp | grep 10000

Installed with the Debian packages instead of Docker? Read the service logs with:

Terminal
sudo journalctl -u prosody -u jicofo -u jitsi-videobridge2 --since "1 hour ago"

Remove passwords, secrets and tokens before you share any output.

Send the output to an engineer

Stuck, or would rather not do this by hand?

Deploy it in one click

A private Jitsi server in your own AWS account with SSL, your domain and optional recording, transcription and JWT. Free 15 minute trial.

Start free trial

Talk to a Jitsi engineer

Setup, fixes, branding, recording, scaling. Tell us what is happening and we reply with a plan and a quote.

Get expert help

Related

Recently updated