HomeStart / GuidesAnleitungen / Self-hosting Jitsi Meet on a VPS/ Jitsi Meet selbst hosten auf einem VPS

Self-hosting Jitsi Meet on a VPS: Docker Compose, the .env generator, and the UDP port that decides call qualityJitsi Meet selbst hosten auf einem VPS: Docker Compose, der .env-Generator und der UDP-Port, der über die Anrufqualität entscheidet

Jitsi Meet is the self-hosted video call app that does not ask you to trust anyone else's server, and the official Docker Compose stack gets it running in under an hour — but the part that decides whether your calls actually connect cleanly lives in your network setup, not in the containers.Jitsi Meet ist die selbst gehostete Videocall-App, bei der du niemandem sonst einen Server anvertrauen musst, und der offizielle Docker-Compose-Stack bringt sie in unter einer Stunde zum Laufen — aber der Teil, der darüber entscheidet, ob deine Calls tatsächlich sauber zustande kommen, steckt in deinem Netzwerk-Setup, nicht in den Containern.

What you are actually installingWas du hier eigentlich installierst

Jitsi Meet is four containers working together, not one app: web (the nginx-served UI plus a signaling proxy), prosody (the XMPP server that handles presence and room membership), jicofo (the conference focus that manages each call's lifecycle), and jvb, the Jitsi Videobridge — the selective forwarding unit that actually relays everyone's audio and video. JVB is the one that matters for sizing: it forwards RTP streams between participants rather than decoding and re-encoding them, which is why a Jitsi server needs no GPU, but forwarding still costs real CPU and bandwidth per participant and per bitrate. Two optional containers, jigasi (SIP/dial-in gateway) and jibri (recording and streaming), exist in the same project but add real complexity and are outside what this guide covers.Jitsi Meet besteht aus vier Containern, die zusammenarbeiten, nicht aus einer einzigen App: web (die von nginx ausgelieferte UI plus ein Signaling-Proxy), prosody (der XMPP-Server, der Presence und Raum-Mitgliedschaft verwaltet), jicofo (der Conference Focus, der den Lebenszyklus jedes Calls steuert), und jvb, die Jitsi Videobridge — die Selective-Forwarding-Unit, die tatsächlich Audio und Video aller Teilnehmer weiterleitet. JVB ist der Container, der für die Dimensionierung zählt: Er leitet RTP-Streams zwischen Teilnehmern weiter, statt sie zu dekodieren und neu zu kodieren, weshalb ein Jitsi-Server keine GPU braucht — aber die Weiterleitung kostet trotzdem echte CPU- und Bandbreitenleistung pro Teilnehmer und pro Bitrate. Zwei optionale Container, jigasi (SIP/Einwahl-Gateway) und jibri (Aufzeichnung und Streaming), existieren im selben Projekt, bringen aber echte Komplexität mit und liegen außerhalb dessen, was diese Anleitung abdeckt.

The project maintains its own Docker Compose setup at jitsi/docker-jitsi-meet on GitHub, and the right move is to clone it rather than hand-write your own — the compose file, env.example, and config volume layout are kept in sync with each other and with the image releases. If this is your first Docker Compose stack on a VPS, Docker Compose on a small VPS covers the basics before you get to a four-service one.Das Projekt pflegt sein eigenes Docker-Compose-Setup unter jitsi/docker-jitsi-meet auf GitHub, und der richtige Weg ist, es zu klonen, statt es selbst von Hand zu schreiben — die Compose-Datei, env.example und das Layout der Config-Volumes werden untereinander und mit den Image-Releases synchron gehalten. Ist das dein erster Docker-Compose-Stack auf einem VPS, deckt Docker Compose auf einem kleinen VPS die Grundlagen ab, bevor es an einen mit vier Services geht.

The compose file and the .env generatorDie Compose-Datei und der .env-Generator

This assumes Docker Engine and the docker compose plugin are already installed from Docker's official apt repository, not the outdated docker.io package Ubuntu ships by default — Docker Compose on a small VPS walks through that install before it gets to any specific stack. From there, getting the Jitsi repo itself is short:Das hier setzt voraus, dass Docker Engine und das docker compose-Plugin bereits aus Dockers offiziellem apt-Repository installiert sind, nicht aus dem veralteten docker.io-Paket, das Ubuntu standardmäßig mitliefert — Docker Compose auf einem kleinen VPS geht diese Installation durch, bevor es zu einem konkreten Stack kommt. Von da aus ist das Holen des Jitsi-Repos selbst kurz:

sudo apt update
sudo apt install -y git
git clone https://github.com/jitsi/docker-jitsi-meet
cd docker-jitsi-meet
cp env.example .env

The repo ships a password generator that fills in every secret the four containers use to talk to each other — the Prosody and JVB auth credentials, the JVB component secret, and more — without you typing any of them by hand:Das Repo bringt einen Passwort-Generator mit, der jedes Secret befüllt, das die vier Container zur Kommunikation untereinander brauchen — die Prosody- und JVB-Auth-Credentials, das JVB-Component-Secret und mehr — ohne dass du auch nur eines davon von Hand eintippen musst:

./gen-passwords.sh

It writes into the .env you just copied and leaves any value you already set alone, so it is safe to re-run if you add a value later. Jitsi also expects a config directory outside the containers to persist Prosody's data, certificates and per-component config across upgrades:Es schreibt in die .env, die du gerade kopiert hast, und lässt jeden Wert, den du schon gesetzt hast, unangetastet — es ist also unbedenklich, es später erneut laufen zu lassen, wenn du einen Wert ergänzt. Jitsi erwartet außerdem ein Config-Verzeichnis außerhalb der Container, um Prosodys Daten, Zertifikate und Config pro Komponente über Upgrades hinweg zu persistieren:

mkdir -p ~/.jitsi-meet-cfg/{web/letsencrypt,web/crontabs,transcripts,prosody/config,prosody/prosody-plugins-custom,jicofo,jvb}

Set CONFIG=~/.jitsi-meet-cfg in .env to point at it — the repo's own env.example shows the same path as a default. The compose file itself pins all four images to one shared version variable, JITSI_IMAGE_VERSION (the default is the floating stable tag); check hub.docker.com/r/jitsi/web/tags (the same version string applies across the sibling jitsi/prosody, jitsi/jicofo and jitsi/jvb repos) for the current release and set it explicitly in .env before your first deploy, since this guide cannot know which one is current when you read it.Setze CONFIG=~/.jitsi-meet-cfg in der .env, damit sie darauf zeigt — das eigene env.example des Repos zeigt denselben Pfad als Standardwert. Die Compose-Datei selbst pinnt alle vier Images auf eine gemeinsame Versionsvariable, JITSI_IMAGE_VERSION (Standard ist der mitlaufende stable-Tag); prüfe hub.docker.com/r/jitsi/web/tags (derselbe Versionsstring gilt auch für die Schwester-Repos jitsi/prosody, jitsi/jicofo und jitsi/jvb) auf den aktuellen Release und setze ihn vor deinem ersten Deploy explizit in der .env, da diese Anleitung nicht wissen kann, welcher gerade aktuell ist, wenn du sie liest.

HTTPS: the bundled Let's Encrypt, or your own front proxyHTTPS: das eingebaute Let's Encrypt oder dein eigener vorgeschalteter Proxy

The simplest path, and the one the project writes its env.example around, is letting the web container handle TLS itself. Point your domain at the VPS first (point your domain at your service), then set:Der einfachste Weg, und der, um den das Projekt sein env.example herum baut, ist, den web-Container TLS selbst erledigen zu lassen. Lass deine Domain zuerst auf den VPS zeigen (deine Domain auf deinen Dienst zeigen lassen), dann setze:

PUBLIC_URL=https://meet.example.com
HTTP_PORT=80
HTTPS_PORT=443
ENABLE_LETSENCRYPT=1
LETSENCRYPT_DOMAIN=meet.example.com
LETSENCRYPT_EMAIL=you@example.com

With HTTP_PORT/HTTPS_PORT set to the standard ports, web's built-in nginx and certbot request and renew the certificate on their own — nothing else on the box can also bind 80 or 443 at the same time.Sind HTTP_PORT/HTTPS_PORT auf die Standardports gesetzt, fordern das eingebaute nginx und certbot von web das Zertifikat selbstständig an und erneuern es — nichts anderes auf der Maschine kann dann gleichzeitig 80 oder 443 belegen.

If you already run a reverse proxy on this VPS for other services, keep ENABLE_LETSENCRYPT=0, leave HTTP_PORT on a high, loopback-only port, and point your existing proxy at it instead, terminating TLS there. Either way PUBLIC_URL has to match the hostname people actually type, because Jitsi bakes it into the page it serves.Betreibst du auf diesem VPS bereits einen Reverse-Proxy für andere Dienste, lass ENABLE_LETSENCRYPT=0, belass HTTP_PORT auf einem hohen, nur lokal (loopback) erreichbaren Port, und zeig stattdessen deinen bestehenden Proxy darauf, der TLS dort terminiert. So oder so muss PUBLIC_URL zu dem Hostnamen passen, den Leute tatsächlich eintippen, weil Jitsi ihn fest in die ausgelieferte Seite einbaut.

The ports that matter: 443, and the one everyone forgetsDie Ports, auf die es ankommt: 443 und der, den alle vergessen

Two ports carry this whole application, and they behave nothing alike. A third, optional one is worth knowing about too:Zwei Ports tragen diese gesamte Anwendung, und sie verhalten sich überhaupt nicht gleich. Ein dritter, optionaler, lohnt sich ebenfalls zu kennen:

There is a second, unrelated NAT problem hiding inside the first one. Docker's own bridge network gives the jvb container a private address, and by default JVB would advertise that private address to remote participants as the place to send media — which nothing outside the box can reach. JVB_ADVERTISE_IPS in .env fixes this by telling JVB which externally-reachable IPv4 address to put in its ICE candidates instead:Im ersten Problem versteckt sich noch ein zweites, unabhängiges NAT-Problem. Dockers eigenes Bridge-Netzwerk gibt dem jvb-Container eine private Adresse, und standardmäßig würde JVB diese private Adresse entfernten Teilnehmern als Ziel für Medien ankündigen — die von außerhalb der Maschine niemand erreichen kann. JVB_ADVERTISE_IPS in der .env behebt das, indem es JVB mitteilt, welche von außen erreichbare IPv4-Adresse es stattdessen in seine ICE-Candidates einträgt:

JVB_ADVERTISE_IPS=203.0.113.10

That has to be the address the outside world actually uses to reach your VPS — with NAT IPv4 that is the shared provider address, not anything ip addr shows you on the machine itself.Das muss die Adresse sein, die die Außenwelt tatsächlich nutzt, um deinen VPS zu erreichen — bei NAT-IPv4 ist das die geteilte Provider-Adresse, nicht irgendetwas, das dir ip addr auf der Maschine selbst anzeigt.

Read this before you buy: NAT IPv4, port 443, and UDP 10000Lies das, bevor du kaufst: NAT-IPv4, Port 443 und UDP 10000

A NAT IPv4 plan hands out one shared address with a specific, fixed list of forwarded ports — not every port you ask for. Whether 443 is among them depends on the plan; never assume it, check the forwarded-port list before you point DNS anywhere. The same applies to 10000/UDP, and UDP is the one people forget to check because most of the rest of the internet runs on TCP.Ein NAT-IPv4-Tarif gibt eine geteilte Adresse mit einer bestimmten, festen Liste weitergeleiteter Ports aus — nicht jeden Port, den du anfragst. Ob 443 darunter ist, hängt vom Tarif ab; nimm es niemals an, sondern prüfe die Liste der weitergeleiteten Ports, bevor du DNS irgendwohin zeigen lässt. Dasselbe gilt für 10000/UDP, und UDP ist der Port, den zu prüfen die meisten vergessen, weil der Großteil des restlichen Internets über TCP läuft.

The two ports fail differently, too. If 443 is not forwarded, nothing works — you cannot even load the page. If 10000/UDP is not reachable, the page loads and the call appears to connect, but media has nowhere reliable to travel: participants see each other freeze, audio cuts in and out, or a call that was fine for two people falls apart the moment a third joins. There is no graceful fallback worth relying on here — treat UDP 10000 as a hard requirement and confirm it is forwarded before you finish the rest of this setup. NAT IPv4 vs a dedicated IP and NAT IPv4, ports and forwarding cover the difference between a NAT IPv4 plan and a dedicated address, and what our own plans actually forward — check it rather than guess.Auch die beiden Ports versagen unterschiedlich. Ist 443 nicht weitergeleitet, funktioniert nichts — du kannst nicht einmal die Seite laden. Ist 10000/UDP nicht erreichbar, lädt die Seite und der Call scheint zustande zu kommen, aber Medien haben keinen verlässlichen Weg: Teilnehmer sehen einander einfrieren, Audio setzt aus und wieder ein, oder ein Call, der zu zweit einwandfrei lief, bricht in dem Moment auseinander, in dem eine dritte Person beitritt. Es gibt hier keinen brauchbaren, elegant abfedernden Fallback — behandle UDP 10000 als harte Voraussetzung und bestätige, dass es weitergeleitet ist, bevor du den Rest dieses Setups fertigstellst. NAT IPv4 vs. dedizierte IP und NAT IPv4, Ports und Weiterleitung behandeln den Unterschied zwischen einem NAT-IPv4-Tarif und einer dedizierten Adresse, und was unsere eigenen Tarife tatsächlich weiterleiten — prüfe es, statt zu raten.

Authentication: so strangers cannot create roomsAuthentifizierung: damit Fremde keine Räume erstellen können

A fresh Jitsi Meet install lets anyone who knows (or guesses) a room name create it — there is no account system running by default. For anything reachable from the open internet, do the ordinary VPS hardening first (secure your VPS), then turn this off before you tell anyone the URL:Eine frische Jitsi-Meet-Installation lässt jeden, der einen Raumnamen kennt (oder errät), diesen Raum erstellen — standardmäßig läuft kein Account-System. Für alles, was aus dem offenen Internet erreichbar ist, mach zuerst die übliche VPS-Härtung (sichere deinen VPS ab), und schalte dies dann ab, bevor du irgendjemandem die URL nennst:

ENABLE_AUTH=1
ENABLE_GUESTS=1
AUTH_TYPE=internal

With this combination, only an authenticated user can start a new room; guests without an account can still join one that is already running, which is the shape most small teams actually want — you do not want every visitor needing a login, just every room needing a host who has one. Restart the stack after changing these, then register your own account against Prosody the way the project's own secure-domain guide documents, using the internal XMPP domain your .env sets (meet.jitsi unless you changed XMPP_DOMAIN), not your public hostname. Skip ENABLE_GUESTS entirely if you want every single participant, not just the room creator, to authenticate first.Mit dieser Kombination kann nur ein authentifizierter Nutzer einen neuen Raum starten; Gäste ohne Account können trotzdem einem bereits laufenden Raum beitreten — die Form, die die meisten kleinen Teams tatsächlich wollen: Du willst nicht, dass jeder Besucher einen Login braucht, nur dass jeder Raum einen Host hat, der einen hat. Starte den Stack nach diesen Änderungen neu und registriere dann deinen eigenen Account gegen Prosody so, wie es die eigene Secure-Domain-Anleitung des Projekts beschreibt, unter Verwendung der internen XMPP-Domain, die deine .env setzt (meet.jitsi, sofern du XMPP_DOMAIN nicht geändert hast), nicht deinem öffentlichen Hostnamen. Lass ENABLE_GUESTS ganz weg, wenn jeder einzelne Teilnehmer, nicht nur der Raum-Ersteller, sich zuerst authentifizieren soll.

Sizing this honestlyEhrlich dimensioniert

A 1:1 call or a handful of people on a video call is genuinely light — JVB is forwarding a few RTP streams, and the web, Prosody and Jicofo containers idle. What scales is participant count multiplied by bitrate: each additional person is another set of streams JVB has to receive, manage simulcast layers for, and forward to everyone else, and that is CPU and bandwidth work regardless of resolution settings. No tier here needs a GPU for this, because JVB forwards media rather than decoding and re-encoding it.Ein 1:1-Call oder eine Handvoll Leute in einem Videocall ist wirklich leichtgewichtig — JVB leitet ein paar RTP-Streams weiter, und die Container web, Prosody und Jicofo laufen im Leerlauf. Was skaliert, ist die Teilnehmerzahl multipliziert mit der Bitrate: Jede zusätzliche Person ist ein weiterer Satz an Streams, die JVB empfangen, für die es Simulcast-Layer verwalten und die es an alle anderen weiterleiten muss, und das ist CPU- und Bandbreitenarbeit, unabhängig von den Auflösungseinstellungen. Keine Stufe hier braucht dafür eine GPU, weil JVB Medien weiterleitet, statt sie zu dekodieren und neu zu kodieren.

Standard (2 vCPU / 4 GiB / 80 GB) comfortably runs the full four-container stack — web, Prosody, Jicofo and JVB together — for occasional calls of a handful of people, with headroom for the OS and Docker itself. Pro (4 vCPU / 8 GiB / 120 GB) is the tier to plan around once calls regularly run 10 or more participants, or several smaller calls overlap on the same box — do not treat any specific participant count as a promise from Jitsi's own numbers; it depends on video quality settings and how many cameras are actually on, so watch CPU and bandwidth on your own box under your own usage rather than trust a number from a blog post.Standard (2 vCPU / 4 GiB / 80 GB) fährt den vollen Vier-Container-Stack — web, Prosody, Jicofo und JVB zusammen — komfortabel für gelegentliche Calls mit einer Handvoll Leuten, mit Luft für das Betriebssystem und Docker selbst. Pro (4 vCPU / 8 GiB / 120 GB) ist die Stufe, mit der du planen solltest, sobald Calls regelmäßig mit 10 oder mehr Teilnehmern laufen oder sich mehrere kleinere Calls auf derselben Maschine überlappen — behandle keine bestimmte Teilnehmerzahl als Versprechen aus Jitsis eigenen Angaben; es hängt von den Videoqualitäts-Einstellungen und davon ab, wie viele Kameras tatsächlich an sind, also beobachte CPU und Bandbreite auf deiner eigenen Maschine unter deiner eigenen Nutzung, statt einer Zahl aus einem Blogpost zu vertrauen.

The thing that bites later: leaving the image tag on stableWas dich später beißt: den Image-Tag auf stable zu lassen

The web, prosody, jicofo and jvb images are released together as one version each cycle, and the compose file ties all four to that single JITSI_IMAGE_VERSION variable rather than four tags you set one by one — a plain docker compose pull always moves all four together, never just one. The trap is leaving the variable on its default, the floating stable tag: every pull then silently picks up whatever the maintainers currently label stable, with no record of which build you were actually running before, and no way to roll back to a specific version if the new one misbehaves. The other way to break the guarantee the project actually gives you — that these four images were built and tested as a set — is hand-pinning one service's image: line directly in the compose file instead of changing the shared variable; do not do that. Pin JITSI_IMAGE_VERSION to a specific dated release instead of stable, then upgrade deliberately: docker compose pull, docker compose up -d, and check docker compose logs -f jicofo jvb for a minute afterward rather than assuming a clean restart means a clean upgrade.Die Images web, prosody, jicofo und jvb werden pro Zyklus gemeinsam als eine Version veröffentlicht, und die Compose-Datei bindet alle vier an diese eine gemeinsame Variable JITSI_IMAGE_VERSION, statt an vier Tags, die du einzeln setzt — ein einfaches docker compose pull bewegt immer alle vier zusammen, nie nur eins. Die Falle ist, die Variable auf ihrem Standard zu lassen, dem mitlaufenden stable-Tag: Jeder Pull übernimmt dann stillschweigend, was die Maintainer gerade als stable kennzeichnen, ohne festzuhalten, welchen Build du vorher tatsächlich gefahren hast, und ohne Möglichkeit, auf eine bestimmte Version zurückzurollen, wenn sich die neue schlecht verhält. Die andere Art, die Garantie zu brechen, die das Projekt tatsächlich gibt — dass diese vier Images als Set gebaut und getestet wurden —, ist, die image:-Zeile eines Services direkt in der Compose-Datei von Hand zu pinnen, statt die gemeinsame Variable zu ändern; tu das nicht. Pinne JITSI_IMAGE_VERSION statt auf stable auf ein konkretes, datiertes Release, und upgrade dann bewusst: docker compose pull, docker compose up -d, und prüfe danach eine Minute lang docker compose logs -f jicofo jvb, statt anzunehmen, dass ein sauberer Neustart auch ein sauberes Upgrade bedeutet.

On overnight.hostBei overnight.host

Full disclosure: this is what we sell. A Standard (2 vCPU / 4 GiB / 80 GB) is a comfortable floor for Jitsi's four containers — web, Prosody, Jicofo and JVB — running 1:1 and small-group calls; move to Pro (4 vCPU / 8 GiB / 120 GB) once calls regularly run 10 or more participants, since the videobridge's cost scales with participants and bitrate, not with the app being installed.Zur vollen Transparenz: Das ist, was wir verkaufen. Ein Standard (2 vCPU / 4 GiB / 80 GB) ist eine komfortable Untergrenze für Jitsis vier Container — web, Prosody, Jicofo und JVB —, die 1:1-Calls und Calls in kleinen Gruppen ausführen; wechsle zu Pro (4 vCPU / 8 GiB / 120 GB), sobald Calls regelmäßig mit 10 oder mehr Teilnehmern laufen, da die Kosten der Videobridge mit Teilnehmerzahl und Bitrate skalieren, nicht mit der Installation der App.

Linux KVM VPS — EUR 4.99 to EUR 59.99 a month, on our own single-tenant bare metal in Dallas, TX and Charlotte, NC. Full hardware virtualisation (KVM), your own kernel, full root. Six tiers, vps-starter to vps-ultra. Starter is 1 vCPU, 1 GiB RAM, 25 GB disk.Linux-KVM-VPS — 4,99 bis 59,99 EUR im Monat, auf unserer eigenen Single-Tenant-Bare-Metal-Hardware in Dallas, TX und Charlotte, NC. Vollständige Hardware-Virtualisierung (KVM), eigener Kernel, volles Root. Sechs Tarife, vps-starter bis vps-ultra. Starter hat 1 vCPU, 1 GiB RAM, 25 GB Speicher.

You order in the shop, pay by card (Stripe) or SEPA bank transfer, and your login details are e-mailed to you once the service is set up. Support is e-mail, run by one person, with no guaranteed response time. All prices are final totals under the German small-business rule (§19 UStG); no VAT is added or shown.Du bestellst im Shop, zahlst per Karte (Stripe) oder SEPA-Überweisung, und deine Zugangsdaten werden dir per E-Mail zugeschickt, sobald der Dienst eingerichtet ist. Support läuft per E-Mail, von einer einzelnen Person betrieben, ohne garantierte Reaktionszeit. Alle Preise sind Endpreise. Gemäß § 19 UStG wird keine Umsatzsteuer ausgewiesen.

Order vps-standard → · Linux KVM VPS overviewvps-standard bestellen → · Übersicht Linux-KVM-VPS

Written by the person who runs overnight.host: a small, honest hosting company on dedicated bare metal — Linux VPS, game servers, web hosting. Live status at up.overnight.host.Geschrieben von der Person, die overnight.host betreibt: ein kleines, ehrliches Hosting-Unternehmen auf dedizierter Bare-Metal-Hardware — Linux-VPS, Gameserver, Webhosting. Live-Status unter up.overnight.host.

Technical guidance is informational. Plans, specifications and final prices are listed in the shop and can be ordered directly; VPS, game server, web hosting, one-click app and automation plans are provisioned automatically after payment. Custom configurations are still arranged by e-mail.Technische Hinweise dienen der Information. Pläne, Spezifikationen und Endpreise stehen im Shop und können direkt bestellt werden; VPS-, Gameserver-, Webhosting-, One-Click-App- und Automatisierungs-Pläne werden nach der Zahlung automatisch bereitgestellt. Sonderkonfigurationen werden weiterhin per E-Mail vereinbart.

FAQFAQ

Do I need a dedicated IPv4 to run Jitsi Meet?Brauche ich eine dedizierte IPv4, um Jitsi Meet zu betreiben?

Not specifically for Jitsi. What you need is 443/TCP and 10000/UDP both reachable from outside, and JVB_ADVERTISE_IPS set to whichever address the outside world actually uses to reach you. A NAT IPv4 plan can satisfy this if both ports happen to be in its forwarded list; a dedicated IPv4 removes the question entirely, since every port is yours. On our plans a dedicated address is arranged by e-mail, not a checkout option.Nicht speziell für Jitsi. Was du brauchst, ist, dass 443/TCP und 10000/UDP beide von außen erreichbar sind, und dass JVB_ADVERTISE_IPS auf die Adresse gesetzt ist, die die Außenwelt tatsächlich nutzt, um dich zu erreichen. Ein NAT-IPv4-Tarif kann das erfüllen, wenn beide Ports zufällig in seiner Liste weitergeleiteter Ports sind; eine dedizierte IPv4 erübrigt die Frage vollständig, weil dir dann jeder Port gehört. Bei unseren Tarifen wird eine dedizierte Adresse per E-Mail vereinbart, nicht als Checkout-Option.

What actually happens if UDP 10000 is blocked?Was passiert tatsächlich, wenn UDP 10000 blockiert ist?

The page loads and the call appears to start, because that part runs over 443. Media does not have a working path, so participants see frozen video, dropped audio, or calls that seem fine one-on-one and fall apart with a third person. This is not a subtle degradation — treat it as a hard failure to fix before you trust the deployment with anyone else.Die Seite lädt und der Call scheint zu starten, weil dieser Teil über 443 läuft. Medien haben keinen funktionierenden Weg, sodass Teilnehmer eingefrorenes Video, aussetzendes Audio sehen oder Calls, die zu zweit in Ordnung wirken und mit einer dritten Person auseinanderfallen. Das ist keine subtile Verschlechterung — behandle es als harten Fehler, den du behebst, bevor du das Deployment irgendjemand anderem anvertraust.

Why can anyone create a room by default, and is that actually a problem?Warum kann standardmäßig jeder einen Raum erstellen, und ist das tatsächlich ein Problem?

Because Jitsi's default install has no account system running, so any name typed into the URL becomes a room. On a server only your team knows the address of, this is low risk in practice; on anything indexed, guessable, or shared beyond a small group, set ENABLE_AUTH=1 and AUTH_TYPE=internal before you rely on it, and decide separately whether guests should be able to join without an account of their own.Weil bei Jitsis Standardinstallation kein Account-System läuft, sodass jeder in die URL getippte Name zu einem Raum wird. Auf einem Server, dessen Adresse nur dein Team kennt, ist das in der Praxis geringes Risiko; bei allem, was indexiert, erratbar oder über eine kleine Gruppe hinaus geteilt ist, setze ENABLE_AUTH=1 und AUTH_TYPE=internal, bevor du dich darauf verlässt, und entscheide separat, ob Gäste ohne eigenen Account beitreten können sollen.

Do I need a GPU for decent call quality?Brauche ich eine GPU für ordentliche Anrufqualität?

No. JVB is a selective forwarding unit — it relays each participant's RTP stream to everyone else rather than decoding and re-encoding video, which is the work a GPU would actually help with. The cost that does scale is CPU and bandwidth per participant and per bitrate, which is a vCPU and network question, not a graphics one.Nein. JVB ist eine Selective-Forwarding-Unit — sie leitet den RTP-Stream jedes Teilnehmers an alle anderen weiter, statt Video zu dekodieren und neu zu kodieren, was die Arbeit wäre, bei der eine GPU tatsächlich helfen würde. Was skaliert, sind CPU und Bandbreite pro Teilnehmer und pro Bitrate — eine Frage von vCPU und Netzwerk, keine der Grafik.

Can I record calls or dial in over SIP?Kann ich Calls aufzeichnen oder mich über SIP einwählen?

Not with the four containers this guide covers. Recording and streaming go through a separate container, jibri, and phone/SIP dial-in through jigasi — both are real parts of the same project but add meaningfully more moving parts (a headless browser for jibri, a SIP trunk for jigasi) and are worth treating as a second project once the core stack is solid, not bundled into your first deploy.Nicht mit den vier Containern, die diese Anleitung behandelt. Aufzeichnung und Streaming laufen über einen separaten Container, jibri, und Telefon-/SIP-Einwahl über jigasi — beide sind echte Teile desselben Projekts, bringen aber spürbar mehr bewegliche Teile mit (ein Headless-Browser für jibri, ein SIP-Trunk für jigasi) und lohnen sich als zweites Projekt, sobald der Kern-Stack steht, statt in dein erstes Deployment gepackt zu werden.

Ready to order?Bereit zu bestellen?

Prices are final totals; no VAT is shown (§19 UStG). Need something the shop does not list? Email us for a written offer.Alle Preise sind Endpreise ohne ausgewiesene USt. (§19 UStG). Du brauchst etwas, das nicht im Shop steht? Schreib uns für ein schriftliches Angebot.

Order now →Jetzt bestellen → Request a custom configIndividuelle Konfiguration anfragen