Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (latest, 2026-09-14), podman (latest, 2026-09-14); Proxmox VM: docker (latest, 2026-09-14), podman (latest, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
prosody:
image: prosody/prosody:latest
container_name: prosody
restart: unless-stopped
networks:
- njorddeploy_net
ports:
- "5222:5222"
- "5269:5269"
volumes:
- prosody_config:/etc/prosody
- prosody_data:/var/lib/prosody
environment:
- DOMAIN=localhost
- ADMIN_USER=admin
- ADMIN_PASS="ChangeMeSecurePassword123!"
- MUC_PREFIX=conference
- UPLOAD_PREFIX=upload
volumes:
prosody_config:
name: njorddeploy-prosody-config
prosody_data:
name: njorddeploy-prosody-data
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
XMPP_DOMAIN |
*None* |
The main domain name for your Prosody server (e.g., example.com) |
XMPP_ADMIN_USER |
admin |
The JID for the Admin User. |
XMPP_ADMIN_PASSWORD |
*None* |
The password for the administrator account. This will be securely stored in the configuration. |
XMPP_MUC_PREFIX |
conference |
The subdomain used for group chats. This value needs to be added as an A or CNAME record for your domain. |
XMPP_UPLOAD_PREFIX |
upload |
The subdomain used for file sharing. This value needs to be added as an A or CNAME record for your domain. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.