Django production checklist
Settings your project needs to run well in a container behind HTTPS. None of this is specific to DjangoCloud, but a missing setting here is the most common reason a first deploy builds fine and then shows an error page.
Read configuration from the environment
Section titled “Read configuration from the environment”Set these as environment variables and read them in settings.py:
import os
SECRET_KEY = os.environ["DJANGO_SECRET_KEY"]DEBUG = os.environ.get("DEBUG", "False") == "True"ALLOWED_HOSTS = os.environ.get("ALLOWED_HOSTS", "").split(",")collectstatic runs during the build with a throwaway secret key, so avoid code that fails on import when a real secret is missing. Use os.environ.get with a safe default for anything the build touches.
Hosts and HTTPS
Section titled “Hosts and HTTPS”Your app is served over HTTPS by a load balancer in front of the container. The container itself receives plain HTTP, so tell Django to trust the forwarded protocol:
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")CSRF_TRUSTED_ORIGINS = ["https://myapp.example.com"]Without SECURE_PROXY_SSL_HEADER, Django thinks every request is insecure and login or CSRF checks can fail. Put your public URL in ALLOWED_HOSTS and CSRF_TRUSTED_ORIGINS.
Static files
Section titled “Static files”Static files are collected during the build and baked into the image. Serve them from your app with WhiteNoise, or from object storage:
MIDDLEWARE.insert(1, "whitenoise.middleware.WhiteNoiseMiddleware")STATIC_ROOT = BASE_DIR / "staticfiles"Database
Section titled “Database”SQLite is lost on every deploy because the container is ephemeral. Use Postgres and read the connection string from the environment. See Databases.
Health check
Section titled “Health check”The platform requests healthcheck_path (default /) and expects a successful response before it switches traffic. A page that redirects to a login screen, or needs a database that isn’t reachable yet, will keep releases from becoming active. Point it at a lightweight view if needed.
Quick checklist
Section titled “Quick checklist”-
DEBUGis off in production -
SECRET_KEYcomes from the environment -
ALLOWED_HOSTSandCSRF_TRUSTED_ORIGINSinclude your public URL -
SECURE_PROXY_SSL_HEADERis set - Static files are served by WhiteNoise or object storage
- Uploads go to object storage, not local disk
- The database is Postgres, not SQLite
