Lesson 23 / 26
Deployment Security Checks
check --deploy.
Settings that must change for production
python manage.py check --deploy reviews settings for production: DEBUG must be False, ALLOWED_HOSTS set, a strong SECRET_KEY from the environment, HTTPS redirects and HSTS, secure session and CSRF cookies. Django also protects against CSRF, XSS (auto-escaping templates), SQL injection (parameterised ORM queries) and clickjacking by default; do not disable these protections without a strong reason. For FastAPI, configure CORS, HTTPS, and security headers explicitly.
Warnings for development settings, run
I ran this with Django 6.1.1 and Python 3.12 in a demo project (shopsite with a catalog app) using SQLite. Run on the freshly generated settings, the check reports 8 issues; the seven security warnings are shown, each trimmed to its first sentence.
python manage.py check --deploy
Output:
(security.W004) You have not set a value for the SECURE_HSTS_SECONDS setting. (security.W008) Your SECURE_SSL_REDIRECT setting is not set to True. (security.W009) Your SECRET_KEY has less than 50 characters, less than 5 unique characters, or it's prefixed with 'django-insecure-' indicating that it was generated automatically by Django. (security.W012) SESSION_COOKIE_SECURE is not set to True. (security.W016) You have 'django.middleware.csrf.CsrfViewMiddleware' in your MIDDLEWARE, but you have not set CSRF_COOKIE_SECURE to True. (security.W018) You should not have DEBUG set to True in deployment. (security.W020) ALLOWED_HOSTS must not be empty in deployment. System check identified 8 issues (0 silenced).
Run check --deploy in CI
Running it against production settings in CI catches insecure configuration before release.
Quick check: Which setting must be False in production?
- DEBUG
- USE_TZ
- APPEND_SLASH
- INSTALLED_APPS
Answer
DEBUG — Debug pages leak sensitive information.