# Deployment Security Checks — Django / FastAPI

Source: https://www.skillbyai.com/en/django-fastapi/q-deploy-check

> check --deploy.

## Settings that must change for production

`python manage.py check --deploy` reviews settings for production: DEBUG must be False, ALLOWED_HOSTS set, a strong SECRET_KEY from the environment, HTTPS redirects and HSTS, secure session and CSRF cookies. Django also protects against CSRF, XSS (auto-escaping templates), SQL injection (parameterised ORM queries) and clickjacking by default; do not disable these protections without a strong reason. For FastAPI, configure CORS, HTTPS, and security headers explicitly.

## Warnings for development settings, run

I ran this with Django 6.1.1 and Python 3.12 in a demo project (shopsite with a catalog app) using SQLite. Run on the freshly generated settings, the check reports 8 issues; the seven security warnings are shown, each trimmed to its first sentence.

```bash
python manage.py check --deploy
```

Output:

```
(security.W004) You have not set a value for the SECURE_HSTS_SECONDS setting.
(security.W008) Your SECURE_SSL_REDIRECT setting is not set to True.
(security.W009) Your SECRET_KEY has less than 50 characters, less than 5 unique characters, or it's prefixed with 'django-insecure-' indicating that it was generated automatically by Django.
(security.W012) SESSION_COOKIE_SECURE is not set to True.
(security.W016) You have 'django.middleware.csrf.CsrfViewMiddleware' in your MIDDLEWARE, but you have not set CSRF_COOKIE_SECURE to True.
(security.W018) You should not have DEBUG set to True in deployment.
(security.W020) ALLOWED_HOSTS must not be empty in deployment.
System check identified 8 issues (0 silenced).
```

## Run check --deploy in CI

Running it against production settings in CI catches insecure configuration before release.

**Quiz:** Which setting must be False in production?

- [x] DEBUG
- [ ] USE_TZ
- [ ] APPEND_SLASH
- [ ] INSTALLED_APPS

*Answer:* DEBUG. Debug pages leak sensitive information.
