Files
dealerhub/backend/config/settings/prod.py
T

57 lines
1.4 KiB
Python
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
"""生产环境配置:PostgreSQL + 严格安全 + Granian。"""
import os
from .base import * # noqa
from .base import env
DEBUG = False
ALLOWED_HOSTS = env.list("DJANGO_ALLOWED_HOSTS", default=["*"])
# PostgreSQL(用 DATABASE_URL 环境变量)
DATABASES = {
"default": env.db(
"DATABASE_URL",
default="postgres://dealerhub:dealerhub@pg-main:5432/dealerhub",
)
}
# 异步连接池
DATABASES["default"]["OPTIONS"] = {
"pool": {"min_size": 2, "max_size": 10, "timeout": 10},
}
# Redis
CACHES = {
"default": {
"BACKEND": env(
"CACHE_BACKEND",
default="django.core.cache.backends.locmem.LocMemCache",
),
"LOCATION": env("CACHE_LOCATION", default="dealerhub-cache"),
}
}
# 安全
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True
SECURE_HSTS_SECONDS = 60 * 60 * 24 * 30 # 30 天
SECURE_HSTS_INCLUDE_SUBDOMAINS = True
SECURE_HSTS_PRELOAD = True
SECURE_CONTENT_TYPE_NOSNIFF = True
SECURE_REFERRER_POLICY = "same-origin"
X_FRAME_OPTIONS = "DENY"
# 生产不打印 SQL(prod 不继承 dev 的配置,避免 KeyError)
LOGGING.setdefault("loggers", {})
LOGGING["loggers"].setdefault("django", {
"handlers": ["console"],
"level": "INFO",
"propagate": False,
})
LOGGING["loggers"].setdefault("django.db.backends", {
"handlers": ["console"],
"level": "WARNING",
"propagate": False,
})