# Recommended Settings and Security Considerations for Production Deployment in Mobile Audit

> Deploy Mobile Audit to production securely. Learn recommended settings like ENV=PROD and DEBUG=0, plus PostgreSQL, Nginx TLS, secure cookies, and hardened HTTP headers for robust security.

- Repository: [Mónica Pastor/mobileaudit](https://github.com/mpast/mobileaudit)
- Tags: best-practices
- Published: 2026-03-07

---

**Deploy Mobile Audit in production by setting `ENV=PROD`, `DEBUG=0`, and a strong `SECRET_KEY` in your `.env` file, then launch the stack using [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) with PostgreSQL and Nginx TLS termination to enforce encryption, secure cookies, and hardened HTTP headers.**

Mobile Audit is a Django-based framework for automated Android security scanning. When moving from local development to production, the default configuration must be hardened to prevent information disclosure, session hijacking, and container escape vulnerabilities. The repository includes a production-ready configuration that isolates the application behind Nginx, enforces HTTPS-only traffic, and eliminates insecure defaults.

## Environment Hardening and Django Settings

### Production Mode Detection

The application uses an environment flag to separate development from production configurations. In [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) (lines 72-88), production-specific security controls are wrapped inside a conditional block:

```python
if env("ENV") == "PROD":
    # Production-only security settings

    DEBUG = 0
    # ... additional hardening

```

Set `ENV=PROD` in your environment file to guarantee that insecure developer conveniences—such as the Django debug page and SQLite database—are never active in live environments.

### Critical Security Variables

The following variables in [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) (lines 62-68) must be explicitly configured for production:

- **`SECRET_KEY`**: Must be a cryptographically strong random value passed via the environment. Never commit the default placeholder to source control.
- **`DEBUG`**: Must be set to `0` (off). Debug mode leaks stack traces, environment variables, and database credentials in error responses.
- **`DJANGO_ALLOWED_HOSTS`**: Populate with your exact domain (e.g., `myaudit.example.com`) to prevent HTTP Host header attacks.
- **`CSRF_TRUSTED_ORIGINS`**: List trusted HTTPS origins (e.g., `https://myaudit.example.com`) to enforce proper CSRF validation.

### Secure Session Management

In [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) (lines 84-88), production deployments must enable secure cookie flags:

```python
SESSION_COOKIE_SECURE = env("SESSION_COOKIE_SECURE", True)  # HTTPS only

SESSION_COOKIE_HTTPONLY = True                              # No JavaScript access

SESSION_EXPIRE_AT_BROWSER_CLOSE = True                      # Limit exposure

```

Setting `SESSION_COOKIE_SECURE` to `True` ensures session tokens are transmitted only over TLS, mitigating session hijacking via man-in-the-middle attacks.

## Database and Message Broker Configuration

### PostgreSQL Backend

Production environments must use the PostgreSQL container defined in [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) (lines 4-11) rather than SQLite. The production compose file configures the database service with persistent storage and internal networking:

```yaml
db:
  image: postgres:13-alpine
  environment:
    - POSTGRES_DB=audit
    - POSTGRES_USER=postgres
    - POSTGRES_PASSWORD=postgres

```

Configure the Django database engine in your `.env` file:

```text
SQL_ENGINE=django.db.backends.postgresql
SQL_HOST=db
SQL_PORT=5432

```

### RabbitMQ Authentication

The Celery task broker defaults to RabbitMQ. In [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) (lines 86-92), override the default guest credentials by setting `CELERY_BROKER_URL` or the component variables in `.env`:

```text
RABBITMQ_DEFAULT_USER=mobileaudit
RABBITMQ_DEFAULT_PASS=<strong-random-password>

```

This prevents unauthenticated task injection into the message queue.

## HTTPS Enforcement and TLS Configuration

### Nginx TLS Termination

The repository provides [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf) for production TLS termination. Key security controls include:

- **Protocol restriction**: `ssl_protocols TLSv1.2 TLSv1.3` (lines 13-15) disables vulnerable SSLv3 and TLSv1.0/1.1.
- **Strong cipher suites**: Enforces modern ECDHE cipher suites with forward secrecy.
- **Security headers**: Adds `Strict-Transport-Security`, `X-Frame-Options DENY`, and `X-Content-Type-Options nosniff` (lines 17-20).

Example Nginx server block:

```nginx
server {
    listen 443 ssl;
    ssl_certificate /etc/nginx/ssl/nginx.crt;
    ssl_certificate_key /etc/nginx/ssl/nginx.key;
    ssl_protocols TLSv1.2 TLSv1.3;
    add_header Strict-Transport-Security "max-age=63072000; includeSubdomains";
    add_header X-Frame-Options DENY;
}

```

### HSTS Preload

Enable `SECURE_HSTS_PRELOAD` in your `.env` file (mapped in [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) lines 86-88) if you intend to submit the domain to browser preload lists. This guarantees browsers always use HTTPS for your domain before ever connecting.

## Container Isolation and Docker Security

### Production Compose Profile

The [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) (lines 16-33) enforces container isolation by:

1. **Removing development port mappings**: The web application container does not expose ports directly to the host.
2. **Binding Nginx to port 443**: Only the reverse proxy is externally accessible, preventing direct access to the Django development server.
3. **Internal networking**: Services communicate via internal Docker networks, minimizing the attack surface.

### Static and Media File Handling

Nginx serves static and media files directly (lines 35-41 in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf)), ensuring Django never handles file serving in production:

```nginx
location /static/ {
    alias /usr/src/app/staticfiles/;
}

```

This reduces load on the application server and eliminates directory traversal risks associated with Django's development file server.

## Practical Deployment Checklist

Follow these steps to deploy a hardened production instance:

1. **Create the environment file** from the provided template:

```text

# .env

ENV=PROD
DEBUG=0
SECRET_KEY=3f1e9c7b2d4a8e9f7c5b6a1d0e2f4c7a9d6b3e1f0a2c4d5e6f7a8b9c0d1e2f3
DJANGO_ALLOWED_HOSTS=myaudit.example.com
CSRF_TRUSTED_ORIGINS=https://myaudit.example.com
SESSION_COOKIE_SECURE=True
SECURE_HSTS_PRELOAD=True
SQL_ENGINE=django.db.backends.postgresql
RABBITMQ_DEFAULT_USER=mobileaudit
RABBITMQ_DEFAULT_PASS=SuperSecretPass123

```

2. **Launch the production stack**:

```bash
docker compose -f docker-compose.prod.yaml up -d --build

```

3. **Install TLS certificates** by placing `nginx.crt` and `nginx.key` in the `nginx/ssl/` directory before starting the containers.

4. **Verify security headers** with curl:

```bash
curl -I -s https://myaudit.example.com | grep -i "strict-transport"

```

5. **Monitor logs** by shipping `logs/debug.log` (configured in [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) lines 94-108) to a centralized logging system such as ELK or Grafana Loki.

## Summary

- **Set `ENV=PROD`** in `.env` to activate production-only security blocks in [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py).
- **Disable `DEBUG`** and use **PostgreSQL** via [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) instead of SQLite.
- **Enforce HTTPS** by configuring Nginx with TLS 1.2/1.3, secure cipher suites, and `SESSION_COOKIE_SECURE=True`.
- **Isolate containers** using the production compose file, which removes direct port exposure and routes traffic only through the Nginx reverse proxy.
- **Protect secrets** by generating strong random values for `SECRET_KEY` and RabbitMQ credentials, storing them exclusively in `.env` (never committed to git).

## Frequently Asked Questions

### What is the minimum `.env` configuration required for production?

At minimum, you must set `ENV=PROD`, `DEBUG=0`, a strong `SECRET_KEY`, and `DJANGO_ALLOWED_HOSTS` containing your domain. Additionally, configure PostgreSQL connection variables (`SQL_ENGINE`, `SQL_HOST`, `SQL_PORT`) and RabbitMQ credentials (`RABBITMQ_DEFAULT_USER`, `RABBITMQ_DEFAULT_PASS`) to replace default development values.

### How do I enable HTTPS for Mobile Audit?

Place your TLS certificate and private key at `nginx/ssl/nginx.crt` and `nginx/ssl/nginx.key`, then ensure `SESSION_COOKIE_SECURE=True` is set in your `.env` file. The [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) automatically configures Nginx to listen on port 443 with the security headers defined in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf).

### Can I use SQLite in production?

No. The production configuration in [`app/config/settings.py`](https://github.com/mpast/mobileaudit/blob/main/app/config/settings.py) (lines 72-88) expects PostgreSQL when `ENV=PROD` is set. SQLite lacks concurrency controls, authentication mechanisms, and durability features required for multi-user production workloads. Use the PostgreSQL service defined in [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) (lines 4-11).

### How are static files handled in production?

Nginx serves static and media files directly via the `/static/` and `/media/` location blocks in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf) (lines 35-41). This prevents Django from serving files, reducing CPU load and eliminating path traversal vulnerabilities associated with the development server.