Recommended Settings and Security Considerations for Production Deployment in Mobile Audit
Deploy Mobile Audit in production by setting ENV=PROD, DEBUG=0, and a strong SECRET_KEY in your .env file, then launch the stack using docker-compose.prod.yaml with PostgreSQL and Nginx TLS termination to enforce encryption, secure cookies, and hardened HTTP headers.
Mobile Audit is a Django-based framework for automated Android security scanning. When moving from local development to production, the default configuration must be hardened to prevent information disclosure, session hijacking, and container escape vulnerabilities. The repository includes a production-ready configuration that isolates the application behind Nginx, enforces HTTPS-only traffic, and eliminates insecure defaults.
Environment Hardening and Django Settings
Production Mode Detection
The application uses an environment flag to separate development from production configurations. In app/config/settings.py (lines 72-88), production-specific security controls are wrapped inside a conditional block:
if env("ENV") == "PROD":
# Production-only security settings
DEBUG = 0
# ... additional hardening
Set ENV=PROD in your environment file to guarantee that insecure developer conveniences—such as the Django debug page and SQLite database—are never active in live environments.
Critical Security Variables
The following variables in app/config/settings.py (lines 62-68) must be explicitly configured for production:
SECRET_KEY: Must be a cryptographically strong random value passed via the environment. Never commit the default placeholder to source control.DEBUG: Must be set to0(off). Debug mode leaks stack traces, environment variables, and database credentials in error responses.DJANGO_ALLOWED_HOSTS: Populate with your exact domain (e.g.,myaudit.example.com) to prevent HTTP Host header attacks.CSRF_TRUSTED_ORIGINS: List trusted HTTPS origins (e.g.,https://myaudit.example.com) to enforce proper CSRF validation.
Secure Session Management
In app/config/settings.py (lines 84-88), production deployments must enable secure cookie flags:
SESSION_COOKIE_SECURE = env("SESSION_COOKIE_SECURE", True) # HTTPS only
SESSION_COOKIE_HTTPONLY = True # No JavaScript access
SESSION_EXPIRE_AT_BROWSER_CLOSE = True # Limit exposure
Setting SESSION_COOKIE_SECURE to True ensures session tokens are transmitted only over TLS, mitigating session hijacking via man-in-the-middle attacks.
Database and Message Broker Configuration
PostgreSQL Backend
Production environments must use the PostgreSQL container defined in docker-compose.prod.yaml (lines 4-11) rather than SQLite. The production compose file configures the database service with persistent storage and internal networking:
db:
image: postgres:13-alpine
environment:
- POSTGRES_DB=audit
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=postgres
Configure the Django database engine in your .env file:
SQL_ENGINE=django.db.backends.postgresql
SQL_HOST=db
SQL_PORT=5432
RabbitMQ Authentication
The Celery task broker defaults to RabbitMQ. In app/config/settings.py (lines 86-92), override the default guest credentials by setting CELERY_BROKER_URL or the component variables in .env:
RABBITMQ_DEFAULT_USER=mobileaudit
RABBITMQ_DEFAULT_PASS=<strong-random-password>
This prevents unauthenticated task injection into the message queue.
HTTPS Enforcement and TLS Configuration
Nginx TLS Termination
The repository provides nginx/app_tls.conf for production TLS termination. Key security controls include:
- Protocol restriction:
ssl_protocols TLSv1.2 TLSv1.3(lines 13-15) disables vulnerable SSLv3 and TLSv1.0/1.1. - Strong cipher suites: Enforces modern ECDHE cipher suites with forward secrecy.
- Security headers: Adds
Strict-Transport-Security,X-Frame-Options DENY, andX-Content-Type-Options nosniff(lines 17-20).
Example Nginx server block:
server {
listen 443 ssl;
ssl_certificate /etc/nginx/ssl/nginx.crt;
ssl_certificate_key /etc/nginx/ssl/nginx.key;
ssl_protocols TLSv1.2 TLSv1.3;
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains";
add_header X-Frame-Options DENY;
}
HSTS Preload
Enable SECURE_HSTS_PRELOAD in your .env file (mapped in app/config/settings.py lines 86-88) if you intend to submit the domain to browser preload lists. This guarantees browsers always use HTTPS for your domain before ever connecting.
Container Isolation and Docker Security
Production Compose Profile
The docker-compose.prod.yaml (lines 16-33) enforces container isolation by:
- Removing development port mappings: The web application container does not expose ports directly to the host.
- Binding Nginx to port 443: Only the reverse proxy is externally accessible, preventing direct access to the Django development server.
- Internal networking: Services communicate via internal Docker networks, minimizing the attack surface.
Static and Media File Handling
Nginx serves static and media files directly (lines 35-41 in nginx/app_tls.conf), ensuring Django never handles file serving in production:
location /static/ {
alias /usr/src/app/staticfiles/;
}
This reduces load on the application server and eliminates directory traversal risks associated with Django's development file server.
Practical Deployment Checklist
Follow these steps to deploy a hardened production instance:
- Create the environment file from the provided template:
# .env
ENV=PROD
DEBUG=0
SECRET_KEY=3f1e9c7b2d4a8e9f7c5b6a1d0e2f4c7a9d6b3e1f0a2c4d5e6f7a8b9c0d1e2f3
DJANGO_ALLOWED_HOSTS=myaudit.example.com
CSRF_TRUSTED_ORIGINS=https://myaudit.example.com
SESSION_COOKIE_SECURE=True
SECURE_HSTS_PRELOAD=True
SQL_ENGINE=django.db.backends.postgresql
RABBITMQ_DEFAULT_USER=mobileaudit
RABBITMQ_DEFAULT_PASS=SuperSecretPass123
- Launch the production stack:
docker compose -f docker-compose.prod.yaml up -d --build
-
Install TLS certificates by placing
nginx.crtandnginx.keyin thenginx/ssl/directory before starting the containers. -
Verify security headers with curl:
curl -I -s https://myaudit.example.com | grep -i "strict-transport"
- Monitor logs by shipping
logs/debug.log(configured inapp/config/settings.pylines 94-108) to a centralized logging system such as ELK or Grafana Loki.
Summary
- Set
ENV=PRODin.envto activate production-only security blocks inapp/config/settings.py. - Disable
DEBUGand use PostgreSQL viadocker-compose.prod.yamlinstead of SQLite. - Enforce HTTPS by configuring Nginx with TLS 1.2/1.3, secure cipher suites, and
SESSION_COOKIE_SECURE=True. - Isolate containers using the production compose file, which removes direct port exposure and routes traffic only through the Nginx reverse proxy.
- Protect secrets by generating strong random values for
SECRET_KEYand RabbitMQ credentials, storing them exclusively in.env(never committed to git).
Frequently Asked Questions
What is the minimum .env configuration required for production?
At minimum, you must set ENV=PROD, DEBUG=0, a strong SECRET_KEY, and DJANGO_ALLOWED_HOSTS containing your domain. Additionally, configure PostgreSQL connection variables (SQL_ENGINE, SQL_HOST, SQL_PORT) and RabbitMQ credentials (RABBITMQ_DEFAULT_USER, RABBITMQ_DEFAULT_PASS) to replace default development values.
How do I enable HTTPS for Mobile Audit?
Place your TLS certificate and private key at nginx/ssl/nginx.crt and nginx/ssl/nginx.key, then ensure SESSION_COOKIE_SECURE=True is set in your .env file. The docker-compose.prod.yaml automatically configures Nginx to listen on port 443 with the security headers defined in nginx/app_tls.conf.
Can I use SQLite in production?
No. The production configuration in app/config/settings.py (lines 72-88) expects PostgreSQL when ENV=PROD is set. SQLite lacks concurrency controls, authentication mechanisms, and durability features required for multi-user production workloads. Use the PostgreSQL service defined in docker-compose.prod.yaml (lines 4-11).
How are static files handled in production?
Nginx serves static and media files directly via the /static/ and /media/ location blocks in nginx/app_tls.conf (lines 35-41). This prevents Django from serving files, reducing CPU load and eliminating path traversal vulnerabilities associated with the development server.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →