Security Architecture
The CLI reads optional secrets from:
Secret handling
~/.dplay/.secretsThe file is parsed locally and values are placed into the current process environment.
The CLI does not intentionally persist secrets to the repository.
Environment encryption
dplay http and dplay ssl invoke:
webapp/paystream/security/encrypt_env.pyas a subprocess.
The CLI does not import or implement the host application's encryption logic.
TLS
Generated development certificates are stored under:
~/.dplay/ssl/The certificate is self-signed and intended only for local development.
The implementation can attempt to trust the certificate in:
- macOS System Keychain
- Debian/Ubuntu-style Linux CA store
- Windows certificate store from WSL
These operations can require elevated privileges.
Process controls
The current process manager uses pkill -9 patterns to stop existing
Celery and Django development processes.
This is intentionally aggressive and should be treated as a development-only process-management mechanism.
Security boundary
The CLI is not a production process supervisor and should not be used to manage production Django, Celery, Redis or PostgreSQL services.