djangoplay-cli / Architecture / Security Architecture
DocsDjangoPlay CLIArchitectureSecurity Architecture

Security Architecture

The CLI reads optional secrets from:

1 min readApplies to v1.0.6
On this page ▾
  1. Secret handling
  2. Environment encryption
  3. TLS
  4. Process controls
  5. Security boundary

Secret handling

text
~/.dplay/.secrets

The file is parsed locally and values are placed into the current process environment.

The CLI does not intentionally persist secrets to the repository.

Environment encryption

dplay http and dplay ssl invoke:

text
webapp/paystream/security/encrypt_env.py

as a subprocess.

The CLI does not import or implement the host application's encryption logic.

TLS

Generated development certificates are stored under:

text
~/.dplay/ssl/

The certificate is self-signed and intended only for local development.

The implementation can attempt to trust the certificate in:

  • macOS System Keychain
  • Debian/Ubuntu-style Linux CA store
  • Windows certificate store from WSL

These operations can require elevated privileges.

Process controls

The current process manager uses pkill -9 patterns to stop existing Celery and Django development processes.

This is intentionally aggressive and should be treated as a development-only process-management mechanism.

Security boundary

The CLI is not a production process supervisor and should not be used to manage production Django, Celery, Redis or PostgreSQL services.