Skip to content

DjangoDeployment API

Import:

from pulumi_django_azure.django_deployment import DjangoDeployment, HostDefinition

HostDefinition

HostDefinition(host: str, aliases: list[str] | None = None)
Member Meaning
host Primary hostname
aliases Optional alias hostnames (sorted)
identifier Property: dots replaced with hyphens
all_hosts Property: [host] + aliases

DjangoDeployment(...)

Shared infrastructure constructor parameters:

Parameter Required Description
name yes Resource name prefix
tenant_id yes Entra tenant for Postgres AAD
resource_group_name yes Target resource group
vnet yes Existing VirtualNetwork
pgsql_sku yes Flexible Server SKU
pgsql_ip_prefix yes Postgres subnet CIDR
app_service_ip_prefix yes App Service subnet CIDR
app_service_sku yes Shared Linux plan SKU
storage_account_name yes Globally unique storage name
storage_allowed_origins no Blob CORS origins
pgsql_version no Default "17"
pgsql_parameters no Server parameters
pgadmin_access_ip no pgAdmin IP allowlist
cdn_host no Custom CDN hostname (str \| None)

Class constant: HEALTH_CHECK_PATH = "/health-check".

Shared exports

  • cdn_cname, optional CDN validation TXT exports
  • pgsql_host
  • pgsql_bootstrap_function_url
  • pgadmin_url
  • access_block_function_name, access_block_queue_url (when at least one site has access block enabled)

add_database_administrator(object_id, user_name)

Registers an Entra user as Postgres administrator. Tenant is taken from the deployment.

A separate user-assigned identity is also registered automatically as an Entra admin so the shared bootstrap Function can create app principals.

add_django_website(...)

Parameter Default Description
name required Per-app prefix
db_name required Database name
repository_url required Git repo URL
repository_branch required Branch to deploy
website_hosts required list[HostDefinition]
django_settings_module required Settings module path
python_version "3.14" Linux runtime via linuxFxVersion (PYTHON|{version}). The Windows-only pythonVersion siteConfig field is not set.
environment_variables None Extra app settings — prefer {}
secrets None Pulumi config name → env prefix — prefer {}
comms_data_location None ACS data location
comms_domains None ACS email custom domains
dedicated_app_service_sku None Dedicated plan for this app
vault_administrators None Entra object IDs
redis_sidecar True Redis sidecar container
django_tasks True Requires Redis
django_rq_cron False RQ cron scheduler under supervisord; requires Redis; sets DJANGO_RQ_CRON + RQ_CRON_CONFIG. Consumer configs must use pulumi_django_azure.cron.register_task (see Redis, tasks, and scheduled jobs)
startup_timeout 600 Container start time limit (seconds)
log_retention_days 7 HTTP log retention; 0 skips setting
auto_create_db_principal True Create Entra Postgres principal + DB ownership via bootstrap Function
db_schema None Optional schema to create + grant USAGE/CREATE; does not set Django search_path
access_block True Enqueue suspicious requests for automated IP Deny rules; set False to disable; provisions shared Function on first enabled site

Per-app exports

  • {name}_site_principal_id
  • {name}_site_db_user
  • {name}_site_domain_verification_id
  • {name}_site_domain_cname
  • {name}_site_inbound_ipv4 — list of App Service inbound IPv4 addresses (DNS A targets); union of current inboundIpAddress and possibleInboundIpAddresses
  • {name}_site_inbound_ipv6 — App Service inbound IPv6 (DNS AAAA target)
  • {name}_deploy_url
  • {name}_deploy_ssh_key_url

Returns the azure.web.WebApp resource.

App Service siteConfig (restarts)

A siteConfig PUT recycles the App Service worker even when values are semantically unchanged. Django Web Apps therefore:

  • Set only stable Linux fields on WebApp.siteConfig (linuxFxVersion, startup command, health check, HTTP/2, FTPS, Always On, scmType=ExternalGit).
  • Manage application settings with a separate WebAppApplicationSettings resource (including WEBSITE_HEALTHCHECK_MAXPINGFAILURES, which Azure would otherwise inject).
  • Ignore subsequent drift on siteConfig.appSettings and siteConfig.scmType (Git source control and sidecars rewrite those).
  • Use a fixed start/expiry on the access-block queue SAS so ACCESS_BLOCK_QUEUE_URL does not change on every pulumi up (it still rotates if the storage account key rotates).

Existing stacks will apply these as a one-time siteConfig update plus a new app-settings resource, then should stay quiet when nothing else changed.