DjangoDeployment API¶
Import:
HostDefinition¶
| Member | Meaning |
|---|---|
host |
Primary hostname |
aliases |
Optional alias hostnames (sorted) |
identifier |
Property: dots replaced with hyphens |
all_hosts |
Property: [host] + aliases |
DjangoDeployment(...)¶
Shared infrastructure constructor parameters:
| Parameter | Required | Description |
|---|---|---|
name |
yes | Resource name prefix |
tenant_id |
yes | Entra tenant for Postgres AAD |
resource_group_name |
yes | Target resource group |
vnet |
yes | Existing VirtualNetwork |
pgsql_sku |
yes | Flexible Server SKU |
pgsql_ip_prefix |
yes | Postgres subnet CIDR |
app_service_ip_prefix |
yes | App Service subnet CIDR |
app_service_sku |
yes | Shared Linux plan SKU |
storage_account_name |
yes | Globally unique storage name |
storage_allowed_origins |
no | Blob CORS origins |
pgsql_version |
no | Default "17" |
pgsql_parameters |
no | Server parameters |
pgadmin_access_ip |
no | pgAdmin IP allowlist |
cdn_host |
no | Custom CDN hostname (str \| None) |
Class constant: HEALTH_CHECK_PATH = "/health-check".
Shared exports¶
cdn_cname, optional CDN validation TXT exportspgsql_hostpgsql_bootstrap_function_urlpgadmin_urlaccess_block_function_name,access_block_queue_url(when at least one site has access block enabled)
add_database_administrator(object_id, user_name)¶
Registers an Entra user as Postgres administrator. Tenant is taken from the deployment.
A separate user-assigned identity is also registered automatically as an Entra admin so the shared bootstrap Function can create app principals.
add_django_website(...)¶
| Parameter | Default | Description |
|---|---|---|
name |
required | Per-app prefix |
db_name |
required | Database name |
repository_url |
required | Git repo URL |
repository_branch |
required | Branch to deploy |
website_hosts |
required | list[HostDefinition] |
django_settings_module |
required | Settings module path |
python_version |
"3.14" |
Linux runtime via linuxFxVersion (PYTHON|{version}). The Windows-only pythonVersion siteConfig field is not set. |
environment_variables |
None |
Extra app settings — prefer {} |
secrets |
None |
Pulumi config name → env prefix — prefer {} |
comms_data_location |
None |
ACS data location |
comms_domains |
None |
ACS email custom domains |
dedicated_app_service_sku |
None |
Dedicated plan for this app |
vault_administrators |
None |
Entra object IDs |
redis_sidecar |
True |
Redis sidecar container |
django_tasks |
True |
Requires Redis |
django_rq_cron |
False |
RQ cron scheduler under supervisord; requires Redis; sets DJANGO_RQ_CRON + RQ_CRON_CONFIG. Consumer configs must use pulumi_django_azure.cron.register_task (see Redis, tasks, and scheduled jobs) |
startup_timeout |
600 |
Container start time limit (seconds) |
log_retention_days |
7 |
HTTP log retention; 0 skips setting |
auto_create_db_principal |
True |
Create Entra Postgres principal + DB ownership via bootstrap Function |
db_schema |
None |
Optional schema to create + grant USAGE/CREATE; does not set Django search_path |
access_block |
True |
Enqueue suspicious requests for automated IP Deny rules; set False to disable; provisions shared Function on first enabled site |
Per-app exports¶
{name}_site_principal_id{name}_site_db_user{name}_site_domain_verification_id{name}_site_domain_cname{name}_site_inbound_ipv4— list of App Service inbound IPv4 addresses (DNS A targets); union of currentinboundIpAddressandpossibleInboundIpAddresses{name}_site_inbound_ipv6— App Service inbound IPv6 (DNS AAAA target){name}_deploy_url{name}_deploy_ssh_key_url
Returns the azure.web.WebApp resource.
App Service siteConfig (restarts)¶
A siteConfig PUT recycles the App Service worker even when values are semantically unchanged. Django Web Apps therefore:
- Set only stable Linux fields on
WebApp.siteConfig(linuxFxVersion, startup command, health check, HTTP/2, FTPS, Always On,scmType=ExternalGit). - Manage application settings with a separate
WebAppApplicationSettingsresource (includingWEBSITE_HEALTHCHECK_MAXPINGFAILURES, which Azure would otherwise inject). - Ignore subsequent drift on
siteConfig.appSettingsandsiteConfig.scmType(Git source control and sidecars rewrite those). - Use a fixed start/expiry on the access-block queue SAS so
ACCESS_BLOCK_QUEUE_URLdoes not change on everypulumi up(it still rotates if the storage account key rotates).
Existing stacks will apply these as a one-time siteConfig update plus a new app-settings resource, then should stay quiet when nothing else changed.