BlogDjango

How to deploy a Django app.

Django deploys with one sentence and runs its migrations for you. Add gunicorn, allow your address, and read the database from the environment.

How the Agent API works
  • gunicornUsed when it is in your requirements
  • manage.py migrateRuns before the new version goes live
  • ALLOWED_HOSTSMust include your address
  • DATABASE_URLSet for you with Postgres

The short answer

To deploy a Django app, give your coding agent the sentence below. Antideploy finds Django in your requirements, creates a Postgres database, runs python manage.py migrate before the new version goes live, and starts the app with gunicorn if it is in your requirements. Without gunicorn it uses Django's built-in server and warns you.

Say this to your coding agent

Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.

What Antideploy detects

  • Django. Detected from django in requirements.txt or pyproject.toml.
  • The start command. With gunicorn, waitress or uwsgi in your requirements: gunicorn yourproject.wsgi --bind 0.0.0.0:$PORT, where the project name comes from your settings.py. Without one: python manage.py runserver 0.0.0.0:$PORT, and a warning that this server is meant for demos, not real traffic.
  • The database and migrations. Django needs a database, so Antideploy creates Postgres, and runs python manage.py migrate before the new version goes live. A failed migration fails the deploy.
  • The port. It starts the app with PORT set.
  • The Python version. From .python-version, runtime.txt or requires-python in pyproject.toml.

Settings Django needs

Three settings in settings.py matter online. Django does not read DATABASE_URL by itself.

settings.py
import os
import dj_database_url

ALLOWED_HOSTS = [".antideploy.app"]
CSRF_TRUSTED_ORIGINS = ["https://*.antideploy.app"]

DATABASES = {
    "default": dj_database_url.config(env="DATABASE_URL", conn_max_age=600),
}
  • ALLOWED_HOSTS must include your address, or Django answers every request with an error. Add your own domain too, if you attach one
  • CSRF_TRUSTED_ORIGINS needs your https:// address, or form posts are refused
  • Add dj-database-url to your requirements, or build the connection from the PG* variables
  • Keep SECRET_KEY out of your code. If your code reads SECRET_KEY, Antideploy generates one for you

Static files

Django does not serve its own static files in production. A common way is WhiteNoise: add it to your requirements and middleware, and run collectstatic during your build. Files that people upload belong in a bucket, not on the app's disk.

Step by step

  1. Add gunicorn and the database package

    List gunicorn and dj-database-url in requirements.txt.

  2. Paste the sentence and approve one link

    Your agent creates the app and the database, writes the connection details into your .env without printing them, and builds against the real database.

  3. Deploy and open the link

    Antideploy installs your requirements, runs python manage.py migrate, starts the app and checks that it answers. Your agent tells you the address.

01Before you commit

Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

  1. Apps sleep when idle

    On every plan, an app nobody is using goes to sleep and the next visit wakes it. The first request took 2.9 to 13.9 seconds in our measurements, depending on the stack. There are no always-on workers, so use a cron job or a webhook for background work.

  2. One instance, no previews

    Each app is one instance with 1 shared vCPU and 1 GB of memory, and a Java app gets 1 dedicated vCPU and 2 GB. There are no preview deployments and no per-branch URLs.

  3. The disk forgets

    Anything written to local disk is gone on the next deploy. Apps that speak S3 get a bucket instead.

02Questions

Django questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
Does Django need a Dockerfile here?

No. Antideploy builds it from your project. If there is a Dockerfile at the root, it is used instead.

Why do I get "DisallowedHost"?

Your address is not in ALLOWED_HOSTS. Add .antideploy.app, or your exact address, and deploy again.

Where does the SECRET_KEY come from?

If your code reads SECRET_KEY, Antideploy generates one, different for every app and the same on every deploy. You can set your own, and yours wins.

Is SQLite fine?

It deploys, but the data is lost whenever the app restarts or deploys. Use Postgres.

Why is the first request slow?

Apps sleep when idle, and the first request after sleeping takes a few seconds. After that, the app answers normally.

Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.