# How to deploy a Django app.

URL: https://antideploy.com/blog/how-to-deploy-a-django-app

Django deploys with one sentence and runs its migrations for you. Add gunicorn, allow your address, and read the database from the environment.

## At a glance

- **gunicorn**: Used when it is in your requirements
- **manage.py migrate**: Runs before the new version goes live
- **ALLOWED_HOSTS**: Must include your address
- **DATABASE_URL**: Set for you with Postgres

Published 7 October 2026. Facts checked 7 October 2026. 2 min read.

## The short answer

To deploy a Django app, give your coding agent the sentence below. Antideploy finds Django in your requirements, creates a Postgres database, runs `python manage.py migrate` before the new version goes live, and starts the app with `gunicorn` if it is in your requirements. Without gunicorn it uses Django's built-in server and warns you.

> **Say this to your coding agent**
>
> Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.

## What Antideploy detects

- **Django.** Detected from `django` in `requirements.txt` or `pyproject.toml`.
- **The start command.** With `gunicorn`, `waitress` or `uwsgi` in your requirements: `gunicorn yourproject.wsgi --bind 0.0.0.0:$PORT`, where the project name comes from your `settings.py`. Without one: `python manage.py runserver 0.0.0.0:$PORT`, and a warning that this server is meant for demos, not real traffic.
- **The database and migrations.** Django needs a database, so Antideploy creates Postgres, and runs `python manage.py migrate` before the new version goes live. A failed migration fails the deploy.
- **The port.** It starts the app with `PORT` set.
- **The Python version.** From `.python-version`, `runtime.txt` or `requires-python` in `pyproject.toml`.

## Settings Django needs

Three settings in `settings.py` matter online. Django does not read `DATABASE_URL` by itself.

**settings.py**

```
import os
import dj_database_url

ALLOWED_HOSTS = [".antideploy.app"]
CSRF_TRUSTED_ORIGINS = ["https://*.antideploy.app"]

DATABASES = {
    "default": dj_database_url.config(env="DATABASE_URL", conn_max_age=600),
}
```

- `ALLOWED_HOSTS` must include your address, or Django answers every request with an error. Add your own domain too, if you attach one
- `CSRF_TRUSTED_ORIGINS` needs your `https://` address, or form posts are refused
- Add `dj-database-url` to your requirements, or build the connection from the `PG*` variables
- Keep `SECRET_KEY` out of your code. If your code reads `SECRET_KEY`, Antideploy generates one for you

## Static files

Django does not serve its own static files in production. A common way is WhiteNoise: add it to your requirements and middleware, and run `collectstatic` during your build. Files that people upload belong in a bucket, not on the app's disk.

## Step by step

### 1. Add gunicorn and the database package

List `gunicorn` and `dj-database-url` in `requirements.txt`.

### 2. Paste the sentence and approve one link

Your agent creates the app and the database, writes the connection details into your `.env` without printing them, and builds against the real database.

### 3. Deploy and open the link

Antideploy installs your requirements, runs `python manage.py migrate`, starts the app and checks that it answers. Your agent tells you the address.

## Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

### Apps sleep when idle

On every plan, an app nobody is using goes to sleep and the next visit wakes it. The first request took 2.9 to 13.9 seconds in our measurements, depending on the stack. There are no always-on workers, so use a cron job or a webhook for background work.

### One instance, no previews

Each app is one instance with 1 shared vCPU and 1 GB of memory, and a Java app gets 1 dedicated vCPU and 2 GB. There are no preview deployments and no per-branch URLs.

### The disk forgets

Anything written to local disk is gone on the next deploy. Apps that speak S3 get a bucket instead.

## Django questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Does Django need a Dockerfile here?

No. Antideploy builds it from your project. If there is a Dockerfile at the root, it is used instead.

### Why do I get "DisallowedHost"?

Your address is not in `ALLOWED_HOSTS`. Add `.antideploy.app`, or your exact address, and deploy again.

### Where does the SECRET_KEY come from?

If your code reads `SECRET_KEY`, Antideploy generates one, different for every app and the same on every deploy. You can set your own, and yours wins.

### Is SQLite fine?

It deploys, but the data is lost whenever the app restarts or deploys. Use Postgres.

### Why is the first request slow?

Apps sleep when idle, and the first request after sleeping takes a few seconds. After that, the app answers normally.

## More guides, and the platform.

Each platform page covers one part of Antideploy: what it does, where it stops and the questions people ask. [See the whole platform](https://antideploy.com/platform), or [all the guides](https://antideploy.com/blog).

- [How to deploy a Flask app for free](https://antideploy.com/blog/how-to-deploy-a-flask-app-for-free): How your app is found, why to add gunicorn, the PORT variable and Postgres.
- [How to add a Postgres database to your app](https://antideploy.com/blog/how-to-add-a-postgres-database-to-your-app): Ask your agent. A Postgres 17 database is created beside your app and DATABASE_URL is set.
- [ModuleNotFoundError: No module named](https://antideploy.com/blog/modulenotfounderror-no-module-named): Your code imports a package that is not in requirements.txt. Add it, using the package name.

- [Hosting](https://antideploy.com/platform/hosting)
- [Database](https://antideploy.com/platform/database)
- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Deployments](https://antideploy.com/platform/deployments)

Facts on this page were checked against the live platform on 7 October 2026.

## Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
