Django ASGI, Deployment, Static Assets & Observability

Deploying Django to production requires transitioning from simple WSGI synchronous workers to scalable ASGI event loops, managing static assets via WhiteNoise or Cloud Storage, and exporting real-time telemetry metrics. Understanding Gunicorn vs Uvicorn process management, ASGI coroutine execution, and OpenTelemetry instrumentation is essential for principal systems engineers.

This chapter covers WSGI vs ASGI execution architecture, production static file streaming, Gunicorn worker management, and observability metrics.


1. WSGI vs. ASGI Architecture & Worker Process Models

Historically, Django ran exclusively on WSGI (Web Server Gateway Interface), a synchronous interface where each HTTP connection maps 1:1 to a worker thread/process. Modern Django (3.0+) supports ASGI (Asynchronous Server Gateway Interface) for async views, WebSockets, and Server-Sent Events (SSE).

WSGI vs ASGI Production Process Models:

[ WSGI (Gunicorn + sync workers) ]
Request 1 ---> Worker Process 1 (BLOCKED during DB/I/O wait)
Request 2 ---> Worker Process 2 (BLOCKED during DB/I/O wait)

[ ASGI (Uvicorn / Gunicorn + UvicornWorker) ]
Request 1 ---\
Request 2 -----> Single Event Loop Process (uvloop)
Request 3 ---/   (Non-blocking I/O via async/await coroutines)

Production Application Server Stack:

In production, run Gunicorn as the Process Manager managing a pool of Uvicorn workers (gunicorn -w 4 -k uvicorn.workers.UvicornWorker myproject.asgi:application). Gunicorn handles process restarts and signals, while Uvicorn executes the uvloop event loop.


2. Production Static Asset Serving (WhiteNoise vs CDN)

During development, manage.py runserver serves static files dynamically. In production, DEBUG=False disables this mechanism.

  • WhiteNoise Architecture: Integrates directly into Django’s WSGI/ASGI middleware stack (whitenoise.middleware.WhiteNoiseMiddleware). It intercept static file requests, applies unique content hashes to filenames (staticfilesjson), appends Cache-Control: max-age=31536000, public headers, and streams gzip/brotli compressed files directly from disk without touching Django Python code.
  • S3 / Cloud Storage CDN: Offloads static assets entirely to AWS S3/CloudFront or Cloud Storage via django-storages.

3. Observability & Telemetry (Prometheus & OpenTelemetry)

High-availability Django deployments enforce zero-downtime health monitoring:

  • Metrics (Prometheus): Instrument endpoints using django-prometheus to export worker memory usage, HTTP status codes, DB connection pool state, and request duration histograms.
  • Tracing (OpenTelemetry): Auto-instrument Django via opentelemetry-instrumentation-django to trace distributed requests across microservices.

4. Production Security Hardening Checklist

  • DEBUG = False (Mandatory; prevents exposing interactive debug tracebacks).
  • ALLOWED_HOSTS = ['api.domain.com'] (Prevents HTTP Host Header attacks).
  • SECURE_SSL_REDIRECT = True & SESSION_COOKIE_SECURE = True.
  • SECURE_HSTS_SECONDS = 31536000 (Enforces HTTP Strict Transport Security).
Display Options
Appearance
Text Size
100%