Security and trust-boundary notes for djangoplay-cli.
Machine-local secrets live in ~/.dplay/.secrets, loaded into the process environment at runtime — never committed to the CLI or application repository.
The CLI never imports the host application’s Django internals; it only talks to it through process boundaries (manage.py, Celery, OpenSSL subprocesses).
dplay system reset is scoped to development only — it stops local Celery processes and flushes the local Redis instance, not a production management mechanism.
TLS certificates are self-signed for local development and trusted into the macOS Keychain automatically; production TLS is out of scope.