Ubuntu服务器上Django SECRET_KEY通过os.environ调用却未在环境变量中存在的排查
Hey there, let's figure out where that missing SECRET_KEY is hiding in your inherited Django project. Since printenv isn't showing it but your settings.py pulls it from os.environ['SECRET_KEY'], it's almost certainly set in the context of how your app runs (nginx/uWSGI) rather than the global system environment. Here are the most likely places to check:
1. uWSGI Configuration Files
- uWSGI typically uses config files (
.ini,.yml) or startup scripts to set environment variables for the app process. Look for lines like:env = SECRET_KEY=your_actual_secret_key - Common locations on Ubuntu 14.04:
/etc/uwsgi/or/etc/uwsgi/apps-available/(with symlinks in/etc/uwsgi/apps-enabled/)- Project-specific folders (e.g.,
/var/www/your_project/uwsgi.ini)
- Also check startup scripts in
/etc/init.d/or upstart configs in/etc/init/— these might launch uWSGI with a--env SECRET_KEY=...flag.
2. Nginx Site Configurations
- While nginx doesn't pass env vars to uWSGI by default, some setups define the key in nginx and pass it via
uwsgi_param. Open your site's nginx config (usually in/etc/nginx/sites-available/or/etc/nginx/conf.d/) and look for:uwsgi_param SECRET_KEY "your_secret_value_here"; - If you find this, you'll need to check your uWSGI config to see if it maps this uWSGI param to an environment variable (e.g.,
env = SECRET_KEY=%(uwsgi_param_SECRET_KEY)). That's how Django would pick it up fromos.environ.
3. The uwsgi_params File
- You mentioned this file specifically — open it (usually located at
/etc/nginx/uwsgi_params) and scan for a line definingSECRET_KEY. If it's here, nginx passes it to uWSGI, but again, uWSGI needs to map it to an environment variable for Django to use it.
4. Virtual Environment Activation Scripts
- If the project uses a virtual environment, check the
bin/activatescript (orbin/activate.csh/bin/activate.fishfor other shells) for anexport SECRET_KEY=...line. Developers sometimes add these to ensure the key is set when the venv is active. - Note: This only works if uWSGI is configured to activate the venv on startup — if not, this won't be the source, but it's worth a quick check.
5. User-Specific Environment Files
- If uWSGI runs as a dedicated user (like
www-dataor a project-specific user), check that user's shell config files:~/.bashrc~/.bash_profile~/.profile
- Look for
export SECRET_KEY=...lines. Keep in mind that system services (like uWSGI started via init/upstart) might not load these files unless explicitly configured to do so.
6. Hidden Django Settings Files
- Many projects use a local settings file (e.g.,
local_settings.py) that's imported intosettings.py. Check if yoursettings.pyhas a line like:from .local_settings import * - If yes, look for
SECRET_KEYin that file. Alternatively, check for a.envfile in the project root — some setups usepython-dotenvto load env vars from this file automatically, even if it's not explicitly mentioned insettings.py.
Quick Debug Tip
If you're stuck, add a debug line to your uWSGI config to dump all environment variables when it starts:
exec-pre-app = printenv
This will output all env vars to the uWSGI log (usually in /var/log/uwsgi/), so you can confirm if SECRET_KEY is present there.
On Ubuntu 14.04, if uWSGI is managed via upstart, don't forget to check /etc/init/uwsgi.conf or app-specific upstart configs for env SECRET_KEY=... lines — upstart lets you set environment variables directly in job definitions.
内容的提问来源于stack exchange,提问作者HenryM

