from decouple import config from .base import * # noqa: F403 DEBUG = False SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https") SESSION_COOKIE_SECURE = True CSRF_COOKIE_SECURE = True # TLS terminates at ingress; probes hit the pod over plain HTTP. SECURE_SSL_REDIRECT = config("SECURE_SSL_REDIRECT", default=False, cast=bool)