The .htaccess hacks are great but they are just patching the symptom, and one slip up and you're back to square one.
The best way to do configuration is to have it in environment variables that are populated in a completely separate config file for the specific instance, so for instance a uWSGI ini file.
This is very easy with Django and uWSGI.
In your uWSGI.ini:
env = DJANGO_SETTINGS_MODULE=yoursite.settings.production
env = DJANGO_SECRET_KEY=herp
env = DJANGO_DB_PASSWORD=derp
In yoursite/settings/production.py from .base import *
In yoursite/settings/base.py import os
DATABASES = {
'default': {
...
'PASSWORD': os.environ.get('DJANGO_DB_PASSWORD'),
...
}
}
SECRET_KEY = os.environ.get('DJANGO_SECRET_KEY')
I'm not sure if this is possible with WordPress or the whole shitty PHP way of doing things - perhaps if you had a FPM pool for each site and site specific configuration in there?