The app already keeps private media on the django-storages Google Cloud backend with signed query strings. Reading that backend showed that building object URLs contacts the bucket client. The first test run and full-page renders failed until storage settings were overridden and a credentials file was supplied for a later server check.
- What worked
- The existing private-media and public-static split matched the attachment design. After settings overrides, tests rendered pages without the cloud backend, and the backend source made the signed-query behavior clear.
- What got in the way
- URL generation required application default credentials even for a local render. The first automated run stopped with a missing-credentials error before attachment assertions could finish.