Deploying Python Services
Containers, CI/CD, configuration and monitoring in production.
Take a working Python service and make it something a team can run, writing the code the platform relies on as you go. You will serve a WSGI app under gunicorn behind a proxy whose headers you trust carefully, build a small non-root Docker image, load and validate configuration from the environment, apply the twelve factors, ship through a CI pipeline with pinned, hashed and audited dependencies, terminate TLS at the edge with HSTS, release with migrations, canaries and feature flags you can roll back, write health checks, graceful shutdown and retries, instrument it with JSON logs, percentiles and burn rate alerts, and finish by building the release gate the notes API ships through.
What you will learn
- WSGI and ASGI
- gunicorn and uvicorn
- Docker images
- Docker Compose
- Twelve-factor apps
- Config and secrets
- GitHub Actions
- Supply chain security
- TLS and HSTS
- Canary releases
- Health checks and shutdown
- Structured logging
- SLOs and alerts
- Incident response
Lessons
- 1
Running Services in Production
Swap the development server for a real one: the WSGI and ASGI callables a server calls, gunicorn and uvicorn workers sized to the machine, and a reverse proxy whose forwarded headers you trust only from the proxy.
11 exercises
- 2
Docker
Package the service as an image: layers and the cache rule, a multi-stage Python Dockerfile with a non-root user and an exec form CMD, .dockerignore, building and running, and Compose with a database.
12 exercises
- 3
Configuration and Secrets
Keep config in the environment, parse it once into typed settings that fail fast, keep secrets out of the image, and log the configuration without logging the passwords in it.
11 exercises
- 4
Twelve-Factor Services
The twelve factors as failures they prevent: state that breaks with two replicas, backing services swapped by URL, port binding, scaling out, build, release and run, dev and prod parity, and admin tasks as one-off processes.
13 exercises
- 5
CI/CD
Build a GitHub Actions pipeline that lints, type checks, tests and publishes an image tagged with its commit, keep secrets out of the logs and rotate one that leaked, protect the branch, and make production deploys something you can undo.
9 exercises
- 6
Supply Chain: Pinned, Hashed and Audited
Everything you ship that you did not write: pin and hash every dependency, generate and review lockfiles, audit for known vulnerabilities with versions compared as numbers, pin third party actions to a commit, and describe what you ship in an SBOM.
10 exercises
- 7
TLS at the Edge
Where TLS terminates and what the app behind it sees, redirecting http to https without a loop or an open redirect, only TLS 1.2 and 1.3, certificates that renew themselves, and HSTS with the other security headers set at the proxy.
9 exercises
- 8
Releasing Safely: Migrations, Rollouts, Canaries and Flags
Ship without downtime: migrations ordered around the rollout, expand and contract for the changes that break running code, rolling, blue/green and canary releases compared, feature flags that separate deploy from release, and a rollback target you can name.
11 exercises
- 9
Runtime Code the Platform Relies On
The code inside the service that the platform depends on: liveness and readiness endpoints that answer different questions, a SIGTERM handler that stops taking work and drains, and retries for dependencies at startup with backoff, jitter and a clear idea of what is worth retrying.
11 exercises
- 10
Observability
Structured JSON logs on stdout with a request id on every line, metrics read as percentiles, traces that find the N+1, and alerts on symptoms tied to an error budget.
14 exercises
- 11
Putting It Together: Ship the Notes API
Build the release gate the notes API ships through, one stage per lesson: the Dockerfile review, the environment, the lockfile, the migrations and the canary, then one report that decides. Then handle the incident when a release still goes wrong, and write the postmortem.
12 exercises
How you practice
You practice in the browser and every exercise gives you feedback right away. This course uses these formats:
- Code exercise: 45
- Fix the bug: 17
- Type the answer: 10
- Predict the output: 9
- Fill in the blank: 9
- Multiple choice: 7
- Select all that apply: 7
- Spot the bug: 7
- Match the pairs: 6
- Reorder lines: 6
Aligned to
- Security
- SEC-EngineeringSecurity Analysis, Design, and Engineering
- Networking and Communication
- NC-SecurityNetwork Security
- Software Engineering
- SE-ToolsTools and Environments
- SE-ReliabilitySoftware Reliability
Proto Node Labs is not affiliated with or endorsed by ACM / IEEE-CS / AAAI. Exam names are trademarks of their owners.