Toolset · Pydantic, SQLAlchemy, async
Python / FastAPI
- Python
- FastAPI
- Pydantic
FastAPI is our default Python backend: async, typed, and self-documenting. Pydantic for validation, SQLAlchemy for data, and a real task queue for background work.
Where two tools compete, the one marked our default is what we reach for.
Packaging & deps
2 toolsFramework & DI
1 toolAsync web framework with typed request/response models and OpenAPI out of the box. Dependency injection is built in via Depends. Our default.
def get_db() -> Session: ... # a dependency
def get_repo(db: Session = Depends(get_db)) -> UserRepository:
return UserRepository(db)
@app.get("/users/{id}")
async def read_user(id: str, repo: UserRepository = Depends(get_repo)):
return await repo.find(id)Validation & settings
1 toolData validation and settings via type hints — parse at the boundary. Our default.
Environment variables
1 toolType-safe environment configuration — define a Settings class with validated fields, load from .env in development, and read config from a single settings object everywhere. Fail fast at startup on anything missing or invalid, and never hardcode values. Our default.
ORM & migrations
2 toolsThe definitive Python ORM/toolkit with a modern async API. Mind session-per-request and isolation. Our default.
Migrations for SQLAlchemy.
Authentication & authorization
2 toolspython-jose for JWTs and passlib for password hashing. Implement auth as a FastAPI dependency (Depends) that verifies the token and returns the user, and wire OAuth2PasswordBearer so the flow shows up in the OpenAPI docs. Never trust decoded claims without verifying the signature. Our default.
Enforce authorization with a dependency that checks the user's role — resolved server-side, never from client input. See the RBAC spec for the data model and enforcement points.
Async DB & HTTP
2 toolsTask queue
2 toolsDistributed task queue (Redis/RabbitMQ). Keep tasks idempotent and carry IDs, not objects. Our default.
A simpler, more ergonomic alternative to Celery — fewer features, less complexity, cleaner API. Decision rule: start with Celery for its robustness and ecosystem; consider Dramatiq for smaller projects or simpler workloads where Celery's complexity is overkill.
Security
3 toolsConfigure CORS with FastAPI's built-in middleware — allow only trusted origins, never a wildcard alongside credentials. Baseline hygiene for any browser-facing API. Our default.
Basic rate limiting to blunt brute-force and abuse; fastapi-limiter is Redis-backed so limits hold across multiple workers.
Add security headers (CSP, X-Content-Type-Options, and more) via a custom middleware or the secure library.
Testing & serving
2 toolsTesting with httpx AsyncClient for API tests. Our default.
ASGI server; run Uvicorn workers under Gunicorn in production.
Monitoring & observability
4 toolsError and performance monitoring with a FastAPI/Starlette integration. Our default for errors.
Vendor-neutral traces and metrics; auto-instrument FastAPI, SQLAlchemy, and httpx, export anywhere. Our default for tracing.
One-line Prometheus metrics endpoint for FastAPI — request latency, counts, and status codes.
Structured, context-aware logging that ships clean JSON to your log pipeline.
CI/CD
5 toolsuv sync, run pytest, then build the image. Our default CI.
Containerise with a slim image for a reproducible deploy. Our default.
Push-to-deploy container hosting for the FastAPI service.
Handle SIGTERM to stop accepting new requests, let in-flight requests finish, and close database and queue connections before exiting. In FastAPI, do startup/shutdown work in the lifespan handler (async with). This prevents dropped requests during restarts and is what makes zero-downtime deploys actually zero-downtime.
Run ruff and formatters on commit and in CI — fail fast on style/lint.
Linting & formatting
3 toolsBuilding on Python / FastAPI?
We ship production Python / FastAPIwith exactly this stack. Tell us what you're building.
Start a conversation