01 / Python · FastAPI
Application programming interface
Accepts a request and returns HTTP 202 after saving durable work. Readiness checks database access.
Build in public / DevOps
A small application with the engineering around it made visible: delivery, security, observability and recovery.
Interactive walkthrough
This demonstration runs in your browser. It does not connect to Kafka, a database or a Kubernetes cluster. Timing and stages are illustrative.
The request moves from acceptance through storage, messaging and completion.
Reduced motion: advance each stage when ready.
The real application
01 / Python · FastAPI
Accepts a request and returns HTTP 202 after saving durable work. Readiness checks database access.
02 / PostgreSQL · outbox
Stores the request and pending event in one transaction. A broker outage keeps the event available for retry.
03 / Apache Kafka
The relay waits for a broker acknowledgement. Events carry OpenTelemetry trace context across the queue.
04 / Python · worker
Processes the event, completes the request and then commits the consumer offset. Replays have idempotent database effects.
Delivery is at least once. Duplicate events are expected; the database completion update is idempotent. This lab uses a single Kafka broker and database instance.
The workflow must run successfully before these checks can be reported as passed. Kubernetes reconciliation through Argo CD is a later phase.
cd experiments/devops-platform-lab
python3 scripts/bootstrap.py
docker compose up --build -d
python3 scripts/smoke.pyOpen the API documentation at localhost:8000/docs and Grafana at localhost:3001. All exposed ports bind to your machine's loopback interface.
Setup and shutdown instructionsSource availability and runtime evidence are separate.
FastAPI, transactional outbox, manual offsets, idempotent completion.
Source availableTests, Ruff, Semgrep, Trivy, Software Bill of Materials, Compose smoke test.
Workflow availablePrometheus, Grafana, OpenTelemetry Collector and Tempo configuration.
Runtime check pendingIllustrative service objectives, alert rules, incident drill and runbook.
Source availableLocal Terraform and Ansible; cloud references remain unapplied.
Next phaseIstio, Vault, Cilium and Hubble need a verified local cluster.
Next phaseFinancial Operations, grounded incident assistance and Internal Developer Platform golden path.
Next phaseOpen Worldwide Application Security Project ZAP and Checkov.
Next phasePrometheus scrapes request counts, latency and worker health. Grafana displays metrics; Tempo stores distributed traces. Alerts and a worker/broker incident drill are configured for local validation.
Read the incident runbookThe platform runs locally and does not provision cloud resources or call paid model APIs. Local hardware, electricity and existing website hosting remain your responsibility. No measured cloud savings or service-level achievement is claimed.