Software · Intermediate

Backend Web Development with Python

Build a real HTTP API in Python with FastAPI: routing and validation, PostgreSQL with migrations, token authentication, tests against a test database, and a Docker Compose stack you can run.

About this course

A backend web service takes requests over HTTP, validates them, reads and writes a database, enforces who is allowed to do what, and returns predictable responses — reliably, under load, without leaking secrets. This course builds one such service from an empty directory to a running, tested, containerised API, using **FastAPI** as the primary framework. The ideas are framework-neutral (Flask and Django REST are noted for contrast), so what you learn transfers. **Building an API (lessons 1–3).** You write a first FastAPI app and run it with **uvicorn**; add routing with path, query and body parameters validated by **Pydantic** models and returned through response models; and refactor into a maintainable project — a package with routers, settings read from the environment (12-factor), and dependency injection. **Data and CRUD (lessons 4–5).** You connect to **PostgreSQL 16** with **SQLAlchemy 2.0**, manage schema changes with **Alembic** migrations, handle sessions and connections safely, and implement full create, read, update and delete with pagination, correct status codes (201, 204, 404, 422) and clean error handling. **Security (lessons 6–7).** You add registration and login with **bcrypt**-hashed passwords and signed **JWT** tokens, protect routes with a dependency, and keep secrets out of code. Then you work through the security basics every backend needs: how the ORM prevents SQL injection, input validation as defence, CORS, rate limiting, and an OWASP-aware review of the API. **Testing, packaging, production (lessons 8–10).** You test the API with **pytest** and the **httpx**-based test client against a real transactional test database, containerise the app with a Dockerfile and a Compose stack (app plus PostgreSQL) with health checks, and finish with production concerns: structured logging, running migrations on deploy, readiness probes and observability, graceful shutdown, and the twelve-factor checklist. **Final project.** "Ship a ticket service": from an empty directory you deliver an authenticated, validated, tested and containerised ticket API, prove it runs, prove the tests pass, and prove that protected routes reject unauthenticated callers — graded against a rubric and automated lab checks. Everything runs on your own lab machine `linux01` (Ubuntu 24.04, Python 3.12, Docker). No cloud account is needed. The course is a learning pathway toward backend and platform work; it makes no promise of employment or any vendor certification, and its credential is an Ultiblob Certificate of Completion.

Content time
10 h 55 min
Lessons
10
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Software — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 10 h 55 min
  1. Lesson 1: How the web works, and your first FastAPI appFree preview

    Understand what a backend does with an HTTP request, then build and run a first FastAPI app with uvicorn and see the automatic docs.

    55 min
  2. Lesson 2: Routing, parameters and validation

    Add routes with path, query and body parameters, validate input with Pydantic models, and shape output with response models.

    1 h
  3. Lesson 3: Project structure, configuration and dependencies

    Break the single file into a package with routers, read configuration from the environment, and use dependency injection to wire everything together.

    55 min
  4. Lesson 4: Persistence with PostgreSQL and SQLAlchemy

    Run PostgreSQL in a container, define ORM models with SQLAlchemy 2.0, manage the schema with Alembic migrations, and hand each request a database session.

    1 h 15 min
  5. Lesson 5: CRUD, pagination and error handling

    Wire the routes to the database for full create, read, update and delete, with pagination, correct status codes and consistent error handling.

    1 h 5 min
  6. Lesson 6: Authentication and authorization

    Register users with bcrypt-hashed passwords, issue signed JWT tokens on login, protect routes with a dependency, and scope data to the current user.

    1 h 15 min
  7. Lesson 7: Input validation and security basics

    Strengthen input validation, understand why the ORM stops SQL injection, configure CORS deliberately, add rate limiting, and review the API against the OWASP list.

    1 h 5 min
  8. Lesson 8: Testing the API

    Test the API with pytest and the httpx-based test client against a real, isolated test database, with fixtures that roll back after every test.

    1 h 10 min
  9. Lesson 9: Containerising with Docker Compose

    Package the app in a Dockerfile with a non-root user and a health check, and run it with PostgreSQL as a Compose stack configured entirely by environment.

    1 h 10 min
  10. Lesson 10: Running in production

    Make the service production-ready — structured logging, readiness and observability, migrations on deploy, graceful shutdown, and the twelve-factor checklist.

    1 h 5 min

Where it leads

Part of these career paths