Packaging & Deployment

The FastAPI service from PY-13 needs a home: Docker images, Azure pipelines, and secrets that never touch a config file. The final mile of Stage 8.

▶ Watch this reel

What you'll learn

  1. Dockerizing Python
  2. CI/CD in Azure DevOps
  3. Azure deploy targets
  4. Key Vault & managed identity

Remember this

Docker

Azure DevOps pipelines

Azure targets

Key Vault & managed identity

Code: The pipeline definition — the whole reel in YAML

# azure-pipelines.yml — build, gate, scan, deploy
trigger: [main]

stages:
  - stage: Build
    jobs:
      - script: |
          pip install uv && uv sync --frozen
          uv run ruff check --fix . && uv run black --check .
          uv run pytest tests/unit -q          # PY-22 suites + Fakes
        displayName: lint + unit tests
      - script: docker build -t $(acr)/app:$(Build.SourceVersion) .
        displayName: build image (SHA-tagged)

  - stage: EvalGate                 # the AI difference
    dependsOn: Build
    jobs:
      - script: uv run pytest tests/evals -q   # golden set, faithfulness,
        displayName: eval gates                # agent regressions (AG-18)

  - stage: Scan
    dependsOn: EvalGate
    jobs:
      - script: trivy image --severity HIGH,CRITICAL --exit-code 1 $(acr)/app:$(Build.SourceVersion)
        displayName: image CVE gate

  - stage: DeployProd
    dependsOn: Scan
    condition: succeeded()
    jobs:
      - deployment: swap
        environment: production              # approval gate here
        strategy: runOnce:
          deploy:
            steps:
              - script: az webapp deployment slot swap -g $(rg) -n $(app) --slot staging --target-slot production