Python Backend Development
Design and ship a production quality backend service in Python, complete with authentication, testing and a real deployment pipeline.
What you'll be able to do
Graduates can design and ship a production-quality backend service.
- Write typed, tested, packaged Python
- Design a normalised relational schema and manage it with migrations
- Build a documented, validated REST API
- Implement authentication, role-based access control and object-level authorisation
- Add background jobs, caching and defensive third-party integrations
- Write unit, integration and API tests that run in CI
- Containerise a service and deploy it through a pipeline
- Diagnose production issues from structured logs and error tracking
Who it's for
- Beginners with logical aptitude and no professional coding experience
- Graduates from any discipline
- Students intending to move into AI, machine learning or data work who need an engineering foundation first
- QA engineers moving toward development
Prerequisites
- None beyond computer literacy
This is the designated entry-level programming course, and it satisfies the Python prerequisite for the Generative AI and Applied Machine Learning courses.
All students complete the two-session Engineering Onboarding module before Module 1.
Tools and technologies
Target roles
Course curriculum
- Concepts
- data types and mutability; control flow; functions, arguments, scope and default-argument pitfalls; comprehensions; iterators and generators and their memory implications; exceptions covering precise catching, custom exception types and the cost of bare handlers; modules, packages and imports; virtual environments and dependency pinning; type hints and static checking; object-oriented design covering classes, composition over inheritance, dataclasses and magic methods, alongside when a plain function is the better choice; file, JSON and CSV handling; standard library essentials; style, linting and formatting; reading a traceback and using a debugger; writing a first test suite.
- Lab
- progressive katas from string handling to a small class-based domain model; refactor a 200-line procedural script into typed, tested modules; debug five faulty programs using the debugger rather than print statements; write tests for untested functions and locate two real bugs.
- Project
- Mini-project 1: a typed, tested, installable CLI application such as an expense tracker or log analyser, with argument parsing, file persistence, error handling and a README.
- Concepts
- relational design covering entities, relationships, cardinality, normalisation to third normal form and the deliberate denormalisation decision; keys and constraints as correctness guarantees; SQL covering joins, aggregation, subqueries, indexes, execution plans and transactions; ORM concepts covering models, relationships, lazy against eager loading and the N+1 problem, plus when to write raw SQL; migrations as versioned, reviewable, reversible schema history; seeding; connection pooling; timestamps, soft deletes and audit trails; parameterisation and SQL injection.
- Lab
- model a domain from a written client specification, compare it against alternatives, then implement it with migrations and realistic seed data; write fifteen queries by hand before using the ORM; create an N+1 problem, detect it in query logs and fix it; write a migration, roll it back, and write a data migration.
- Project
- the capstone data layer with schema, migrations, seeds and an entity-relationship diagram, reviewed before API work begins.
- Concepts
- HTTP covering methods, status codes, headers, content negotiation and idempotency; REST design covering resource naming, nesting, pagination, filtering, sorting and versioning; request and response validation with schemas separated from database models; consistent error contracts and exception handlers; dependency injection; project structure that survives growth across routers, services and repositories; automatic OpenAPI documentation as a deliverable; file upload handling; CORS; a comparative session on Django and Django REST Framework covering the batteries-included trade-off, the admin interface as a business asset, serializers and viewsets, and a framework selection framework.
- Lab
- build a validated, paginated, filterable CRUD API with a consistent error contract and published documentation; return deliberately incorrect status codes and have a classmate audit against the specification; implement two endpoints in Django REST Framework and write a comparison.
- Project
- Mini-project 2 begins: the documented core API for the capstone domain.
- Concepts
- password storage covering hashing, salting and algorithm choice, plus the common failures; sessions against JWTs and their trade-offs in revocation, size and statelessness; refresh tokens and rotation; OAuth2 and social login flows; email verification and password reset with secure single-use tokens; authorisation covering role-based access control, object-level ownership checks, permission dependencies and administrative boundaries; the OWASP Top 10 applied to a Python API, covering broken access control, injection, mass assignment, insecure direct object references, secrets handling, SSRF, misconfiguration and data exposure; rate limiting and brute-force defence; input sanitisation; secure headers; configuration per environment; audit logging; dependency vulnerability scanning.
- Lab
- implement the full authentication lifecycle; implement role-based access control plus per-object ownership checks; attack a classmate's API for broken access control, insecure direct object references and mass assignment, file the findings, then fix and retest your own; run a dependency audit and remediate.
- Project
- Mini-project 2 completes: the API is authenticated, authorised, rate-limited and security-reviewed, with an authorisation matrix in the README.
- Concepts
- asynchronous Python covering the event loop, concurrency against parallelism and the blocking-call pitfall; background work covering task queues, workers, retries with backoff, idempotent task design, scheduled jobs and dead-letter handling; caching covering what to cache, invalidation strategies, cache stampede and common Redis patterns; email and notification delivery; defensive third-party integration covering timeouts, retries, circuit-breaker behaviour and sandbox against production credentials; payment integration as the worked example; webhook receipt with signature verification and replay protection; integrating an LLM into a backend with server-side key handling, streaming, cost ceilings, timeouts and fallback behaviour; object storage; report and export generation; feature flags.
- Lab
- move slow report generation into a background job with status polling and retry on failure; add caching to an expensive endpoint and measure the latency change; consume a signed webhook and prove a replayed request is rejected; add a streaming AI feature with a token budget and a graceful failure path; disable an external dependency and verify the service degrades rather than fails.
- Project
- the capstone gains background processing, caching, an external integration and an AI feature.
- Concepts
- backend testing covering unit tests for domain logic, integration tests against a real test database, API-level tests through the client, fixtures and factories, isolation and transaction rollback, mocking external services while never mocking your own database, coverage as a signal, and regression tests written from real bugs; Docker for Python covering multi-stage builds, excluded development dependencies, non-root users and small base images; Compose for application, database, cache and worker; environment configuration; CI/CD covering lint, typecheck, test, build, migrate and deploy stages, branch protection, migration strategy and rollback; production operations covering worker sizing, health endpoints, structured JSON logging with correlation identifiers, error tracking, uptime monitoring and basic metrics; database backups; profiling and bottleneck identification.
- Lab
- build the test suite to meaningful coverage of business logic and all endpoints; containerise the stack so it starts with one command; build the pipeline with a required green check to merge; deploy to production; diagnose a deliberately broken deployment from logs and error tracking alone, then roll back; profile and fix the slowest endpoint.
- Project
- the capstone is tested, containerised, pipeline-deployed, logged and monitored.
- Concepts
- Agile practice covering backlog, user stories with acceptance criteria, estimation, sprint, standup, review and retrospective; issue tracking and definition of done; code review as a craft; refactoring under test cover; technical debt as a recorded decision; documentation covering README, API reference, architecture decision records and onboarding guide; handover; reading and contributing to an unfamiliar codebase; expectations for a developer's first ninety days.
- Lab
- a two-day sprint on a shared client backlog with full ceremonies; each student reviews two classmates' pull requests against a rubric; contribute a fix to an unfamiliar repository; write an onboarding guide and have a classmate follow it without assistance.
Capstone project
A production-quality backend service for a real domain. Options include a clinic booking and records API, a school fee and attendance system, a microfinance loan management API, or a logistics dispatch and tracking API.
Requirements
- Normalised PostgreSQL schema with migrations and an entity-relationship diagram
- Documented, validated, paginated REST API with OpenAPI reference
- Full authentication with role-based and object-level authorisation
- Rate limiting and a completed security review
- Background jobs with retry handling
- Caching
- One external integration with defensive error handling
- One AI-assisted feature
- Unit, integration and API tests green in CI
- Docker Compose local environment
- CI/CD pipeline with branch protection and migration handling
- Deployed live URL
- Structured logging, error tracking and a health endpoint
- README covering architecture, setup, API reference, trade-offs and known limitations
- Complete incremental pull request history
Assessment
Pathway
Also serves as the feeder course for the Generative AI and Applied Machine Learning programs.
Out of scope
- Substantial frontend work beyond a minimal interface
- Microservices architecture
- Advanced asynchronous internals
- Data science libraries
Enquire about this course
Ask about the next cohort, schedule or prerequisites and our team will get back to you.



