Sign inSign up

riteshatri/resource-management-backend

By riteshatri

•Updated 9 months ago

Production-ready FastAPI backend for Resource Management System with Azure SQL support

Image
0

1.5K

riteshatri/resource-management-backend repository overview

⁠🚀 Resource Management Backend -- Production Docker Image

This repository provides a production-grade Docker image for the Resource Management Backend, built using FastAPI, Gunicorn, and Azure SQL.

This Repository overview is written A to Z, so that anyone can:

  • Understand what this image does
  • Know what is required to run it
  • Deploy it confidently in production

⁠📌 What is this Image?

This Docker image runs a FastAPI backend application that:

  • Connects to Azure SQL Database
  • Provides REST APIs for a Resource Management system
  • Uses JWT-based authentication
  • Is optimized for production workloads

The application runs using:

  • Gunicorn (process manager)
  • Uvicorn workers (ASGI)
  • Non-root user (security best practice)

⁠📦 Docker Image Information

  • Image Name
<!-- -->
riteshatri/resource-management-backend
<!-- -->
8000

⁠🧠 How this Container Works (Inside Story)

When the container starts:

  1. Docker starts the container
  2. Gunicorn launches FastAPI using Uvicorn workers
  3. App reads configuration from environment variables
  4. App connects to Azure SQL
  5. APIs become available on port 8000
  6. /health endpoint confirms service status

No manual command, no systemd, no SSH required.


⁠⚙️ Prerequisites (Before Running)

You only need:

  • Docker installed on your system or VM
  • Internet access (to pull image)
  • Azure SQL credentials
⁠Install Docker (Ubuntu)
sudo apt update
sudo apt install -y docker.io
sudo systemctl enable docker
sudo systemctl start docker

⁠🔐 Environment Configuration (.env file)

This application does NOT work without environment variables.

Create a file named .env in any directory on your server.

⁠📄 Example .env file
# ==============================
# Azure SQL Database Configuration
# ==============================
AZURE_SQL_SERVER=your-server.database.windows.net
AZURE_SQL_DATABASE=your-database-name
AZURE_SQL_USERNAME=your-db-username
AZURE_SQL_PASSWORD=your-db-password

# ==============================
# Security / JWT Configuration
# ==============================
SECRET_KEY=your-very-long-random-secret-key
ALGORITHM=HS256
ACCESS_TOKEN_EXPIRE_MINUTES=30

# ==============================
# CORS & Frontend
# ==============================
CORS_ORIGINS=["*"]
FRONTEND_URL=http://your-frontend-url:frontendPort

⁠🔑 Generating SECRET_KEY

If you don't already have a secret key, generate one using Python:

python3 -c "import secrets; print(secrets.token_hex(32))"

⁠🔐 Generating SECRET_KEY using PowerShell (Windows)

This guide explains the simplest and safest way to generate a SECRET_KEY on Windows using PowerShell, without installing Python or any extra tools.


🔐 How to generate SECRET_KEY on Windows (PowerShell)

⁠✅ Generate SECRET_KEY (PowerShell)

⁠Step 1: Open PowerShell

Press:

Win + X → Windows PowerShell
⁠Step 2: Run this command
[System.Guid]::NewGuid().ToString("N")
⁠🔥 Example Output
9f7c1b3c5e8a4f0b8d5c1a6e9f4a7b2c

For production environments, generate a stronger secret:

  1. Run the same command two times
  2. Copy both outputs
  3. Paste them together (concatenate)
⁠Example
SECRET_KEY=9f7c1b3c5e8a4f0b8d5c1a6e9f4a7b2c8d1a7f9c5e4b2a6d9f0c1e3a4b5

✅ This is secure enough for production JWT signing.


⁠🧠 Why This Works

  • GUIDs are randomly generated
  • Extremely difficult to guess
  • Fully acceptable for JWT SECRET_KEY
  • Used widely in production systems

⁠❌ Important Rules (Never Break These)

  • ❌ Do NOT commit SECRET_KEY to GitHub
  • ❌ Do NOT paste real secrets in README files
  • ❌ Do NOT reuse the same SECRET_KEY across projects

⁠📌 Best Practice Summary

  • Generate a unique secret per environment (dev / uat / prod)
  • Store secrets only in .env or secret managers
  • Rotate secrets periodically for better security

✅ No Python
✅ No installation required
✅ 100% Windows native solution

⁠🔒 Security Rules for .env
  • ❌ Never commit .env to GitHub
  • ❌ Never bake .env inside Docker image
  • ✅ Always pass it at runtime
------------------------------------------------------------------------

⁠▶️ Running the Container (Production Way)

⁠Step 1️⃣ Pull Image
docker pull riteshatri/resource-management-backend:latest

⁠Step 2️⃣ Run Container
docker run -d   --name resource-backend   --env-file .env   -p 8000:8000   --restart unless-stopped   riteshatri/resource-management-backend:latest
⁠What these flags mean:

Flag Purpose


-d Run in background
--env-file .env Inject environment variables
-p 8000:8000 Expose API
--restart unless-stopped Auto-start on reboot
--name Easy container management


⁠🩺 Health Check

Once container is running:

curl http://localhost:8000/health

Expected response:

{"status":"healthy"}

This confirms: - App started correctly - Database connection is working


⁠📜 Logs & Monitoring

View live logs:

docker logs -f resource-backend

Restart container:

docker restart resource-backend

Stop container:

docker stop resource-backend

⁠🔄 Updating the Application

When a new version is released:

docker pull riteshatri/resource-management-backend:latest
docker stop resource-backend
docker rm resource-backend
docker run -d   --name resource-backend   --env-file .env   -p 8000:8000   --restart unless-stopped   riteshatri/resource-management-backend:latest

No data loss, no reconfiguration.


⁠🔐 Security Best Practices

  • Runs as non-root user
  • Secrets never stored in image
  • Uses environment variables only
  • Suitable for cloud & enterprise deployments

⁠🚀 Production Recommendations

  • Use Nginx as reverse proxy
  • Enable HTTPS (SSL)
  • Restrict port 8000 via firewall
  • Use Docker Compose or Kubernetes for scaling
  • Monitor with centralized logging

⁠🛠 Technology Stack

  • Python 3.12
  • FastAPI
  • Gunicorn
  • Uvicorn
  • Docker
  • Azure SQL

⁠👨‍💻 Maintainer

⁠Ritesh Atri


⭐ If this Docker image helps you, please consider starring the GitHub repository.

Tag summary

Content type

Image

Digest

sha256:e89ebc941…

Size

84.4 MB

Last updated

9 months ago

docker pull riteshatri/resource-management-backend