This plan is optimized for an experienced software engineer targeting production-ready Python backend delivery.
| Category | Topics | Priority | Why it matters in 2026 |
|---|---|---|---|
| Python Core Engineering | Python fundamentals, modules/packages, semantic versioning, repository metadata/scripts, typing, data structures and algorithms | Must Know | Core reliability, maintainability, and team-scale collaboration depend on language and packaging discipline. |
| Architecture and Design | Interfaces/protocols, OOP, SOLID, KISS, YAGNI, design patterns | Must Know | Enables low-coupling codebases that evolve safely under changing product requirements. |
| API and Web Backend | HTTP/HTTPS, REST, GraphQL, RPC, API clients, framework selection | Must Know | Backend value is exposed through stable API contracts and dependable protocol behavior. |
| Data and Persistence | SQL fundamentals, PostgreSQL, MySQL/MariaDB, SQL Server, NoSQL, cloud databases | Must Know (SQL + PostgreSQL), Good to Know (others) | Data modeling and query quality dominate backend correctness and performance. |
| Performance and Concurrency | Async IO, threading, multiprocessing, synchronization, caching, Redis, Memcached | Must Know (async + Redis), Good to Know (others) | Throughput and latency improvements come from correct workload model and cache strategy. |
| Distributed Systems | Message brokers, microservices, real-time communication | Must Know (one broker + service decomposition basics), Good to Know (vendor-specific tools) | Event-driven flows and service boundaries are common in modern backend architectures. |
| Quality Engineering | Unit/integration/E2E tests, mocking, pytest ecosystem, BDD/UI tools | Must Know (pytest + test pyramid), Good to Know (BDD/UI automation) | Fast and trustworthy release cycles require robust test strategy and automation. |
| Observability | Logging, log aggregation, distributed tracing, exception tracking | Must Know | You cannot operate or debug production systems without telemetry quality. |
| Security Engineering | AuthN/AuthZ, OAuth2, JWT, secrets, input validation, secure dependencies/containers | Must Know | Security defects are production incidents and business risk, not optional hardening. |
| Delivery and Team Workflow | Git, Scrum/Kanban, Docker-based testing, CI/CD | Must Know | Reliable delivery cadence requires repeatable build/test/release workflows. |
| Optional ML Adjacent | NumPy, Pandas, Scikit-learn, TensorFlow, Keras, PyTorch, NLTK | Optional | Useful specialization, but not required for most backend engineering roles. |
| Item | Action |
|---|---|
| Pipenv | Keep as legacy awareness only. Not a default for new backend projects. |
| Memcached vs Redis | Redis first. Memcached as Good to Know for existing systems. |
| Flask and Django only | Add FastAPI as primary API-first recommendation. |
| Robot Framework/Cucumber/Selenium in core path | Keep as Good to Know; not required for backend-first progression. |
| ActiveMQ/Azure Service Bus/RavenDB/CouchDB | Keep as ecosystem-specific Good to Know unless needed by target role. |
Assumption: 12-15 focused hours per week.
| Week | Main Learning Goal | Concepts to Study | Hands-on Tasks | Mini Project / Exercise | Recommended Tools and Libraries | Expected Output |
|---|---|---|---|---|---|---|
| 1 | Baseline modern Python workflow | Python 3.12+, typing, modules, pyproject, semver | Initialize repository, lint/type/test setup | Typed utility package and CLI | uv, ruff, mypy, pytest, Click | Clean project skeleton with passing checks |
| 2 | Architecture fundamentals in practice | Protocols, OOP trade-offs, SOLID, KISS, YAGNI | Refactor into layered architecture | Strategy + Factory in a service module | typing.Protocol, dataclasses, pydantic | Refactored modules with tests and design notes |
| 3 | Build API foundation | HTTP semantics, REST conventions, error models | Build CRUD API with validation | Task service API v1 | FastAPI, Uvicorn, Pydantic v2 | OpenAPI-documented API with consistent error contracts |
| 4 | Data modeling and migrations | SQL fundamentals, indexing, transactions, isolation | Integrate relational DB and migrations | User/project/task schema implementation | PostgreSQL, SQLAlchemy 2, Alembic | Versioned schema and repository layer |
| 5 | Performance and concurrency | Async IO, event loop, thread/process decisions, caching patterns | Add async endpoints and Redis cache-aside | Measure cached vs non-cached endpoint latency | redis-py, asyncio, locust or k6 | Performance notes and cache invalidation strategy |
| 6 | Testing maturity | Unit/integration/E2E boundaries, mocking, fixture design | Build robust API + DB integration tests | Failure injection for external dependency calls | pytest, pytest-mock, httpx, testcontainers | Reliable CI-ready test suite |
| 7 | Background processing | Queue semantics, retries, DLQ, idempotency, scheduling | Add worker and recurring jobs | Async report/email pipeline | Celery or Dramatiq, RabbitMQ, APScheduler | Worker subsystem with retry and monitoring hooks |
| 8 | Multi-protocol APIs | GraphQL/RPC fundamentals, client resilience | Add GraphQL or gRPC interface | Client package with retry/backoff | Strawberry/Graphene or grpcio, tenacity | Multi-interface backend + resilient client |
| 9 | Observability integration | Structured logs, traces, metrics, exception tracking | Add telemetry context and correlation IDs | Incident drill with root-cause tracing | OpenTelemetry, Jaeger, Sentry, structlog | Operational telemetry baseline and runbook |
| 10 | Security hardening | OAuth2, JWT, RBAC/ABAC, OWASP API risks | Implement authN/authZ and secure defaults | Threat model one endpoint and mitigate risks | Authlib, passlib, PyJWT/python-jose, pip-audit, bandit | Security checklist and hardened release |
| 11 | Microservice delivery | Service boundaries, messaging contracts, CI/CD workflows | Split one bounded context into a second service | Local multi-service compose stack | Docker, docker compose, GitHub Actions | Automated build/test/security/deploy pipeline |
| 12 | Capstone productionization | SLOs, load testing, release discipline, operations | Finalize architecture and deployment runbooks | v1 release with changelog and on-call notes | k6, Prometheus/Grafana (optional) | Portfolio-grade production-ready backend project |
| Milestone | Definition of done |
|---|---|
| Week 4 Gate | API + DB migrations + integration tests all green in CI |
| Week 8 Gate | REST plus GraphQL or gRPC with client reliability features |
| Week 12 Gate | Security scans, telemetry, load baseline, deployment docs complete |
- Runtime: Python 3.12 or 3.13
- API: FastAPI
- Validation: Pydantic v2
- ORM and migrations: SQLAlchemy 2 + Alembic
- Primary database: PostgreSQL
- Cache and rate limit store: Redis
- Queue/broker: RabbitMQ (tasks), Kafka (streams)
- Tests: pytest, pytest-mock, testcontainers, httpx
- Observability: OpenTelemetry, Jaeger, Sentry, structured logs
- Packaging and dependencies: pyproject.toml + uv
- Delivery: Docker + GitHub Actions
| Framework | Use When | Strengths | Trade-offs |
|---|---|---|---|
| FastAPI | API-first services, async-heavy workloads | Performance, OpenAPI by default, strong typing ergonomics | Less batteries-included than Django |
| Django | Full product backend with admin-heavy internal workflows | Mature ecosystem, built-in admin/auth/ORM | Heavier defaults, less lightweight for pure API microservices |
| Flask | Small or custom services where minimalism is preferred | Simple, flexible, low abstraction overhead | Requires more architecture decisions as codebase scales |
| Technology | Prefer When | Avoid When |
|---|---|---|
| PostgreSQL | Default OLTP, strong consistency, rich SQL features | Workload is pure event replay and append-only analytics |
| Redis | Caching, distributed locks, rate limiting, ephemeral state | You need durable source-of-truth business records |
| RabbitMQ | Reliable command/job queue semantics and routing | High-volume event replay is a hard requirement |
| Kafka | Event-stream processing, replay, analytics pipelines | Your use case is only simple background job processing |
| MongoDB | Document-centric, rapidly changing nested payloads | Highly relational domains with strict transactional guarantees |
| Elasticsearch | Full-text search and log search analytics | Primary transactional record storage |
| Tooling | Recommendation |
|---|---|
| pyproject.toml + uv | Default for new backend projects in 2026 |
| Poetry | Strong choice where team standardizes on Poetry workflows/publishing |
| pip + virtualenv | Acceptable for minimal stacks and constrained environments |
| conda | Better for data-science/native dependency ecosystems |
| pipenv | Legacy compatibility only |
uv init
uv add fastapi uvicorn sqlalchemy alembic pydantic redis pytest pytest-mock httpx
uv sync
python -m venv .venv
pip install -r requirements.txt
poetry init
poetry add fastapi sqlalchemy pytest
conda create -n pybackend python=3.12- Description: Multi-user tasks/projects API with auth and audit logs.
- Architecture: Modular monolith, layered services.
- Main libraries: FastAPI, SQLAlchemy, Alembic, Pydantic, pytest.
- Database: PostgreSQL.
- API design: REST, pagination, filtering, idempotent writes.
- Testing: Unit + integration + migration tests.
- Logging/monitoring: Structured logs + Sentry.
- Docker setup: API + PostgreSQL + Redis compose stack.
- Security: Password hashing, JWT rotation, RBAC, rate limiting.
- Deployment: Managed container platform or VM.
- GitHub proof: API design quality, migration discipline, test quality.
- Description: Inventory reservation and order workflow with async processing.
- Architecture: API + worker + message broker.
- Main libraries: FastAPI, Celery/Dramatiq, Redis, RabbitMQ, SQLAlchemy.
- Database: PostgreSQL + Redis.
- API design: REST with idempotency keys.
- Testing: Queue integration tests, retry/DLQ behavior tests.
- Logging/monitoring: Queue lag metrics, business event traces.
- Docker setup: Multi-container compose (api/worker/db/cache/broker).
- Security: Signed webhooks, strict schema validation.
- Deployment: Autoscaled workers in managed containers.
- GitHub proof: Reliability engineering and event-driven workflow design.
- Description: Channel messaging, presence, notifications.
- Architecture: REST API + Socket gateway + Redis pub/sub.
- Main libraries: FastAPI, python-socketio, Redis.
- Database: PostgreSQL + Redis.
- API design: REST for resources and WebSocket events for live collaboration.
- Testing: Protocol-level event tests and pub/sub integration tests.
- Logging/monitoring: Connection metrics, latency, dropped events.
- Docker setup: API + gateway + Redis + PostgreSQL.
- Security: Auth on connect, room-level authorization.
- Deployment: Container platform with session strategy.
- GitHub proof: Real-time architecture and event correctness.
- Description: Event ingestion, transformation, and analytics query API.
- Architecture: Producer, stream processor, query service.
- Main libraries: FastAPI, aiokafka or confluent-kafka, pydantic.
- Database: PostgreSQL or ClickHouse, optional Elasticsearch.
- API design: Versioned event contracts + analytics endpoints.
- Testing: Contract compatibility tests + load tests.
- Logging/monitoring: Consumer lag, throughput, trace propagation.
- Docker setup: Local Kafka ecosystem in compose.
- Security: ACLs, secret rotation, schema validation.
- Deployment: Managed Kafka plus containerized services.
- GitHub proof: Streaming architecture and performance engineering.
- Description: Tenant-isolated backend with compliance-friendly audit trails.
- Architecture: Service-oriented modules + auth service + async jobs.
- Main libraries: FastAPI or Django, ORM stack, Celery, OpenTelemetry.
- Database: PostgreSQL with tenant isolation strategy.
- API design: Versioned tenant-aware APIs.
- Testing: Tenant isolation regression, security suite, smoke/perf tests.
- Logging/monitoring: Tenant-aware logs, SLO dashboards, runbooks.
- Docker setup: Multi-service compose with profiles.
- Security: OAuth2, JWT key rotation, secrets manager integration.
- Deployment: Blue/green or rolling deployment strategy.
- GitHub proof: Production architecture, operations maturity, security depth.
- Advanced typing (Protocol, TypedDict, generics), packaging, and error boundaries.
- Profiling and memory usage awareness for critical paths.
- Stable module boundaries and semantic versioning discipline.
- Apply SOLID where it improves maintainability.
- Prefer composition over inheritance unless inheritance is clearly justified.
- Implement Strategy, Factory, Adapter, and Repository patterns where practical.
- Correctly choose async IO for network-bound, multiprocessing for CPU-bound work.
- Prevent blocking calls in async paths.
- Validate synchronization behavior with race-condition tests.
- Stable contracts and explicit versioning.
- Consistent status/error models and idempotency guarantees.
- Pagination/filtering/sorting conventions and backward compatibility.
- Transaction semantics and isolation-level awareness.
- Index design and query plan analysis.
- Migration safety and rollback strategies.
- Test pyramid enforcement in CI.
- Integration tests against real infra (DB/broker/cache) with containers.
- Contract tests for service boundaries.
- AuthN/AuthZ with RBAC/ABAC enforcement.
- Strict input validation and output encoding.
- Dependency, secret, and container scanning gates in CI.
- Structured logging with correlation IDs.
- Trace context propagation across services.
- Alert thresholds tied to service-level indicators.
- Cache key strategy and TTL policy.
- Explicit invalidation and anti-stampede mechanisms.
- Hit ratio and stale read monitoring.
- Idempotent consumers and retry/DLQ policy.
- Message schema versioning and compatibility policy.
- Operational observability for lag and failure rates.
- Bounded context-driven decomposition.
- Contract governance and resilience patterns.
- Outbox/Saga patterns where consistency spans services.
- Pipeline stages: lint, type-check, tests, security scans, build, deploy.
- Environment promotions and rollback automation.
- Artifact immutability and provenance tracking.
- Hardened container images and health probes.
- Release strategies (rolling, blue/green, canary).
- Capacity planning, scaling, and on-call runbooks.
| Security topic | What to implement | Practical proof task |
|---|---|---|
| Authentication | Secure password flow, token lifecycle | Implement refresh token rotation and session revocation |
| Authorization | Resource-level policies | Add RBAC/ABAC checks and policy tests |
| JWT and OAuth2 | Claims discipline, key management | Integrate OAuth2 provider and rotate signing keys |
| Secrets management | No secrets in source/images | Integrate a secrets manager and CI secret scanning |
| Dependency scanning | Vulnerability and license checks | Add pip-audit and fail on high severity |
| Input validation | Strict schemas at boundaries | Reject malformed payloads with explicit error codes |
| SQL injection prevention | Parameterized query guarantees | Remove unsafe dynamic SQL paths |
| SSRF prevention | Outbound allow-list and DNS/IP checks | Harden external URL fetch functionality |
| Deserialization risks | Safe parsing only | Remove unsafe YAML/pickle patterns |
| Sensitive logging | Redaction and data classification | Add middleware-based log redaction |
| Rate limiting | Abuse and brute-force mitigation | Add per-IP and per-identity throttling |
| Secure Docker images | Minimal base, non-root, scanned images | Add Trivy scan and non-root runtime policy |
| Area | Beginner | Intermediate | Advanced |
|---|---|---|---|
| Python language | Typed modules and clean exceptions | Profiling-informed improvements | Package-quality API with strong tooling |
| OOP/design | Basic pattern usage | SOLID-driven refactor with clear rationale | Low-coupling architecture with explicit trade-offs |
| APIs | Working REST CRUD | Versioned APIs, robust error model, resilient client | Multi-protocol architecture and governance |
| Databases | Basic schema + CRUD | Indexing and transaction correctness | Query plan tuning and data evolution strategy |
| Testing | Core unit tests | Integration tests with real dependencies | Contract/performance testing integrated in CI |
| Concurrency | Async basics | Correct synchronization model selection | Benchmark-backed throughput optimization |
| Caching | Basic cache-aside | Invalidation and stampede prevention | Correctness and observability under failure |
| Messaging | Basic producer/consumer | Idempotent consumers + retry/DLQ | Schema governance + delivery semantics maturity |
| Security | JWT + password hashing | OAuth2, scans, strict validation | Threat modeling + secure SDLC integration |
| Observability | Structured logs | Metrics + tracing dashboards | SLO-driven alerting and incident response quality |
| Microservices | Basic service split | Contract and failure-aware communication | Distributed consistency patterns and ops maturity |
| CI/CD and deployment | Automated lint/test | Deploy pipeline with rollback | Progressive delivery and health-based automation |
- Beginner proof: one service repo with typed code, tests, and local Docker runtime.
- Intermediate proof: async workers, Redis cache, integration tests, CI quality gates.
- Advanced proof: multi-service system with telemetry, security controls, load test evidence, and deployment runbooks.
service-root/
pyproject.toml
src/app/main.py
src/app/api/
src/app/core/
src/app/domain/
src/app/repository/
src/app/services/
migrations/
tests/unit/
tests/integration/
tests/e2e/
docker/
.github/workflows/
docs/architecture/
docs/runbooks/
| Milestone | Deliverable |
|---|---|
| M1 | API skeleton + lint/type/test baseline |
| M2 | DB integration + migrations + repository tests |
| M3 | Redis cache + queue worker + retry policy |
| M4 | Security hardening + observability baseline |
| M5 | CI/CD and deployment docs + capstone release |
# Setup and dependency management
uv init
uv add fastapi uvicorn sqlalchemy alembic pydantic redis pytest pytest-mock httpx
uv sync
# Run API
uv run uvicorn app.main:app --reload
# Migrations
uv run alembic revision --autogenerate -m "init"
uv run alembic upgrade head
# Testing and quality checks
uv run pytest
uv run ruff check .
uv run mypy src