openstead
Guides

Deploy FastAPI

Run an ASGI API with Uvicorn and connect it to private application data.

Suggest a change

FastAPI runs as a web service using an ASGI server. This example assumes the application object is app in main.py.

Prepare the application

Declare FastAPI and Uvicorn in your production dependencies, for example through requirements.txt or pyproject.toml. Add a simple health route:

from fastapi import FastAPI

app = FastAPI()

@app.get("/health")
def health():
    return {"status": "ok"}

@app.get("/")
def root():
    return {"message": "Hello from Openstead"}

Commit your manifest and lockfile. Test the app locally with the same import path that the production command will use.

Create a web service

SettingValue
Build methodRailpack
Build commandLeave empty unless the application needs an extra build step
Start commanduvicorn main:app --host 0.0.0.0 --port $PORT
Port8000
Health check path/health

For src/api/main.py, the correct module might be api.main:app with the appropriate working directory or --app-dir src. Adjust the import path to your package layout rather than keeping the detected default blindly.

Do not use --reload in production. Begin with a worker count that fits the selected memory and CPU, then measure before increasing concurrency.

Configure a database

Add the managed database's private connection details as environment variables. If you use an async driver, construct the URL in the format that driver expects; a generic PostgreSQL URL may need an application-level scheme adjustment for an async SQLAlchemy engine.

For Alembic, use the appropriate release command, commonly:

alembic upgrade head

Run it as a paid pre-deploy command. Do not create or migrate a production schema automatically inside every application worker's startup hook.

Configure browser access

Set CORS origins explicitly when a separate browser frontend calls the API. Keep private database credentials out of frontend configuration. If the API receives traffic through a trusted reverse proxy, configure Uvicorn's forwarded-header behavior deliberately for the ingress you actually use.

FastAPI's generated OpenAPI and interactive documentation endpoints belong to your application. Decide whether those endpoints should be publicly accessible or protected; Openstead does not automatically apply your application's authorization to them.

Verify the deployment

Check /health, an authenticated endpoint, and a database-backed operation. Look for import errors, missing production dependencies, and failed lifespan initialization in runtime logs. Long-lived job processing belongs in a separate worker rather than a background task that must survive an application restart.

Need a hand? Contact Openstead support.

On this page