Deploy FastAPI
Run an ASGI API with Uvicorn and connect it to private application data.
FastAPI runs as a web service using an ASGI server. This example assumes the application object is app in main.py.
Prepare the application
Declare FastAPI and Uvicorn in your production dependencies, for example through requirements.txt or pyproject.toml. Add a simple health route:
from fastapi import FastAPI
app = FastAPI()
@app.get("/health")
def health():
return {"status": "ok"}
@app.get("/")
def root():
return {"message": "Hello from Openstead"}Commit your manifest and lockfile. Test the app locally with the same import path that the production command will use.
Create a web service
| Setting | Value |
|---|---|
| Build method | Railpack |
| Build command | Leave empty unless the application needs an extra build step |
| Start command | uvicorn main:app --host 0.0.0.0 --port $PORT |
| Port | 8000 |
| Health check path | /health |
For src/api/main.py, the correct module might be api.main:app with the appropriate working directory or --app-dir src. Adjust the import path to your package layout rather than keeping the detected default blindly.
Do not use --reload in production. Begin with a worker count that fits the selected memory and CPU, then measure before increasing concurrency.
Configure a database
Add the managed database's private connection details as environment variables. If you use an async driver, construct the URL in the format that driver expects; a generic PostgreSQL URL may need an application-level scheme adjustment for an async SQLAlchemy engine.
For Alembic, use the appropriate release command, commonly:
alembic upgrade headRun it as a paid pre-deploy command. Do not create or migrate a production schema automatically inside every application worker's startup hook.
Configure browser access
Set CORS origins explicitly when a separate browser frontend calls the API. Keep private database credentials out of frontend configuration. If the API receives traffic through a trusted reverse proxy, configure Uvicorn's forwarded-header behavior deliberately for the ingress you actually use.
FastAPI's generated OpenAPI and interactive documentation endpoints belong to your application. Decide whether those endpoints should be publicly accessible or protected; Openstead does not automatically apply your application's authorization to them.
Verify the deployment
Check /health, an authenticated endpoint, and a database-backed operation. Look for import errors, missing production dependencies, and failed lifespan initialization in runtime logs. Long-lived job processing belongs in a separate worker rather than a background task that must survive an application restart.