Creating a containerized Django + React + PostgreSQL... by Dan Taylor
Published October 25, 2019
This video features Dan Taylor, Elad Silberring, Laura Lorenz, Luan Fonseca, Noah Kantrowitz, Rachell Calhoun, Sergey Golovchenko, Tyler Jackson and Vince Salvino at DjangoCon US 2018 in San Diego, California, USA.
DjangoCon US 2018 - Lightning Talks Day 3
00:00 - Rachell Calhoun
03:48 - Vince Salvino
08:52 - Sergey Golovchenko
14:06 - Dan Taylor
19:20 - Noah Kantrowitz
23:56 - Tyler Jackson
28:26 - Laura Lorenz
33:11 - Elad Silberring
37:36 - Luan Fonsecca
Follow DjangCon US 👇
https://twitter.com/djangocon
Follow DEFNA 👇
https://twitter.com/defnado
https://www.defna.org/
The presenters cover a wide range of practical Django and Python topics. Rachel Calhoun explains how refusing to sign an anti-same-sex-marriage policy cost her a job, and how the Django community helped her find another; CodeRed CMS shows how Wagtail can provide a Bootstrap-based, WordPress-style marketing CMS with little or no coding. Sergey Golovchenko advocates having new engineers ship a small change on their first day, supported by automation, tests, reviews, monitoring, rollback, and structured onboarding, while Dan Taylor demonstrates installing and managing multiple Python versions, virtual environments, and Django development with VS Code on Windows. Noah Kantrowitz gives a concise DevOps glossary; Laura Lorenz describes moving a long-lived environmental information system from Perl toward Django; Tyler Jackson presents Easy Django Mockups for letting frontend developers prototype templates with JSON data; Elad Silberring demonstrates building a Chrome extension; and Luan Fonseca shows a Django management command for auditing REST API views for missing or incorrect permissions.
Summarised automatically from the transcript.
Automatically transcribed, so expect mistakes in names and technical terms.
Speaker 1: All right. Hi, my name is Rachel Calhoun. Um, my talk is How My Wife Got Me Fired. Spoiler alert, we're still married. Okay, so don't worry. Um so before I can kind of get that's my wife, her name is Dayong, she's great. Um So before we get started, my origin story. I graduated with a degree in Spanish and French. I didn't know what to do with my life, so I went to Korea and I taught English there for nine years. Um well I was there, I met my wife, but I thought, wow, I have to find a career. Like, what am I gonna do when I go back to the US? So I started um Oh yeah, sorry, oh man. Okay, so for I have four um foreign languages. I speak French, Spanish, uh I studied Arabic, and I speak Korean now and English
Speaker 1: Two bachelor's degrees and a travel agent. So I went to Korea, and this is me having fun with little kids. That's basically why I loved it. I love teaching. It was really fun, but I thought like what am I gonna do with my life after this in the US? Um so then um there were two people they were starting a Python users group or and so we met up every Saturday we'd do some online courses through Coursera or edX. And for about a year we studied all kinds of stuff with Python. And some of them were programm, some of them were programmers, some of them were just, you know, students that wanted to learn something new. And then I became an organizer, Jane Girl Soul. It was huge. It blew up. And uh since I was in a leader position, I was like, wow, I should take this more seriously, I should know what I'm talking about. So I started, you know, studying a little bit harder.
Speaker 1: And then I went to I got a scholarship to go to JaneCon Europe. And there I saw a talk about by Rebecca Connolly, who I now work with, about becoming a developer from Dancer to Developer and later in life transition. So I was like, I can do this. Um, and then Lacey, uh, sh if you know her, anyway, she encouraged me to do a talkat you know, um DjangoCon US. So I did. I applied a few talks and I got one accepted. So I did talk there on um Git inversion control. And um So I was like, you know, then we got married. I moved, you know, temporarily with my parents, and I had tons of application, job applications, a ton of interviews, and I had a job offer. I was like, yay, right? I made it.
Speaker 1: Um, so I got a lease, I moved there, and the first day of work, they gave me a code of ethics. They asked me to sign. And part of it said, I believe a marriage is only between a man and a woman. And obviously I couldn't sign this because I don't believe that. Um so it was very hard for me to give this up because I worked so hard to get my first job in tech. Um but I did. I told them I couldn't sign it and the next day they fired me. Um and it was totally legal and there's nothing I could do about it. And that's the same day we got the president we have now. So that day was really a rough day for me Uh yeah, but luckily this ended up to be a great pity story to some people here, and I told them about it and they helped me out. They stepped up, and that's why like this Django community is so important. important to me because they helped me and a couple weeks later I found another job remote and now um
Speaker 1: and they found my second job remote too. So people here are really important. So basically um It's an awesome community, so thank you. And you know who you are. But basically keep creating inclusive and supportive spaces and more importantly, vote. Thank you.
Speaker 2: So this is a new project that we just put on GitHub a few months ago. We've been using it internally for a while. Pip install code red CMS if you happen to have a fresh uh virtual Env hanging out. But this is a Wagtail-based uh CMS for marketing websites We really set out to build a viable WordPress alternative. We've been using it. Our clients have been loving it. So if you're not familiar with Wagtail, it's a great CMS framework. There's been a couple talks about it here So this is uh really all you need to do to get started. No coding required, just pip install and then the usual Django TDM, um migrate, create super user, run server, etc. So I'm going to do that right now. And um
Speaker 2: I've to prevent the Wi-Fi from bombing out, I've already installed it. So run server. Oh, that's weird. Let's see, thank you, PowerPoint Okay.
Speaker 3: There we go.
Speaker 2: Python uh manage PY run server. This is after a fresh pip install. And I'm going to go to my browser. Go to localhost 8000, nice empty website. Um this is you know familiar when you install Wagtail, you get an empty page. So let's go to the admin. I created a super user logged in. But we can go right away and start editing. So let's do a little bit of styling. Settings layout and we can add a logo. We'll do Django Con And uh maybe we want to change the navbar to a darker colored navbar. This is all based on Bootstrap, Bootstrap 4, so feel free to use Bootstrap 4 classes.
Speaker 2: Anywhere and let's check out oh there's our logo, a nice branded experience and local estate thousand. Cool, we got our logo there. Let's start editing the homepage. So out of the box, you know, we have custom page types, we have uh the stream field is loaded with blocks that you can start using. Um there's SEO attributes and all kinds of other stuff that you know it It's just there out of the box. But everything's based on the bootstrap grid system. So we'll add a actually let's add a hero unit. And do something a little bit flashier. Hero units, um, let's grab a background image. This is all meant to be very general purpose. and designed for specifically marketing websites, something you would probably use WordPress for
Speaker 2: and not be very happy about it. So let's just add some text. And let's make this a H2. Let's add a button below this. We'll just do a learn more button. It's not going to point to anything right now. And because it is bootstrapped, there's a lot of the bootstrap stuff that you're familiar with already built in. So we'll do outline light and we'll do large And let's preview what we have so far. Cool. We got our website going.
Speaker 2: Let's add one more thing since we still have a few minutes Let's add some cards. These are bootstrap cards. We'll uh just uh every all the bootstrap components are pretty much already built into this, so you can feel free to go crazy with it. Um Django, subtitle , Lorum Ipsum, um add a learn more button here as well. Let's add one more card. We'll add another button. And we'll do one final card before Kojo
Speaker 2: hits me. Um hitting.
Speaker 3: No hitting.
Speaker 2: I mean uh uh approaches gently caresses, maybe. Okay, so I added three cards, one without a button. Let's preview what we have so far. Woohoo, we got some bootstrap cards. So very quickly you can get up and running without having to write any models or any stream fields or any blocks and you can just start using Wagtail in a way that you would normally use WordPress. We got blog, we got forms, everything's in there. So check it out. Check it out. Good CMS. Thank you.
Speaker 4: Yeah, hi, my name is Sergei. It's my first time at DjangoCon. Yeah. Yeah, I work at Rover and today I would like to talk about onboarding new engineers. Uh if you seen this movie, you probably know the first rule of Fight Club is you do not talk about fight club, so is the second rule. But What's the eighth rule of Fight Club? Anyone? That's right. If it's your first night at Fight Club you have to fight. So at Rover If it's your first day as a software engineer you will code and chip to production. Why? Some people might ask Um I think it's cool and it's rewarding and it's exciting.
Speaker 4: If you like me, software engineer, you like to code. So that's why You got this job not to fill HR paperwork, not to configure your environment all day, but you you code and you ship. And you see results right away. Um and you also get uh familiar with the code and with the with the process. And it's also not rewarding, not rewarding not only for you, but it's rewarding for the whole team Um this is a screenshot from Slack. Someone did their first deploy. See the reaction from the whole team. Everybody happy. So, what about initial environment setup? You still have to do it. Um configuration credentials, um installing dependencies, yes you still have to do it. That's why you have documentation.
Speaker 4: You have to document the process. And if you documented it, chances are you can automate it So you can script the whole thing. If somebody is really curious how like what it's doing, they can always look. Of course, you have your favorite ID, but if it's your favorite ID, you know already how to set it up. So you can do it quickly Get done with all this stuff and get to code. Is it risky? Of course it is risky. You you have a person who doesn't know much about your system shipping the code on the first day, but guess what? Somebody who's been with the company company since beginning can also ship code that will break everything. So um we need to minimize this risk. We have to build our process around it so that there is less risk. And how to do it? You start with a small ticket.
Speaker 4: Small I mean not just lines of code, but actually the scope. Like it could be like a text change. It could be like a Like a link change, it could be like you remove one unused function or you refactor a function. Uh use commit hooks. Uh this will help you quickly find things like really really small things like if your code doesn't comply with the coding standard. standard. Um use automated uh continuous deploym um CI C D so our CI C D pipeline is about fifteen minutes from the merge Till your code shows up in production. But before you merge it, we're gonna run the tests on on your commit. So every commit triggers a build and we run all the tests. And for that you have to have the test. We have over thirty thousand tests
Speaker 4: and with uh eighty-nine percent coverage, so we're not hundred percent, but we're trying to get there. Um Do code reviews. If you don't do it, just do it. And you have to have monitoring in place. So after all this, after all these tests and all the code reviews Uh bugs and uh defects can still make it into production, and you have to have a system in place where something will trigger an alarm and something will tell you, okay. Um stuff is broken. And there are two kinds of monitoring. There is kind of like DevOps sort of monitoring where you know like your endpoint is all of a sudden became slow or there are too many queries running And there are also business metrics kind of
Speaker 4: monitoring where all tests are passing, everything is fine, your endpoints are much faster, but all of a sudden you have half as many bookings. So maybe that's why everything fast. Um and you have to have the ability to quickly undo the change. And it's not just the revert, but it would be very nice, and we do have it, to roll back to the quick to the previous build. Like I mentioned before, the CI CD pipeline takes about 15 minutes, but sometimes you need just instant go back to the previous state of the world. So you fixed a small ticket on the first day. Now what? Do you know everything? Of course you don't. That's why we have more of more onboarding things. We have formal onboarding program which lasts four days and spread over two weeks and it does not start on the first day.
Speaker 4: We have formal pair programming program where you matched with an experienced programmer. experience in terms of in terms of tenure at Rover and once one hour per week you just spend working together on a ticket and we have team rotations. So in conclusion, I would like to say like if you want to your engineers to be effective, productive, and get up to speed quickly, just put some effort into your onboarding program. And if you want to experience all this first hand, Rover is hiring.
Speaker 2: Thank you.
Speaker 5: All right, so hi everyone. Thank you for uh having me up here today. I'm Dan Taylor, I'm a program manager for our Python developer tools at Microsoft. And I saw some people struggling with uh running Python on Windows uh yesterday at the conference, so I was motivated to come up here and share with you some tips about running Python on Windows. Uh and also uh as a bonus, show you how to use Visual Studio Code with Python on Windows uh because uh a lot of people are interested in doing that these days and it 's a lot of people happens to work particularly well. So why do we care? So uh Koja just mentioned that uh he's surprised by how many people use Python on Windows. So if you look at the uh Python Software Foundation survey actually about half of Python developers are using Windows Now not half of people in this room are using Windows, so it's a good uh reason for me to come up here and share with you a few tips. So how do you use Python on Windows? First you need to install it.
Speaker 5: So to install Python on Windows, go to python. org slash downloads And so there's a number of things you can click on on this page. I like to click on the uh download link down here, and I'll show you why in a minute. Uh the other thing you can do is you can go to python. org and uh you can click the latest uh download link there. And then after you click that link, you're given a list of options to choose from. Don't worry, there's there's about you know eight different options for Windows. Go for the executable installer. And in particular I like to pick 64-bit because I've run into many situations where I'm doing data analysis on Windows and I run out of uh run out of address space with a 32-bit version. Uh so after you do that, what happens? Okay, we get this nice installation prompt which says install now. And uh if you click the uh customize installation, just a pro tip, you can install the debugging symbols uh for the Python installer, which allows you to do
Speaker 5: to do cross language C<unk> and Python debugging if you have Visual Studio. I'm not going to show that today, but there's another talk you can watch on that Uh one thing you might be tempted to check that box that says add Python 3. 7 to the path. No, don't do that. Why? Because you might have multiple versions of Python installed and then you're going to be messing with your path to try and get them to work. So I'll show you some tips about how to deal with that. In a minute. Now, before we move on, a couple other helpful things you might want to install. Git for Windows. So Git for Windows gives you everything you need to do to do to do source cloud code control. And uh it also includes a git bash prompt which lets you do familiar things like RM and LS and all sorts of things that you might be doing out of habit when working with bash. And then after you go there, go to code. visualstudio. com and hit the bright green download button, which gets you VS Code.
Speaker 5: And there's a number of different extensions for VS Code. The Python extension is the fastest growing extension and the most popular extension in the Visual Studio Code marketplace. Visual Studio Code is extremely popular with Python developers. So uh for Python developers you get all sorts of things like IntelliSense, Linting, debugging, refactoring, unit testing, live share, source control, Azure integration, and Docker support. And then That's said enough. I'm going to go right into a demo. So you've got a quick command prompt on Windows. Uh let's go right into that. Oh, my mouse is jumping all over the place. There we go. Okay, tiny little font. First thing we want to do is increase that font size. Go to properties. There, font 36. Wonderful. Alright. So the first thing I would like to do, Python launcher, PY, that launches whatever version of Python you have installed and it tries to pick
Speaker 5: the best one. If I type Py dash 0 it shows me all the versions of Python I have installed. So if I want to run Python 2, I type Py dash 2, I get Python 2. Isn't that wonderful? If I want to run Python 3. 7 32 bit, I do Py dash 3. 7 Dash 32. And now I'm running Python 3. 732 bit. Awesome. Now I want to create a virtual environment. Py-3 -m uh vem, I'm gonna run the Venv module and then create A virtual environment called my AMV. So what's happening here? This is creating a virtual environment. It's creating a copy of the Python runtime with a copy of the site packages so that you can start with an environment that has the exact business of Python that you want, uh as well as install just the packages that you you want to get started. Once you have that uh myenv installed, I'll switch over to another command line here.
Speaker 5: You can say env scripts activate. to then activate that virtual environment and then I can type code dot to open Visual Studio Code. Cujo 's gonna give me a hug anytime now. All right, now that we're in Visual Studio Code, I can open a uh Python file. Uh I've already installed the Python extension. And there's a few different things that I get with that. My virtual environment shows up in the command line or in the status bar. I can click that and I can switch between other virtual environments or other Python, Anaconda, or other installations I want to use. I can install Pylant, but I'm going to forget that for now. Just want to show you that IntelliSense works here. Uh there. And if you want to debug, we can click add configurations here. And we can debug this using
Speaker 5: Django in a minute. Click the Django button, press play, and we're off and running. So obviously I didn't get through all of that, but uh just so you know there's also you can run Python on Ubuntu on Windows if you type Ubuntu into your start menu prompt, install Ubuntu, follow the instructions, and there you go. Thank you so much. There's my Twitter slides. Have a great day.
Speaker 6: Hi, I'm Noah, and I'm here to talk about what all of these words mean a DevOps glossary. I'm Noah, I work for Ride Cell, moving on when I have much time. Uh if you've been in one of my talks before, I talk So what's a virtual machine? Close to the mic? Uh okay. Um what's a virtual machine? Virtual machines are running on simulated hardware. These days it's not usually actually simulated, but close enough. What is a VM image? This is the disk that is going to be part of a virtual machine in the future. So it's all the files that will go into a future virtual machine. Vagrant, a bit old school now, but it's a tool for making local development virtual machines. Cloud is someone else's computers, usually located somewhere in Virginia. AWS is the most popular cloud vendor. EC2 is the Amazon product for virtual machines.
Speaker 6: S3 is their Amazon product for file storage or one of them. CloudFormation is the Amazon product for managing other Amazon products. Terraform is like CloudFormation, instead of just for Amazon, it's for lots of clouds and it does a lot more stuff. Probably use Terraform. GCE is Google's cloud, and Azure is Microsoft's cloud. Yes, you can run Linux on Azure, it's quite nice. OpenStack is like a cloud, except you also have to run it yourself. A container is a cool way to run a process. All it is is a process with a bunch of security flags so that your process can't see certain things on the system. That's it. That's all a container is, I promise. A container image is the larval form of a container. So it's a tarball containing all of the files that will go into a future container, just like a VM image is all the files will go into a future VM. Docker docker docker is not the only way to make containers, but it is the most common.
Speaker 6: A Docker file are the steps to make a Docker image, which you use Docker build to actually turn into a Docker image or other tools, but usually Docker build. There was a great talk yesterday by Graham on uh Kubernetes. Check out the video if you didn't see it, because I'm not going to go over it in nearly that much detail because I have three minutes left. Swarm was Docker 's internal attempt at making a multi-server container thingy, but Kubernetes is a lot more popular, so probably don't use Docker Swarm anymore. Sorry to anyone that likes it. Compose is the much smaller case, so just if you have a couple of containers on one server and you want to manage just those, Docker Compose. Orchestration is a general term for all of those things like Kubernetes and Compose for coordinating a whole bunch of containers into doing something useful. Resource scheduling is figuring out how to place a container on multiple servers. So you have if you have constraints like
Speaker 6: I have this much RAM available on this much server and this much on the other server, where do I put my container? That's resource scheduling. Serverless or functions as a service or AWS Lambda, it's a way to write APIs less boilerplate. That's basically it. Uh some of them expose things like if you write a single function, it'll expose it as a REST API. Some of them are just If you've got a Django app, I'll expose that easily. But all under that general category of less boilerplate because who likes boilerplate? CI does not mean continuous integration anymore. I don't know anyone other than Microsoft that still actually continuous integration. Continuously integrates, it means continuous testing, but we still call it CI for some reason. Uh pipelines are a way to organize complex test environments, test suites. Test stuff in general for your CI system. Jenkins is the most popular of the CI tools, although it's a bit cranky at this point.
Speaker 6: Travis is a newer one. You'll probably see it in a lot of open source projects because it's free for open source. Continuous delivery or continuous deployment just means if the tests pass, it goes out to production. Exactly what that means can vary depending on the environment, but something like that. Big data, I use 10 terabytes as the threshold, but in general it's trying to run a query on more data than fits in any one of your servers. Hadoop is a very popular set of tools for running big data queries, and Spark in particular, if you see that one, is a thing that is used a lot for running the queries themselves. Hadoop also includes stuff for like storing big data and all that kind of thing. ETL extact transform load is a name of a pattern used in big data for extracting data from usually a relational Postgres MySQL whatever database, transforming it in some way with MapReduce, and then loading it back into an analysis database.
Speaker 6: Switching gears to security in my last 60 seconds. InfoSec is keeping your data safe. Black hats are the bad people, white hats are the good people. Red team are the people that are doing attacking and offensive things, but they have permission. They are good people that are doing it for the benefit of everyone. Blue team are the defenders and purple team are the for people that do both. And very quickly, a hash is a one-way function, so given the output you cannot find the input, whereas encryption is reversible, but only if you have the right key. And thank you very much. If you have any questions, come find me after.
Speaker 7: I'm just really impressed by the organizers. I've organized non-technical events of several hundred people. I know how much work goes into this process, so just thank you very much for putting such a welcoming event together. Um so I'll introduce Lauren Silvermore very briefly for those that aren't familiar. We are a multi-program national security laboratory We work on national security needs for the United States. We also work on fundamental science research, and so a lot of different areas coming together. Uh Kojo mentioned, what is it that Livermore Labs does? I don't even know everything that we do. We have 7,000 employees and countless projects. Uh it's a pretty fun place to work. We're hiring. Um and so I work in the computation division. I work in a division called Application Simulations and Quality, which works on two very different areas, which is
Speaker 7: Massively uh parallel high-performance computing simulations and web development. Um and so what uh the environmental restoration department focuses on is Environmental remediation, so cleaning up historical contamination at the site that is developed through years of different uses that the lab has gone through. And so we have an application that we call it Times. It's the Environmental Information Management System. It's a data management application support. We use it for sampling, monitoring, analysis, and reporting. There's a probably over a hundred individual applications within this suite that we've developed over quite a long period of time And so we began using Ingress with C and terminal access, and then began moving to Perl, which we've been using for over 20 years now, and has grown to quite a large
Speaker 7: uh Development platform. And so um we also moved to Oracle in that same timeframe and We're anticipating like environmental restoration at the lab is gonna be around at least until 2075. So I'll see you all at DjangoCon 2075. And we wanted to move to a more sustainable platform. Perl is pretty much Yeah. And so we have about eight developers on our development team working on Django now. And so just a high-level approach to what we're moving towards. is we have an existing Oracle 12C database. We have several hundred tables across multiple schemas. We're using Django 1. 11 right now. We've integrated it with Active Directory resources.
Speaker 7: Love the Django Rest framework. Uh it's an excellent tool. We love it a lot. Um of the biggest improvements for us in our development histories, we're moving to unit testing and we're moving to functional testing and continuous integration, which I've learned. Just recently, maybe not means what I think it is. Um and so the cr primary technologies that we're using right now are like Python, Django, Kendo UI. Um Just a smattering. And so one of the goals of coming to DjangoCon for me was to just meet people. I really wanted to network and I really wanted to see how many different projects there were using Django. And so I just wanted to give this opportunity to kind of share a little bit about what we've done as well and maybe prompt some conversations in the hall afterwards.
Speaker 7: And so I'll talk a little bit about why we decided to go this route. It's gone pretty similarly to uh COBOL. It's getting a little hard. And Python is very popular. It's easy to read maintain. We love developing in it. The data science support is excellent. Although we have this application suite, we also have a wide variety of scientists developing their own data science scripts. And so it's very easy to integrate that together with what we have. We're developing applications much more quickly. Uh love the ORM in moving away from some extremely complex SQL that I have spent days trying to understand what they did. And uh the plugins and really the community. I I love the community here. It's been excellent to uh learn from different people
Speaker 7: And some of the biggest challenges we faced, and so I'm not sure if this is the same for everyone, is we had to bring our database with us. And so we have several hundred tables, and so a lot of problems that we've run into are just supporting the legacy. Side of things. They're unmanaged, and so we've had some permissions kind of come up there. And but overall, Django's been excellent. And so I just want to take this opportunity to share what we do. And so thank you. Uh
Speaker 8: I was surprised to see how emoji-friendly this was, so I thought I would put up my favorite emoji while I was doing this. uh because I also am 99% demo, 0% slides, 1% emoji. So uh what I want to talk about is a little Django app that my team built a couple weeks ago on WoW Day, which is work on us Wednesday when we try and make stuff that makes our lives easier. Our issue was that we were having a hard time between front-end and back-end describing our requirements for data structures that needed to pass between them so um we would have some nice uh like ux mock ups um from uh sketch or balsamic But that didn't always translate 100%
Speaker 8: to what was possible in the back end, not to mention that um sometimes it wasn't really self-evident. Uh we have a group of um front-end developers who have experience working with with the Django templating language. So they really like designing in browser themselves, but they don't always have the models that they need access to when we're we're developing a new feature. So what would start to happen is they would ask us for like sort of a vague thing and we would build like seed them a branch that had a piece of it and then they would start designing in browser and then they would be like, wait, I need this other thing. And then we were like, oh, we were working on something else. Like we'll get back to you later. And anyways, there was just a lot of communication issues. So what we came up with was a bit of an easier way for them to kind of just do that themselves.
Speaker 8: Basically, we developed this um little Django app called Easy Django mockups uh that you can use to um basically if you put your HTML files, which can use whatever Django templating uh stuff in this folder mockups or configure it yourself where you say it's going to be in your templates wherever your template loader is going to find it, then we will automatically go find uh where that is and render it for you um at this mock-up slash whatever the name of your template is and um uri and then you can see the thing that you made So one other thing that we included is that you can add a JSON file that's named after the same thing. So you can arbitrarily build out some data structure just in JSON. that you can then access.
Speaker 8: In this case I have the this here things key with this list of um thing one, thing two named. Uh but you can see that I'm just iterating over that here as if like I had received this in the context and this way the front end developers can just totally do this themselves. They already know you know how to write valid JSON so we don't have to do any of this back and forth. And then once they're done with that project, they can kind of show us this. And now we have something to take sort of to the back end and build out all of the other stuff in terms of models. And then we can just sort of plug that into that template that already exists. exists. So a little bit about the thing itself, which we're in the process of pulling out of our monolithic Django codebase um for the purposes of open sourcing it and also as an experiment for ourselves to make um
Speaker 8: Django apps separately so we could also break up our real monolithic one privately sometime. Um but yeah it's pretty it's pretty simple. Uh we'll peel off whatever this URL has to say to try and go detect what uh these template files are named and these JSON files are named. Um in our view here, uh we have some stuff to sort of Check where your mock-ups directory is or if you want to see JSON errors propagated to the front end. We're using the Django messaging framework. So for example, if I go back up here and mess up my JSON a little bit. So messed up. Then over here kind of surface some of that here for uh the front end and just trying to take advantage of some Django stuff that already exists to make that like totally like a browser, in browser experience as much as possible.
Speaker 8: But yeah, basically just detecting some stuff there. in our views, you know, we abstracted it away a little bit to this mock-up object, but basically can go use all that stuff it's figured out to render what this request is with the template that should be named after uh whatever the URI is. And the oh god. The um ah woo. Um and the JSON file that's named the same. So yeah, just trying to make it a little magical. In conclusion, I learned that there's other types of ghost emojis, and I decided that the Samsung one is my number two, but my Apple one is still a number one. That's it.
Speaker 3: Thank you very much. All right, um so my name is Aladd Silbering, also
Speaker 5: first time here, enjoying it very much. I would like to thank my company for bringing me here. Um a developer at US News. Um it's a news company and that does rankings and the DC area. And you guys for coming and hearing and seeing and And talking and drinking and whatnot was fun. Um all right, so what is a Chrome extension? So very shortly to put it, a Chrome
Speaker 6: extension is actually something that um interacts with your browser activity um that you want to customize.
Speaker 8: So if you want to do something different other than what your browser would normally do. on a page and there's tons of them. The number one I think is a ad blocker. Yeah. I have no idea what the number two is, but I think everyone has a ad blocker. Okay. Uh so what do you need to start? You need um to know basic CSS, JavaScript, and HTML. Um that's then N next talk in five minutes. I'm kidding. Um, have an idea. Create a manifest file, which is kind of a settings file for a Chrome browser. Uh create the UI and the JavaScript function.
Speaker 8: What should I do? You need to do something fun. You need to do something that's usable. Uh and if this is not like for learning purposes, you should do something that solves a problem. And keep in mind that list is more and that's also a good thing to keep in mind. mind when you're developing anything, whether it's Python, Django, JavaScript, HTML. These things should always be on in your mind when developing, in my opinion. So this is a manifest file and we'll go shortly through it. The version is gonna be two, that's like the uh extension framework version. You're gonna give it a name, description.
Speaker 8: This is actually what would pop up when you open the extension page and that's gonna be the description. It's kind of like a SEO for your site. So this is all the tags and add words and where you use your where the image is coming from. Also, this is where you ask permissions from your use the users, so you can take control of like the camera, the microphone, and whatever. The UI. This is basic HTML CSS all packed into one slide. So you can just copy paste it. By the way, this is all. You can copy paste it, put it in the manifest. json. This is exactly what I did. Copy pasted this, put it in in pop -up HTML. Then I copy pasted this.
Speaker 8: This is the actual JavaScript. I also added a JavaScript file that was just jQuery. And this is uh what's actually happening So in short, I'm taking uh CSS style and adding it to each anchor tag that's uh between one and ten words, uh letters, sorry. The hard part deploying. You have to drag extension into browser. Uh yeah, so this is The extension page. Um I don't have the correct permissions, so for some reason I can do it, but you can see you can drop to install. Since my doesn't work, I
Speaker 8: have to load it for whatever reason and that's it I have it now we try it out so this is a wiki link apparently yes there's a wiki page about buffalo buffalo buffalo buffalo buffalo buffalo buffalo and uh this is what it does makes your anchor tags jump very useful
Speaker 3: So sometimes authentication is like, oh, you put this thing, this line inside your code, and then magically you have authentication running. But there's an issue in there because
Speaker 7: Sometimes we don't test every single page that we had. Like if we are using normal authentication, just a token authentication for High Framework API.
Speaker 3: And you
Speaker 7: start to create groups of users
Speaker 3: and then you need to assure that certain group should only see some views and then it starts to go up as soon as your project is starting to grow up. Sometimes no one or one some time um sometimes someone is reviewing your PR or something and it may be not that Like well
Speaker 8: how can I say that
Speaker 3: not though not that good to review your code and sometimes some view can pass through the reviewing process and The code will be deployed and will be a leak on your endpoint API rest framework or something. Sometime you need to QA this and need to assure that every view is okay, is having permissions and authentication and stuff I had that 2QA and any point and then I was like, oh, view per view and looking, oh, this permission is wrong. And I, okay, this permission is wrong, we need to fix it. it but if the project s is bigger it's not sustainable anymore and you need to programmatically do that. Yeah sometimes means usually almost every time because we are humans And what I did was this.
Speaker 3: I created a command for Django Management. And then you can pass an app. It's nice because you can use Third party apps like Hast Off. And then you can see which holes they had in their codes. Because if you're using this group of users, they just do regular authentication. So it's kind of leaky. And you need to extend the view and fix it by yourself. Okay, what's the real outcome of that? You have the view name from your file and which permissions they are using. Which is nice. We can get so much main information from it, like authentication classes that we are using, parent classes that in here here it's from this like some custom permission, iterates from other permission classes that should have holes in there
Speaker 3: too. So the code is like really ugly because it's to make it work as a proof of concept. But we are using uh in this call command show release is from a third third part library called jung extensions which is awesome And then we I went to each endpoint for endpoint and got the view and from the view I got the permission classes and played and just printed. So it's really a 10-minute job, so it's awesome. Okay, you can install it if you wanted to use in your your Django project, but in fact you can because I didn't deploy it at PyPy. So you can use it, use it, use it, really use it. But I have a bit. ly that you can grab the snippet that I wrote.
Speaker 3: And and I think that It's really easy to use it because it's just a one command line and probably should be a check, like for you to put in your continuous integration stack like Oh, run the Python manager. py, manager. py, check, and it will check for the permission and see, oh, this view has no permission at all. So it really should be open as it is, like a login. Then the point or not. So that's what I did one in the morning. And in fact, I did it in this morning because I lost this code that I wrote back then. And then I need to rewrote it, but it's okay. And thank you, obrigado. It's from Brazil, Portuguese. So my name is Luan Fonseca. You can follow me on almost everything is like Luan Fonseco
Speaker 3: with C because someone took the Fonseca with S so I need to put and see and now um it's Fonseca. It's my first Django Con in fact too. Thank you.
Her employer required her to sign an ethics statement saying marriage is only between a man and a woman. She refused to sign it because it conflicted with her beliefs, and the company fired her the next day.
Discussed at 2:40CodeRed CMS is installed with `pip install code-red-cms`, followed by the usual Django setup commands such as `migrate`, creating a superuser, and running the server. It provides a Wagtail-based, Bootstrap-powered CMS for marketing sites without requiring users to create models or StreamField blocks from scratch.
Discussed at 3:52Start the engineer with a very small ticket, use commit hooks, automated tests and CI/CD, code reviews, monitoring, and fast rollback capability. The speaker also recommends documentation and scripted environment setup, followed by formal onboarding, pair programming, and team rotations.
Discussed at 11:03Install the 64-bit executable installer from python.org, and avoid adding Python directly to PATH when multiple versions may be installed. Use the Python Launcher, such as `py -2`, `py -3.7-32`, or `py -0`, to select and inspect installed versions.
Discussed at 14:57Run `py -3 -m venv myenv`, activate it with `myenv\Scripts\activate`, and open VS Code with `code .`. The Python extension lets you select the virtual environment and provides features such as IntelliSense, linting, debugging, refactoring, and testing.
Discussed at 17:42A virtual machine runs on virtualized hardware, while a container is a process isolated with security restrictions. A VM image contains the files for a future VM, and a container image is a tarball containing the files for a future container.
Discussed at 19:25In this talk, CI is used mainly for continuous testing through organized pipelines, even though the acronym traditionally means continuous integration. Continuous delivery or deployment means that code is sent to production when the tests pass, with the exact process depending on the environment.
Discussed at 21:42They wanted a more sustainable platform for an application expected to be maintained for decades. Python was easier to read and maintain, accelerated development, integrated well with data science, and provided useful tools such as Django's ORM, plugins, and community support.
Discussed at 27:10The team had to support an existing Oracle 12c database with hundreds of tables across multiple schemas. Because many tables were legacy and unmanaged by Django, they encountered issues involving permissions and other parts of maintaining the existing system.
Discussed at 27:58The Easy Django Mockups app discovers HTML templates in a configured mockups directory and renders them at URLs based on the template names. A same-named JSON file supplies arbitrary context data, allowing front-end developers to design and test templates without waiting for back-end models.
Discussed at 30:03You need basic HTML, CSS, and JavaScript skills, then create a `manifest.json`, build the UI, and add the JavaScript behavior. For local testing, open the browser's extension page and load or drag the extension into the browser.
Discussed at 33:57The speaker created a Django management command that takes an app, inspects its endpoints and view classes, and prints the permissions and authentication classes being used. The command can reveal views with missing or incorrect protection and could be added to continuous integration as a project check.
Discussed at 37:18Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.
Published October 25, 2019
Published October 25, 2019
Published October 25, 2019
Published November 22, 2023
Published October 25, 2019
Published October 23, 2025
Published July 10, 2024
Published November 22, 2023
Published June 13, 2025
Published December 6, 2024
Published July 19, 2024
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 14, 2026