Source Catalog
Chapters cite the specific pages that support version-sensitive claims. This catalog records the primary authorities used across the repository and the topic each one governs.
Python and protocols
- Python documentation: language, typing,
asyncio, multiprocessing, logging, and standard-library behavior. - ASGI specification: application and server interface.
- HTTP Semantics, RFC 9110: methods, status semantics, fields, and caching terminology.
- HTTP Caching, RFC 9111: cache behavior and validators.
- OAuth 2.0 Authorization Framework, RFC 6749: protocol roles and grants.
- JSON Web Token, RFC 7519: JWT claims representation.
FastAPI stack
- FastAPI documentation: routing, dependencies, security helpers, response handling, deployment, and testing.
- Starlette documentation: ASGI middleware, requests, responses, lifespan, background tasks, WebSockets, and test client behavior.
- Pydantic documentation: Pydantic v2 validation, serialization, settings, fields, and model configuration.
- Uvicorn documentation: ASGI server settings, process management, proxy headers, and deployment behavior.
Data systems
- PostgreSQL documentation: SQL behavior, constraints, indexes, MVCC, transactions, locking, and query plans.
- SQLAlchemy 2.0 documentation: Core, ORM mappings, sessions, async extension, relationships, and loading.
- Alembic documentation: migrations, autogeneration, operations, and cookbook patterns.
- Redis documentation: data types, expiration, transactions, persistence, clustering, and client patterns.
Security
- OWASP Cheat Sheet Series: practical controls for authentication, passwords, sessions, file uploads, logging, secrets, REST, and webhooks.
- OWASP API Security Top 10: common API risk categories and mitigations.
- NIST Digital Identity Guidelines: identity proofing, authentication, and federation guidance.
Deployment and operations
- Docker documentation: image builds, Compose, runtime, and build best practices.
- NGINX documentation: reverse proxy, TLS, buffering, and upstream configuration.
- OpenTelemetry documentation: signals, context propagation, semantic conventions, collectors, and instrumentation.
- pytest documentation: fixtures, parametrization, monkeypatching, and test configuration.
- Celery documentation: workers, tasks, retries, routing, and schedules.
- RabbitMQ documentation: exchanges, queues, acknowledgements, reliability, and consumer behavior.
- Apache Kafka documentation: topics, partitions, offsets, consumer groups, and delivery model.
Cloud concepts
- AWS Well-Architected Framework: operational, security, reliability, performance, cost, and sustainability review concepts.
- Amazon ECS documentation: managed container scheduling concepts.
- Amazon RDS documentation: managed relational database operations.
- Elastic Load Balancing documentation: health checks, listeners, routing, and load-balancer behavior.
- Amazon S3 documentation: object storage, multipart upload, policies, and lifecycle.
OpenAI and AI backends
- OpenAI developer quickstart: SDK and Responses API starting point.
- OpenAI streaming responses: Responses API streaming event model.
- OpenAI background mode: long-running provider-managed responses.
- OpenAI webhooks: events and signature verification.
- OpenAI vector embeddings: embedding requests and similarity concepts.
- OpenAI production best practices: project, security, scaling, and operational guidance.
Citation policy
Use the canonical project documentation or specification for externally verifiable behavior. Architecture recommendations are identified as decisions and include assumptions rather than borrowing authority from a citation. A source link is checked for relevance before merge; it is not evidence merely because it is official.
The web changes. When a cited API changes, update the explanation and example together, then run the repository quality checks.