The path to a professional AI engineerPro

Python for AI Career

A six-month career track — a professional environment with uv, clean code, OOP, testing, FastAPI, RAG on pgvector, security, Docker, a React client and a full capstone project. Six steps and a ten-question quiz in every chapter.

The six steps in every chapter

  1. 1Encounter
  2. 2Understand
  3. 3Worked
  4. 4Predict
  5. 5Apply
  6. 6Stretch

This course is Pro

The chapter list is open to everyone — you should be able to see what is taught before deciding. Reading the chapters needs Pro.

See Pro
  1. 01The AI engineer track, and dev environments with uvProInstalling Python, why uv instead of pip, and an isolated, reproducible environment for every project with uv init, uv add and uv run — plus the right interpreter in your editor.35 min10 questions
  2. 04pathlib, JSON/YAML config and environment variablesProin-reviewPaths that work from any folder with pathlib, nested JSON and YAML config, .env and environment variables — and a config loader that stops at the start when a value is wrong.40 min10 questions
  3. 05Lists, dictionaries, sets, loops and comprehensionsProin-reviewWhen to use each of Python's four containers, loops and conditions, comprehensions, and counting words in messy tickets to find a top five that comes out the same every time.40 min10 questions
  4. 06Functions and error handlingProin-reviewSplitting a monolithic script into small, testable functions — pure functions, *args and **kwargs, scope, try/except/else/finally, and your own exceptions to handle a missing file cleanly.40 min10 questions
  5. 07Data validation with Pydantic and JSONProin-reviewData from outside is a claim, not a proof. Validating at the door with Pydantic v2 models: silent type coercion and strict mode, field_validator, and JSON in and out.40 min10 questions
  6. 14Memory management and resource leaksProin-reviewReference counting, reference cycles and gc, Python's real leaks — unbounded caches and lru_cache on methods — and using tracemalloc to find and bound the leak in a long-running worker.45 min10 questions
  7. 15Mutation bugs and state managementProin-reviewMutable objects, aliasing, the default argument trap, shallow versus deep copies — and chatbot state built with frozen dataclasses so one user's messages cannot reach another.40 min10 questions
  8. 18Refactoring legacy code — better structure, same behaviourProin-reviewRecognising code smells, capturing current output with a golden master, safe renaming, constants and extract method — and cleaning up a token-billing script step by step, verifying every step.45 min10 questions
  9. 19Hands-on lab: refactoring a legacy pipelineProin-reviewA wrong ticket pipeline with a memory leak, mutation bugs and unclosed files — from symptoms to causes, fixing one at a time, then refactoring into classes and proving the output is right and memory bounded.50 min10 questions
  10. 20Milestone 2 review — the refactored pipelineProin-reviewA review rubric for refactoring PRs, reading a unified diff, proving hidden regressions with a check script, labelled review comments, and receiving a review as the author — deliverable 2.45 min10 questions
  11. 21Testing fundamentals with pytestProin-reviewUnit versus integration tests, adding pytest with uv, reading assert's detailed report, pytest.raises, and writing a full test suite for a Pydantic model with fixtures and parametrize.45 min10 questions
  12. 22Deep debugging with pdbProin-reviewReading a traceback from the bottom up, stopping a program with breakpoint() and python -m pdb, stepping through it, moving between stack frames, and using post-mortem debugging to find and fix a silent logic bug.40 min10 questions
  13. 23Mocking and test isolationProin-reviewReplacing external APIs with controlled stand-ins while tests run: MagicMock, return_value and side_effect, assert_called_once_with, patch and monkeypatch — and the "patch where it is looked up" rule, without which tests quietly reach the real network.45 min10 questions
  14. 24Controlling time in tests — freezegun and injected clocksProin-reviewTests of code that calls datetime.now() are green today and red tomorrow. Freezing and advancing time with freezegun, testing token-expiry and renewal boundaries, and injecting a clock as a parameter.40 min10 questions
  15. 28Automated validation — pre-commit hooks and CIProin-reviewRuff, mypy and secret checks before every commit with pre-commit, pytest before every push, and a GitHub Actions workflow with uv that runs the same checks — because local hooks can be skipped.45 min10 questions
  16. 29Hands-on lab: debugging production bugsProin-reviewOne deep crash and two silent bugs in a billing sandbox — from the traceback to the real cause with pdb post-mortem and breakpoints, a failing regression test for each first, then the fix.50 min10 questions
  17. 30Milestone 3 review — the regression suiteProin-reviewA review rubric for test suites, why 100% coverage is not proof, catching order-dependent tests with pytest-randomly, and measuring a suite's real value by running it against buggy and fixed code — deliverable 3.45 min10 questions
  18. 33Resilient API clients — timeouts, retries and circuit breakersProin-reviewhttpx AsyncClient and MockTransport, a timeout on every external call, which errors and methods are safe to retry, exponential backoff with jitter, a circuit breaker and FastAPI BackgroundTasks — all testable without any real waiting.45 min10 questions
  19. 34Milestone 4 review — a concurrent FastAPI serviceProin-reviewA review rubric for an async API PR: blocking calls in async routes, status codes that tell the truth, leaked internal errors, and structured logs with request ids — each one proven with a check script. Deliverable 4.45 min10 questions
  20. 35Data handling and SQL optimisation — PostgreSQL and indexesProin-reviewCleaning messy records before insert, a document-library schema, parameterised queries with psycopg versus SQL injection, B-tree, composite, expression and GIN indexes verified with EXPLAIN, and a connection pool.50 min10 questions
  21. 38RAG prompts and retrieval — grounded answersProin-reviewThe part between retrieval and generation: a distance threshold, a context budget, a grounded prompt with numbered sources and an exact "I don't know", citation checks, and a language model behind a Protocol — tested with a fake, run with the Anthropic SDK.45 min10 questions
  22. 39Hands-on lab: a RAG APIProin-reviewFastAPI, a psycopg pool, pgvector and RAG in one service: schema and pool in lifespan, connections and the model through Depends, old chunks removed on update, and tests against a real database with a fake model via dependency_overrides.50 min10 questions
  23. 40Milestone 5 review — RAG retrieval diagnosticsProin-reviewA rubric for RAG PRs, an evaluation set labelled with evidence sentences, recall@1, recall@3 and MRR, checking index usability with enable_seqscan, and drilling into a failed question chunk by chunk — deliverable 5.50 min10 questions
  24. 41Prompt injection defence and AI securityProin-reviewThe OWASP Top 10 for LLM applications, direct and indirect prompt injection, and data exfiltration. Building input screening in FastAPI, seeing why a blocklist alone is not enough, then layered defence: instructions kept apart from data, least-privilege tools and output validation.40 min10 questions
  25. 43Container networks with Docker ComposeProin-reviewA Dockerfile for a uv-managed FastAPI app with layer caching and a non-root user, then the API and a pgvector database in Compose — healthchecks, networks, env files and volumes.45 min10 questions
  26. 45Milestone 6 review — a hardened container setupProin-reviewA rubric for container PRs, a key in ENV and docker history, inspecting the built image with docker image inspect and a throwaway container, a check script's own three mistakes, and a security fix list — deliverable 6.50 min10 questions
  27. 47React hooks and fetch — connecting to FastAPIProin-reviewControlled inputs and updater functions with useState, loading, error and success from one status, calling FastAPI with fetch, useEffect dependencies and cleanup, StrictMode's double effect, and testing CORSMiddleware and the preflight.55 min10 questions
  28. 48JWT authentication — login, tokens and protected endpointsProin-reviewHashing passwords with argon2, creating and verifying tokens with PyJWT, why a forged payload, an expired token, alg none and the wrong key all fail, HTTPBearer and get_current_user in FastAPI, and sending a Bearer token from React.55 min10 questions
  29. 49SSE streaming — an LLM's answer word by wordProin-reviewThe SSE wire format, authenticated streaming with FastAPI's EventSourceResponse, an error event for mid-way failures, stopping work when the client leaves, chunk and UTF-8 boundaries, and reading the stream with fetch in React with a Stop button.55 min10 questions
  30. 50Milestone 7 review — an authenticated streaming clientProin-reviewA rubric for authentication-and-streaming PRs, a URL token in the logs and EventSource's repeated requests on a real server and browser, security-contract checks with TestClient, a check that passed for the wrong reason, and a security fix list — deliverable 7.55 min10 questions
  31. 53Deployment and monitoring — staging, smoke tests and rollbackProin-reviewLiveness and readiness, a database, a run-once migration and the API in Docker Compose, releases named by commit SHA, a smoke test after every deploy, a bad release with a two-second rollback, and errors in Sentry with their release and route.60 min10 questions
  32. 54Demo rehearsal — preflight, a fallback plan and measured practiceProin-reviewA ten-minute demo built around one golden path, freezing the release after the last rehearsal, a Python preflight that checks release, readiness and time budgets, a recorded fallback and its rule, and dividing time with the median of rehearsals.45 min10 questions