FDE Foundations · Module 9: Production
Containers and Environment Parity
The customer will run your code in their way. Containers with environment-driven configuration and a reproducible environment description make their way and yours the same.
11 min reading
Objectives
- Containerize a small service with a production-grade image
- Manage configuration through environment, not code
- Keep environments reproducible from a description file
Images that behave
Build small images from pinned base versions, multi-stage where it helps: build tools out, runtime and your artifact in. A non-root user, a health endpoint, and logged process signals (SIGTERM handled) are the difference between an image that passes security review and one that circles back for a week. Pin everything; "latest" is not a version.
Configuration through environment
Twelve-factor discipline: config in environment variables, secrets injected by the platform, no environment names in code. Provide a documented list of variables with types and defaults, and fail fast at boot if a required one is missing. A service that starts half-configured fails at 3 a.m.; one that refuses to boot without config fails in CI, loudly.
Environment parity
Describe environments as files: compose files for local, the customer's orchestration manifests for theirs. The closer local matches staging matches production, the fewer "works on my machine" conversations you will have with their ops team. Where parity is impossible (their database, their identity provider), build an adapter layer and fake the boundary in local tests.
You are not deploying code into an environment. You are negotiating your code's entry into an environment someone else owns.
Quick check
An optional 2-3 question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Exercise
Write the production plan for containerizing a fictional sync service: base image choice, five environment variables with types, health endpoint design, and the two boundaries you would fake locally.
Pass criteria
Pinned base image and non-root user named, env vars typed with failure-at-boot rule, health endpoint defined, and both faked boundaries justified.