Skip to content

feat: add Copier template for production-ready Python projects - #2

Merged
jitsejan merged 2 commits into
mainfrom
feat/1-copier-template
Oct 4, 2026
Merged

jitsejan merged 2 commits into
mainfrom
feat/1-copier-template

Conversation

@jitsejan

@jitsejan jitsejan commented Oct 4, 2026

Copy link
Copy Markdown

Why

Every new project should start where a good team's projects end up: locked dependencies, strict linting and typing, a coverage gate, secrets scanning and a tested container, with CI that can't drift from local checks. This template packages that so Qualixto projects, and anyone cloning them, start there.

What changed

  • copier.yml with validated questions (name, slug, package, Python 3.12–3.14, licence, optional API)
  • Generated project: uv, ruff (incl. security rules), mypy --strict, pytest with branch coverage ≥ 90%, invoke tasks shared with CI, pre-commit (gitleaks, conventional commits, tests on push), uv audit, Dependabot, Docker image with smoke test, DEFINITION_OF_DONE.md, ADRs and CLAUDE.md
  • Optional API variant: FastAPI with an injectable httpx2 upstream, fake upstream, and Bruno collection run as end-to-end tests
  • Template repo tooling: tests that render each variant and run its own lint and tests; CI that also runs audit, smoke and Bruno inside the rendered projects

Reviewer notes

  • Verified locally: both variants pass lint, test, audit, smoke, api-test and pre-commit; Python 3.12/3.14 and MIT/Proprietary renders pass lint and test.
  • httpx2 replaces httpx because Starlette's test client now deprecates httpx.
  • api-test and the Docker smoke test bind free ports, so they don't clash with anything already running on 8000/8001.
  • Try it: uvx copier copy --trust --vcs-ref feat/1-copier-template gh:Qualixto/python-template /tmp/demo

Closes #1

Checklist

  • Branch is named <type>/<issue>-<short-description>
  • Commits follow <type>: <description>
  • New behaviour is covered by tests and CI passes
  • Documentation is updated
  • Security checks pass and no secrets are committed

Jitse-Jan added 2 commits October 4, 2026 18:41
Generated projects meet the Technical, Quality and Security pillars from
the first commit: uv, ruff, strict mypy, pytest with a coverage gate,
pre-commit with gitleaks and conventional commits, uv audit, a tested
Docker image and GitHub Actions CI that runs the same invoke tasks as a
developer does locally.

An optional API variant adds a FastAPI service around an injectable
upstream client, a fake upstream, and a Bruno collection that runs as
end-to-end tests. It uses httpx2 because Starlette's test client now
deprecates httpx.

The template's own tests render each variant and run its lint and test
tasks, and CI additionally runs audit, smoke and API tests inside the
rendered projects, so a template change can't ship a broken project.
setup-uv no longer publishes a moving major tag, so @v10 fails to
resolve. Dependabot keeps the pinned version current.
@jitsejan
jitsejan merged commit 2a6db5d into main Oct 4, 2026
5 checks passed
@jitsejan
jitsejan deleted the feat/1-copier-template branch October 4, 2026 20:32
jitsejan pushed a commit that referenced this pull request Oct 4, 2026
* feat: add Copier template for production-ready Python projects

Generated projects meet the Technical, Quality and Security pillars from
the first commit: uv, ruff, strict mypy, pytest with a coverage gate,
pre-commit with gitleaks and conventional commits, uv audit, a tested
Docker image and GitHub Actions CI that runs the same invoke tasks as a
developer does locally.

An optional API variant adds a FastAPI service around an injectable
upstream client, a fake upstream, and a Bruno collection that runs as
end-to-end tests. It uses httpx2 because Starlette's test client now
deprecates httpx.

The template's own tests render each variant and run its lint and test
tasks, and CI additionally runs audit, smoke and API tests inside the
rendered projects, so a template change can't ship a broken project.

* fix: pin setup-uv to a published release tag

setup-uv no longer publishes a moving major tag, so @v10 fails to
resolve. Dependabot keeps the pinned version current.

---------

Co-authored-by: Jitse-Jan <jitsejan@qualixto.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Build the Copier template for Python projects

1 participant