There are some details about this in the blog post.
- no execution request is sent by the front-end.
- code is stripped out unless explicitely stated otherwise.
For deployment, we are working on several scenarios around JupyterHub.
Please consider the request for a Docker based output build in addition to whatever you do for jupyterhub
> with --strip_sources=False, input cells will be included in the resulting web application (as read-only pygment snippets).
So the sources are presumably not there by default.