Flask Mega-Tutorial (2017)
blog.miguelgrinberg.com
blog.miguelgrinberg.com
Happy to see people continue to find my tutorial useful and relevant. If you have any questions, I'll be happy to answer.
One thing that people often complain is that it is hard and/or tedious to build tables with data, which is one of the building blocks most admin pages need. Last year I wrote a blog article where I show how I build tables in my Flask apps: https://blog.miguelgrinberg.com/post/beautiful-interactive-t....
Now this is my personal opinion, but you cannot say the same about FastAPI. Even though the ecosystem of asyncio compatible libraries has grown, it is still several orders of magnitude smaller than what is available for standard non-async Python. So in my view, in terms of access to 3rd party libraries Flask is a better choice.
The FastAPI docs read like a full project, a very dense project. Sometimes you just want to learn about a specific feature, but you walk into a page that assumes you have the context of the previous chapters, that puts me off a lot.
I also dislike how some of the documentation is absolutely enormous (the SQL chapters is one example), but I suspect this might have to do with the not-so-simple approach FastAPI takes, as opposed to Flask, which is indeed very simple.
I really can't join the crowd here. I don't think FastAPI is a replacement for Flask, even when async is taken out of the equation. Flask has some weird quirks to it (like "g"), but it really is a beautiful and simple API for the web.
But it could _really_ do with some "Reference" documentation. Sometimes I just want to know exactly what a call does or what the various parameters mean.
Pytorch, 8400
Pandas, 3400
Tensorflow, 2100
jupyter notebook, 2000
scikit-learn, 1500
pytest, 720
requests, 170
The outlier seem to be Flask.
django, 1101 open, 32662 closed
cherrypy, 218 open, 1505 closed
starlette, 31 open, 570 closed
pyramid, 70 open, 966 closed
falcon, 168 open, 789 closed
flask, 14 open, 2318 closed
fastapi, 1044 open, 1855 closed
Fast api has one of the worst ratio regarding open/closed issues.
Also fastapi allows people to ask questions with the issues. On the 1000+ open issues, 826 are tagged as question.
It's hard to find a fair metric. Open/close ratio rewards older project with fluctuating/stable popularity. Fastapi popularity is still growing[0], so having some difficulties to work on issues is expected.
[0] -- https://trends.google.com/trends/explore?date=today%205-y&q=...
As far as Swagger integration, you can use APIFairy with Flask and get similar type of auto-generated docs. Disclaimer, APIFairy is an extension that I created: https://github.com/miguelgrinberg/APIFairy
The difference is that even without the benefits of async, FastAPI offers a vastly better developer experience IMHO, with its integration with Pydantic, Python type hints and the lack of reliance on global objects
Your Flask tutorials are my webapp I Ching. Thanks a bunch. Just about to launch another Flask webapp in the next few weeks, and your tutorials are invaluable.
Oh! Before I forget - flask-migrate! Lifesaver! Thanks Miguel!
Thanks again
Thanks to Miguel (and also official Flask docs) I have some Flask Apps running non stop for a few years by now.
Flask is extremely easy to write in regards that the mental model is easy to follow. Sure there is magic there but the abstractions seem "non-leaky". By contrast I can't get into Django because it seems too much magic.
The worst part of using Python for back end was deployment. Setting up WSGI server to host Python apps was a bit of a pain.
https://flask.palletsprojects.com/en/2.1.x/deploying/
I think I went with Gunicorn but there was a bit of learning curve there. I am not even sure if that was the right choice
https://cloud.google.com/run/docs/quickstarts/build-and-depl...
That being said, Django is great, and so is Python :)
I was a Data Scientist and I superficially used Flask to build an internal matching tool between internal products and competitors product (after an ML model). Then I started the Mega-Tutorial to build a small app to track our foosball matches and run a team tournament. Eventually, I wanted to accelerate my learning and joined a bootcamp (Le Wagon) where I learned Ruby on Rails from scratch. My Flask introduction with this tutorial was really helpful to understand things on almost all layers.
I always recommend this tutorial to people who come from Python and want a sneak peak to web development. I am very grateful for Miguel's work and for sharing it.
Try Django instead. If you read my comment history you'll see that I learnt this the hard way.
That's my impression at least.
It worked ok for internal apis not open to customers, but even then Django was much better as just setting up the admin side provided a lot of value to the business (for free).
All forgotten now but wasted a huge amount of time glueing things together that came for free with Django.
While you get up and running faster with Django, in the long run you spend more time fighting it, whereas with Flask you only spend time on stuff that you actually need.
I even recommend people not to install too many flask extensions, just use Django if that is how you like your development. Flask is much better when you just build for it - It takes longer to deliver, but you'll be enjoying that project for years.
Flask is for longevity.
Haven't tried Flask myself though
I have some tips I use in all my Django projects:
1. Split your settings.py in multiple files
This is inspired by Elixir's compile-time config per environment/release/etc...
Instead of a huge settings.py, I have:
settings/__init__.py : Import the correct settings
settings/core.py : The stuff that Django generates and that you touch almost never
settings/base.py : The basic settings of your project (your apps, middlewares, ...)
settings/envs/dev.py : Development settings
settings/envs/prod.py : Production settings (read from env vars, the 12 factors app way)
settings/envs/test.py : Test suite settings
See my gist as an example for the `settings/__init__.py`: https://gist.github.com/linkdd/4aac2c2efc4a51af6ca4b05f395de...2. Separate your business code from your Django apps
In most project, I have the package `myproject.lib` which contains all the business code, easily testable and mockable. Then I have the Django apps in `myproject.apps.<appname>` which imports from `myproject.lib`.
This allows you to make your views quite small because all the logic is not there.
3. Most of the time, you don't need class-based views.
A small function which call your business code and render a JSON document, or an HTML document is more than enough. Django provides many function decorators that are easier to reason about (login_required, permission_required, require_http_methods, ...).
4. You might not need an API
Server Side Rendering is coming back into trends, huge SPA that are heavy on the client's resource are becoming less frequent. Then, why would you need a REST/GraphQL API?
You can work with HTMX, Django Forms, small views that call your business code and return some small rendered template, then sprinkle some Alpine.JS (or jQuery) on top of it, and you get your SSR SPA that scales well enough.
5. Deploy with gunicorn and whitenoise
By default, Django won't serve staticfiles in production, you need to distribute them via a CDN. Which is a bit more complicated to deploy. Instead, use Whitenoise to force Django to serve staticfiles but with the correct HTTP cache headers so services like Cloudflare can take over after the first request (usually done by your E2E test suite by the way).
Then you only need one Docker image, one gunicorn, and if you deploy in Kubernetes, one Ingress resource.
6. Use django-anymail
This is, by far, the best library out there. I usually make a mailjet account, add my API key to my settings, and use the mailjet backend of django-anymail. No SMTP setup required.
All of those tips might seem obvious, but they get you far, very far. Also, IMHO the urls.py from Django is vastly superior to the route decorator from Flask.
TL;DR: Don't fight Django, embrace it.
You have a function, which takes a request and URL parameters, and returns an HTTP response. You add some decorators to require an authenticated user and/or some permissions. That's it.
This is no different than flask views.
Mixins are an OOP pattern that promotes spaghetti code if not done carefully, especially in Python where there is no encapsulation.
ViewSets are from the Django REST Framework, this is simply all the boilerplate code that you copy/paste hundreds of times. And even that, you might not need it if your API is different enough from your database schema. Even more if you don't need an API.
There is nothing "magical", every single framework have a happy path, you should follow it if you decide to use this framework.
And no, Flask is not a framework, it is a library, much smaller scope, much more boilerplate code that you need to copy/paste, or you build your own framework on top of it.
Flask is about the freedom of choice while Django made the decisions for you 10 years ago. Having some experience with Rails, SpringBoot, Phoenix, Symphony, Laravel, Flask, Express, etc... it turns out that I don't want to make those decisions every single time, for every single project.
Or maybe it's culture non-fit. I'm not used to web dev/django habits.
Extra methods on Django Models? Nope. A function in my business logic package which takes a model instance as parameter? Yes. Models should only contain data.
Huge views that do more than one thing? Nope. A function, or a class, in my business logic package which takes the request data (POST form, GET query string) and returns the data to feed to the template and/or the "state" needed to decide which template to render? Yes. Views should be small.
Also, split your templates, don't be afraid of `{% include %}` (which works well with HTMX as well).
This methodology also have another huge advantage. If you need to walk away from Django, you can. Your business logic won't change that much (there are not many difference between a Django Model instance and an SQLAlchemy model instance, or even a MongoEngine model instance). Your business logic knows nothing of HTTP or serialization.
Django, and Flask or any other framework are just the glue between the WSGI/ASGI and your business code.
If your code is async but your web framework isn't, you can still put a `asyncio.run` or `trio.run` inside your view, and you won't have to change a thing once you switch to an async web framework.
Basically, I use Django for:
- the ORM
- the Forms
- the routing with urls.py
- the settings management
- the templating engine
- the builtin User system
- the builtin admin website
- the vast ecosystem (django-anymail, django-tailwind, django-money, django-flags, django-social-auth, ...)
What I dislike about Flask is: - routing is tied up to the views (via a decorator)
- the request object is a global singleton instead of a function parameter
- no builtin admin website (this is just so useful to get things going at the beginning)
- there is a lot of boilerplate to make the different extensions work together where django is just about adding a string to INSTALLED_APPSbtw, didn't django add routing decorators too ? I always prefered it to split file because .. it's a small amount of information that needs to be tracked separately mentally if in urls.py .. plus inclusion/sub-routes feel confusing (but that may only be me)
When I'm onboarding on a huge code base, someone from the frontend reports a bug, I'm like "ok so where does this URL go?", I open the urls.py (which can be split with include), and from there I navigate to the relevant piece of code quite easily.
But with routes as decorators, you need to know the structure of the code beforehand. Which can take some time if you're onboarding a new project.
IMHO, having the route next to the code managing the request does not add useful information to the code being modified.
Also, thanks to django-flags (a feature flag django extension), I can easily enable/disable routes with feature flags in the urls.py without overwhelming the "request handler" with irrelevant information.
But that's only a personal preference.
Flask is scaling really well for us and it’s flexibility is far better than Django’s opinionated approach.
Flask is fantastic and I would recommend it to anyone starting out developing webapps.
I built a json ui for my flask apps the other day - Jsonify - https://github.com/xzava/jsonify
While I am a flask fan, a lot of good things can be said about fastapi.
I did his flask tutorial a year + ago before I started learning react. I'd love to see the workflow for developing a backend Flask API first (without Jinja/render_template). It seems less straight-forward than FastAPI which I am using because I think it's simpler to develop APIs first (ala the name)
FastAPI is async web-framework for Python comparable [0] to Flask.
Read it as Flask is "old" and "slow" (i.e. synchronous and needs multiprocess deployment), whereas FastAPI is really fast, single threaded and async.
[0] IMHO comparable only at "hello world" level as FastAPI is much more and uses a lot of goodies of newer Python versions (typing, asyncio, etc.)
> synchronous and needs multiprocess deployment
Async python still has the issue of the GIL, you still need multiple processes to scale out with async.
The only seriously useful thing async gives you is the ability to run multiple async IO operations in parallel while processing a single request. But most async request processing is still being written in a somewhat sync way, "awaiting" each IO operation within a view/request processing function.
I tend to only use async for long running requests (web-sockets, SSE, long polling), or if I have a view that is calling lots of slow IO which doesn't depend on each other. Think views that are calling multiple REST APIs, and multiple DB requests, you can do them all at once. That is incredible rare though, usually requests do depend on each other and so have to be run sequentially.
I understand the pros/cons of async vs sync. Just did not want to get into multi-paragraph tirade to explain everything.
EDIT: though FastAPI is still fast compared to other python frameworks and especially synchronous ones: https://www.techempower.com/benchmarks/#section=test&runid=7...
The trouble with all these things is what the definition of faster is. If it’s “requests per second” then yes these async frameworks are incredible on these benchmarks with their somewhat simplistic view code (I haven’t looked in detail at the one linked, but many often are only echoing back a response).
Really for the vast majority of developers the speed that matters is “time to first meaningful paint” - the time it takes to get a webpage to display on the users browser, or for an api the time until the response is ready to be passed by your front end code. Async doesn’t increase the speed at which that will happen, except in some situations with heavily paralyzable IO within a view.
It is however true that you can get more out of your hardware with async if your are handling 10s or 100s thousands requests per second. Very few of us ever get close to that though.
(Again not suggesting you don’t know this, commenting for others)
Though personally when I mentally imagine web frameworks "speed" - it is requests per second as well as getting better bang for your buck out of your hardware.
Great writeup - I think we are on the same page.
A good starter to mess around in is this project https://github.com/tiangolo/full-stack-fastapi-postgresql
There is more useful and battle tested solutions out there for flask than fastapi (due to it's obvious time in the market, but still).
It's also interesting to check number of github issues for both frameworks (14 vs >1k).
Nonetheless fastapi is great.
Surprisingly enough, it's terribly easy to put together a REST API with Jooby. I was expecting a lot of arcane tricks to set things up, but it's one of the less.verbose frameworks out there.
I wonder why it's adoption rate is so low.