Systems
Security
Data
Python

PLEXData Engineering for people and agents that act on systems

Permissions, Limits, Evidence & eXecution.

No. 012 Latest feature

Wednesday, 30 September 2026

plexdata.online

003

Published
Updated 29 Sep 2026
Author
Dorian Sotpyrc
Reading
8 minutes · 6 sections
Fields
  • Python
  • Reliability
  • Security
  • Operations

Execution · 10 lines

10 Python Lines I Trust in Production (And the Ones I Don't)

The lines I keep are not clever. They put a bound on waiting, surface failure, make security explicit or remove an assumption the runtime would otherwise make for me.

References
In this article · 6 sections
  1. 01Bound the wait
  2. 02Make failure loud
  3. 03Treat secrets as secrets
  4. 04Keep data boundaries explicit
  5. 05Files need boring guarantees
  6. 06What these lines cannot do

Production Python is mostly ordinary Python with fewer silent assumptions.

The lines I trust are not universal recipes. Each one closes a specific failure mode: waiting forever, accepting a bad response, losing a traceback, generating the wrong kind of token, building SQL from text, writing ambiguous timestamps or letting the platform choose an encoding.

The test is simple: when this line fails at 03:00, does it stop, raise, log or preserve enough evidence for the next person to understand what happened?

Listing 1 · The ten lines
  1. 01response = requests.get(url, timeout=(3.05, 10))
  2. 02response.raise_for_status()
  3. 03subprocess.run(args, check=True, timeout=30)
  4. 04logger.exception("job failed")
  5. 05token = secrets.token_urlsafe(32)
  6. 06hmac.compare_digest(received, expected)
  7. 07cursor.execute("SELECT * FROM jobs WHERE id = ?", (job_id,))
  8. 08stamp = datetime.now(UTC).isoformat()
  9. 09os.replace(tmp_path, final_path)
  10. 10text = Path(path).read_text(encoding="utf-8")

§ 01Bound the wait

Line 1: requests.get(url, timeout=(3.05, 10))

Requests does not time out by default. Its own documentation says most external requests should have a timeout, and a tuple lets you separate the connection wait from the read wait.1

The line I do not trust is the shorter one:

requests.get(url)

It looks clean until a remote service stops answering and a worker spends an unbounded amount of time waiting for somebody else's network.

Line 2: response.raise_for_status()

A completed HTTP request is not the same thing as a successful application request. Requests exposes raise_for_status() so 4xx and 5xx responses become exceptions instead of quietly travelling deeper into the program.1

§ 02Make failure loud

Line 3: subprocess.run(args, check=True, timeout=30)

check=True turns a non-zero exit into a CalledProcessError. timeout=30 puts a ceiling on the wait. The Python docs recommend run() for common subprocess work and document both behaviours.2

The line I do not trust is subprocess.run(args) when the return code matters. It can fail and hand control back as if nothing happened.

Line 4: logger.exception("job failed")

Inside an exception handler, Logger.exception() records the message and traceback. That is a better operational artifact than print(exc), which often throws away the path that led to the error.3

§ 03Treat secrets as secrets

Line 5: secrets.token_urlsafe(32)

Python's secrets module exists for cryptographically strong random values used in password resets, hard-to-guess URLs and similar security-sensitive cases. The docs still use 32 bytes as a typical security level for tokens.4

The line I do not trust for security tokens is anything built from random. That module is useful for simulation and sampling. It is the wrong source for a reset link.

Line 6: hmac.compare_digest(received, expected)

For HMAC or other secret-derived values, Python recommends compare_digest() rather than ordinary equality to reduce timing-analysis exposure.5

§ 04Keep data boundaries explicit

Line 7: cursor.execute("SELECT * FROM jobs WHERE id = ?", (job_id,))

The value is data, not SQL. Python's sqlite3 documentation explicitly warns against building queries with string operations and recommends parameter substitution instead.6

The line I do not trust is an f-string that places user data inside the SQL text.

Line 8: datetime.now(UTC).isoformat()

An aware UTC timestamp says what instant it represents. Python documents naive datetimes as ambiguous and deprecated datetime.utcnow() in Python 3.12 in favour of an aware UTC datetime.7

§ 05Files need boring guarantees

Line 9: os.replace(tmp_path, final_path)

When the temporary file and destination are on the same filesystem, os.replace() gives you replacement semantics without exposing a half-written destination file. Python documents a successful replacement as atomic where the operating system provides that guarantee.8

This line is the final move, not the whole durability story. If the file must survive power loss, you still need the appropriate flush and filesystem durability strategy before replacement.

Line 10: Path(path).read_text(encoding="utf-8")

Explicit encoding removes a machine-dependent assumption from a text boundary. Path.read_text() accepts the encoding directly and closes the file for you.9

The line I do not trust is Path(path).read_text() when the file format says UTF-8. Let the file format decide the encoding, not whichever workstation happens to run the code.

§ 06What these lines cannot do

A trusted line is not a trusted system. Timeouts need retry policy. Retries need idempotency. Atomic replacement needs a correctly staged temporary file. Parameterised SQL does not replace authorization. Logging a traceback does not replace monitoring.

The value of these lines is smaller and more useful: each one removes a category of silent ambiguity.

Before merge

Six questions for the boring path

§References

  1. 1Requests — Timeouts and errorsrequests.readthedocs.io
  2. 2Python — subprocessdocs.python.org
  3. 3Python — Logging HOWTOdocs.python.org
  4. 4Python — secretsdocs.python.org
  5. 5Python — hmac.compare_digestdocs.python.org
  6. 6Python — sqlite3 parameter substitutiondocs.python.org
  7. 7Python — aware and naive datetime objectsdocs.python.org
  8. 8Python — os.replacedocs.python.org
  9. 9Python — pathlib.Path.read_textdocs.python.org