EO Engineering Learning OS
PROJECT LADDER · P04
Back to map ↑
CORE PROJECT · TARGET L3 · 4–5 days
P04

Nginx + HTTPS

Introduce a production web boundary with DNS, TLS and reverse proxy behavior.

01 / CONCEPT MAP

Know what the parts mean.

Learn each concept deeply enough to recognize it, place it in the system and reason about normal and failed behavior.

01

Reverse proxy

Define it · locate it · observe it · explain its failure mode.

02

DNS

Define it · locate it · observe it · explain its failure mode.

03

TLS certificates

Define it · locate it · observe it · explain its failure mode.

04

Ports 443 and 8000

Define it · locate it · observe it · explain its failure mode.

05

Headers and 502 isolation

Define it · locate it · observe it · explain its failure mode.

02 / SYSTEM FLOW

Trace it end to end.

BrowserDNSTLS :443NginxUvicorn :8000FastAPI

For every transition: identify input, output, identity, protocol, state, trust boundary, evidence and owner.

03 / GUIDED BUILD

Build, observe and explain.

Documentation and AI are allowed. The engineer must review every output and demonstrate the result from direct evidence.

  1. 01Install Nginx
  2. 02Proxy to Uvicorn
  3. 03Configure DNS
  4. 04Issue and renew TLS
  5. 05Forward required headers
  6. 06Test each layer independently
04 / INCIDENT

Nginx returns 502 although its own configuration is valid; isolate the failed upstream.

Required investigation

State impact → collect evidence → form competing hypotheses → test the cheapest discriminator → isolate root cause → contain → correct → verify.

Evidence pack

Timeline, relevant logs/metrics, failed assumptions, root cause, correction, verification and one prevention action.

AI ownership

AI may suggest causes and commands. The engineer must explain why each check is safe, what result is expected and how the result changes the hypothesis.

05 / DESIGN CHALLENGE

Defend the decision.

Explain why Uvicorn stays private and where TLS should terminate.

06 / VERIFY, SUBMIT & REVIEW

Submission evidence

Architecture review

  • Explain nginx + https without relying on memorized commands.
  • Draw the flow and name what crosses every arrow.
  • Identify the most likely, highest-impact and hardest-to-detect failure.
  • Show the evidence that proves the solution works.
  • Defend one security, reliability and cost trade-off.

Definition of Done

  • Acceptance criteria pass
  • Flow is drawn and explained
  • Security implications considered
  • Logs/metrics checked
  • Failure is tested
  • AI output is understood
  • Runbook is reusable
  • Mentor review passes
07 / MENTOR GUIDE

Do not score memory. Score the engineer’s ability to form a model, collect evidence, make a safe change and defend the trade-off.

1 Cannot explain2 Understands with gaps3 Implements and troubleshoots4 Designs and reviews