Develop a MaaS API Wrapper: FastAPI, Monitoring, and Security

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
Develop a MaaS API Wrapper: FastAPI, Monitoring, and Security
Medium
~3-5 days
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

We often see this: you train a model, spend weeks tuning hyperparameters, and get excellent metrics. But how do you now serve it to clients? Simply passing weights won't work. You need an API with authentication, versioning, and monitoring. A raw model is not an endpoint. Our team develops an API wrapper that solves these problems at the code level. Without a proper wrapper, the model remains inaccessible to external systems, and manual integration with each client leads to chaos and data leaks. This approach turns the model into a full-fledged microservice for machine learning, transforming it into a scalable machine learning microservice.

Architecture of MaaS API

[Client] → [API Gateway] → [Auth/Rate Limit] → [Request Validation]
               → [Model Router] → [Inference Service] → [Response Formatter]
                   ↕                    ↕
            [Usage Logger]       [Cache Layer]

The client sends a request, API gateway checks the key, rate limiter controls frequency, and cache (Redis) returns results for repeated requests. Only if the cache is empty does the request go to the model. This reduces load and improves latency.

Implementation with FastAPI

from fastapi import FastAPI, HTTPException, Depends, Header
from fastapi.middleware.cors import CORSMiddleware
from pydantic import BaseModel, Field
import time
import hashlib

app = FastAPI(title="Model-as-a-Service API", version="1.0.0")

class PredictionRequest(BaseModel):
    inputs: list[dict] = Field(..., description="List of feature dictionaries")
    model_version: str = Field(default="latest")
    options: dict = Field(default_factory=dict)

class PredictionResponse(BaseModel):
    predictions: list
    model_version: str
    request_id: str
    latency_ms: float

async def verify_api_key(x_api_key: str = Header(...)):
    if not await api_key_store.verify(x_api_key):
        raise HTTPException(status_code=401, detail="Invalid API key")
    return await api_key_store.get_client(x_api_key)

@app.post("/v1/predict", response_model=PredictionResponse)
async def predict(
    request: PredictionRequest,
    client = Depends(verify_api_key)
):
    # Rate limiting
    if not await rate_limiter.check(client.id, limit=100, window=60):
        raise HTTPException(status_code=429, detail="Rate limit exceeded")

    # Cache check
    cache_key = hashlib.md5(str(request.inputs).encode()).hexdigest()
    cached = await cache.get(cache_key)
    if cached:
        return cached

    # Inference
    start = time.perf_counter()
    try:
        model = model_registry.get(request.model_version)
        predictions = model.predict(request.inputs)
    except Exception as e:
        await logger.error(client.id, request, str(e))
        raise HTTPException(status_code=500, detail=str(e))
    latency = (time.perf_counter() - start) * 1000

    response = PredictionResponse(
        predictions=predictions,
        model_version=model.version,
        request_id=generate_request_id(),
        latency_ms=latency
    )

    # Log usage
    await usage_logger.log(client.id, request, response, latency)
    await cache.set(cache_key, response, ttl=300)

    return response

FastAPI uses Pydantic for data validation and automatic documentation generation. Compared to Flask, it wins in performance: FastAPI delivers 2–3x lower latency than Flask under the same load. This is confirmed by FastAPI benchmarks.

Why FastAPI over Flask for ML APIs?

FastAPI delivers 2–3x lower P95 latency under high load due to async processing and automatic validation. According to official benchmarks, it handles up to 1000 RPS on a single instance, while Flask handles around 300. This is critical for production ML services where every millisecond affects user experience. Our REST API for ML models must be fault-tolerant and scalable.

API Versioning

# v1 — legacy format
@app.post("/v1/predict")
async def predict_v1(request: PredictionRequestV1):
    ...

# v2 — new format with batch support
@app.post("/v2/predict")
async def predict_v2(request: PredictionRequestV2):
    ...

# Deprecation header for v1
@app.middleware("http")
async def add_deprecation_header(request, call_next):
    response = await call_next(request)
    if request.url.path.startswith("/v1/"):
        response.headers["Deprecation"] = "true"
        response.headers["Sunset"] = "set at deployment"
    return response

Versioning allows the API to evolve without breaking existing clients. Old versions are marked as deprecated but continue to work until clients migrate.

How We Ensure Security and Performance?

Security is built on three layers: authentication (API keys or JWT), rate limiting (limiting requests per minute per client), and input validation via Pydantic. For performance, we use Redis caching with a 5-minute TTL. Typical cache hit rate for repeated requests is 40–60%, reducing latency by 30–50%.

Common Problems When Deploying an ML Model to Production

We often encounter three issues when deploying an ML model. First, lack of access control: anyone can call the model, leading to overload and uncontrolled costs. We solve this with API keys and token bucket rate limiting. Second, model updates cause downtime: while weights are being replaced, the service is unavailable. Versioning and blue-green deployment help. Third, no monitoring: you don't know request count or latency. We set up Prometheus + Grafana with automatic alerts.

What's Included in the API Wrapper Development?

Component Description
Endpoints REST API with versioning support (v1, v2)
Authentication API keys, JWT, or OAuth2 on request
Rate Limiting Configurable per-client limits (requests/min)
Caching In-memory (Redis) for repeated requests
Monitoring Prometheus metrics, Grafana dashboards, alerts
Documentation OpenAPI/Swagger, Postman collection
SDK Python and JavaScript clients for integration
Streaming SSE support for LLM models
Batch Inference Grouping requests to increase throughput

Additional: webhook callbacks for long predictions, support for quantized models (INT4/INT8) to lower cost per token.

Monitoring and Target SLAs

Metric Target SLA
p95 latency < 200 ms
error rate < 0.1%
uptime 99.9%
cache hit rate > 40%

Case Study: How We Reduced Latency by 40%

For a client with an LLM model based on LLaMA 3, we implemented request batching (batch size 8) and model quantization to INT4. This cut p95 latency from 800 ms to 450 ms and doubled throughput. Cost per token decreased by 35% through more efficient GPU utilization. Inference ran on Triton Inference Server.

With over 10 years of experience, certified Kubernetes setup, and guaranteed 99.9% uptime, our team knows the pitfalls of production ML. Development starts at $5,000 and can reduce deployment costs by 30%. The process involves six steps: 1) Requirement gathering, 2) Model optimization, 3) API design, 4) Implementation, 5) Monitoring setup, 6) Deployment. Contact us to assess your project. We will develop a turnkey API wrapper and estimate timelines in 1–2 days. Request a consultation to discuss the details.

MLOps: Infrastructure for Training, Deploying, and Monitoring ML Models

The model is trained, metrics — F1 0.94 on validation. Three months later in production, quality drops by 12%. No one knows when — there is no monitoring. It's impossible to retrain quickly — the training script is in a Jupyter notebook of a data scientist who has already left. Data for retraining is collected manually from three disparate systems. About half of the projects come to us with this pain. We build a turnkey MLOps platform: from experiment tracking to automatic deployment and data drift monitoring. We will assess your infrastructure in 1–2 weeks, and in 4–6 weeks you will get a basic MLOps core running in production. Our team has 10+ years of experience in ML infrastructure, over 50 implementations.

How does MLOps infrastructure benefit your ML projects?

Experiment Tracking and Reproducibility

Without tracking, an ML project turns into chaos: it's unclear which checkpoint is better, which hyperparameters were used, which dataset. Reproducing a result a month later is a quest.

Why is experiment tracking the foundation of reproducibility?

MLflow is an open source standard for tracking. It logs parameters, metrics, artifacts (models, graphs), and code. MLflow Model Registry is a centralized model storage with versioning and lifecycle stages (Staging → Production → Archived). Deployment via MLflow Serving or integration with external systems.

Typical initialization in code:

import mlflow

mlflow.set_experiment("fraud-detection-v2")
with mlflow.start_run():
    mlflow.log_params({"learning_rate": 3e-4, "batch_size": 64, "epochs": 10})
    mlflow.log_metric("val_f1", val_f1, step=epoch)
    mlflow.pytorch.log_model(model, "model")

This is the minimum. In production, we add logging of system metrics (GPU utilization, memory), dataset (hash, version), code (git commit hash). Weights & Biases — richer UI, collaboration features, sweep for hyperparameter optimization. MLflow — for on-premise deployment without external dependencies.

DVC (Data Version Control) — versioning of data and models on top of git. Data is stored in S3/GCS/Azure Blob, only metadata (hashes) in git. dvc repro reproduces the entire pipeline from raw data to metrics.

To ensure reproducibility of training, fix random seeds (torch.manual_seed, numpy.random.seed, random.seed) and record them in experiment metadata. Without this, debugging irregular results is painful. Log the dataset version (DVC hash) and git commit — then any experiment can be reproduced down to the byte.

Pipeline Orchestration: Kubeflow, Airflow, Prefect

A pipeline orchestrator becomes necessary when: A 100-line training script in cron is fine for simple tasks. But as soon as you have a multi-step pipeline (data loading → preprocessing → feature engineering → training → validation → deployment if quality above threshold), you need an orchestrator with retry logic, visualization, and alerts.

Kubeflow — Kubernetes-native orchestrator for ML (see Kubeflow). Each step is a Docker container. Supports parallel steps, conditional branches, artifacts between steps. Integrates with Katib (AutoML), KServe (serving), Feast (feature store).

Apache Airflow — more general DAG orchestrator. Wide ecosystem of operators (S3, Spark, DBT, Kubernetes). Easier to deploy if Airflow already exists in the company.

Prefect / Metaflow — less boilerplate. Prefect 2.x with @flow and @task decorators — quick start for small teams.

Typical training pipeline architecture on Kubeflow:

  1. Data ingestion component — fetches data from S3/DB, validates schema via Great Expectations
  2. Preprocessing component — transformations, normalization, train/val/test split
  3. Training component — training on GPU, logging to MLflow
  4. Evaluation component — metric calculation, comparison with baseline in Model Registry
  5. Conditional deployment — deploy only if new model is better than current by >2% F1

Each component is a separate Docker image. Pipeline is versioned in git. Scheduled run (retraining once a week on new data) or manual.

Model Registry and Lifecycle Management

Model Registry is not just a checkpoint store. It is a centralized system that knows:

  • Which model is currently in production (and with what metrics)
  • History of all versions with training parameters
  • Metadata: dataset, git commit, validation results
  • Lifecycle stage: None → Staging → Production → Archived

MLflow Model Registry — standard. For enterprise — Vertex AI Model Registry (GCP), SageMaker Model Registry (AWS), Azure ML Model Registry.

Model promotion through stages: automatically move model to Staging after successful eval, then manual or automatic (during A/B test) promotion to Production. Rollback — switch to previous Production version in seconds.

Serving: From FastAPI to Triton Inference Server

Simple case. FastAPI + PyTorch/ONNX on one server — 80% of production ML deployments are exactly that. Sufficient for most tasks with load up to 100 req/s.

from fastapi import FastAPI
import onnxruntime as ort

app = FastAPI()
session = ort.InferenceSession("model.onnx", providers=["CUDAExecutionProvider"])

@app.post("/predict")
async def predict(request: PredictRequest):
    inputs = preprocess(request.text)
    outputs = session.run(None, {"input_ids": inputs})
    return {"label": postprocess(outputs)}

Triton Inference Server — production standard for high loads (500+ req/s). Dynamic batching, concurrent model execution, model ensemble. Supports TensorRT, ONNX, PyTorch TorchScript, TensorFlow SavedModel.

KServe — Kubernetes-native ML serving with autoscaling, canary deployments, A/B testing out of the box. Scale-to-zero for inactive models — savings on infrastructure up to 40% annually for a project with 10 models.

Monitoring: Data Drift, Model Drift, Infrastructure Metrics

Monitoring — what is usually done last and regretted first. Three levels.

Infrastructure monitoring. Latency (P50/P95/P99), throughput (req/s), error rate (4xx, 5xx), GPU/CPU utilization. Prometheus + Grafana — standard. Alert when P99 latency > threshold or error rate > 1%.

Data drift monitoring. Distribution of input data changes over time. Detect via PSI (Population Stability Index) for numerical features: PSI > 0.2 — strong drift. Chi-squared test for categorical, Kolmogorov-Smirnov test for continuous. Evidently AI — open source library with ready-made drift tests.

Model drift monitoring. If ground truth is delayed (e.g., we know conversion after a week) — monitor real metrics. If not — surrogate metrics: distribution of prediction scores, proportion of confident predictions.

Alerting. Three levels: INFO (minor drift, log it), WARNING (significant, notify team), CRITICAL (quality dropped below threshold — automatic switch to fallback model).

Why is data drift monitoring important?

Without it, you learn about model degradation only from user complaints or ringing SLA. A drift alert allows you to retrain the model in advance, before errors start causing losses. In one of our projects, PSI monitoring detected drift 2 days after a data source change — this saved the campaign.

Common Mistake Consequences Solution
Lack of data versioning Irreproducible experiments Implement DVC or similar
Manual model deployment Human errors, slow rollback Automate CI/CD pipeline
Monitoring only by business metrics Late drift detection Add data drift monitoring (PSI, KS)

Feature Store

Feature Store solves the training-serving skew problem. If preprocessing during training and inference is implemented in two different places — divergence is inevitable.

A Feature Store is needed when:

  • Several models use the same features
  • Features are computed from streaming data (real-time)
  • Large team with different people on feature engineering and model training

Feast — open source Feature Store. Offline store (S3 + Parquet) for training, online store (Redis, DynamoDB) for low-latency inference. Feature definitions as code, materialization job syncs offline → online.

Tecton (commercial), Vertex AI Feature Store (GCP), SageMaker Feature Store (AWS) — managed options with less ops overhead.

CI/CD for ML

ML CI/CD is regular CI/CD plus specific ML steps.

ML-specific checks in CI:

  • Reproducibility check: run training with a fixed seed, result must match
  • Data validation: Great Expectations or Pandera on schema/distribution checks
  • Model performance check: automatic eval on holdout, block merge if degradation > threshold
  • Latency regression test: inference must meet SLA

GitOps for deployment. Merge to main → CI triggers training → eval → if passes → automatic deployment to Staging → smoke tests → manual promotion to Production or automatic upon successful canary.

Tools: GitHub Actions / GitLab CI for CI, ArgoCD for GitOps deployment on Kubernetes.

What's Included in MLOps Platform Development

We provide a full cycle of work, documentation, and team training.

Stage Duration Result
Audit of current infrastructure and data pipeline 1–2 weeks Roadmap with risks and priorities
Core deployment: MLflow, orchestrator, serving 4–6 weeks Working training and deployment pipeline
Feature Store and CI/CD for ML 2–3 months Feature Store, automatic retrain and deployment
Drift monitoring and alerting 3–4 weeks Dashboards, alerts, incident playbook
Team training and documentation 1–2 weeks Runbook, policies, training for data scientists

Total time from audit to full MLOps platform: 3–5 months. Also possible phased launch: basic level (tracking + serving) in 4–6 weeks.

Cost is calculated individually based on data volume, number of models, and infrastructure requirements. Order an MLOps infrastructure audit — get a roadmap in 1–2 weeks. Contact us for a project assessment — we will send a preliminary estimate within 2 business days.

Note: warranty on architectural solutions — 12 months. We provide integration certificates with major cloud providers (AWS, GCP, Azure). During our work, we have not lost a single client after the first implementation — the experience of 50+ successful MLOps projects speaks for itself. Get a consultation on building an MLOps platform today.