Guide Python Intermediate

12.16 Sets in DevOps

Five places sets are the natural fit in infrastructure code -- deduplicating IP addresses from logs, comparing installed vs. required packages, diffing security group rules, flagging duplicate log lines, and comparing server inventories.

2 min read

Five places sets are the natural fit in infrastructure code — specifically because deduplication and fast comparison matter, the same reason tuples show up in 11.12 Tuples in DevOps for fixed records and lists show up in 10.15 Lists in DevOps for ordered collections.

Unique IP Addresses

>>> log_ips = ["10.0.0.1", "10.0.0.2", "10.0.0.1", "10.0.0.3"]
>>> set(log_ips)
{'10.0.0.1', '10.0.0.2', '10.0.0.3'}

Installed Packages

Comparing what’s installed against what’s required with set difference — instantly reveals missing packages.

>>> installed = {"nginx", "redis", "curl"}
>>> required = {"nginx", "redis", "postgres"}
>>> required - installed     # missing packages
{'postgres'}

Security Groups

Finding ports allowed by both of two security groups via intersection — useful when auditing overlapping rule sets.

>>> sg1 = {"22", "80", "443"}
>>> sg2 = {"80", "443", "8080"}
>>> sg1 & sg2
{'80', '443'}

Duplicate Log Detection

Tracking a running “seen” set while scanning lines to flag exact repeats — a lightweight duplicate-log detector.

seen, duplicates = set(), set()
for line in ["a", "b", "a", "c"]:
    if line in seen:
        duplicates.add(line)
    seen.add(line)

>>> duplicates
{'a'}

Inventory Comparison

Comparing a current server fleet against the expected one — reporting what’s missing and what’s extra with two differences run in opposite directions.

>>> current = {"web01", "web02", "db01"}
>>> expected = {"web01", "web02", "web03"}
>>> print("missing:", expected - current)
missing: {'web03'}
>>> print("extra:", current - expected)
extra: {'db01'}

Quick Interview Answer

“Sets show up in DevOps tooling anywhere the question is ‘what’s unique,’ ‘what’s missing,’ or ‘what overlaps’ — deduplicating IPs pulled from a log file, diffing an installed-package set against a required one to find gaps, intersecting two security groups’ ports to audit overlapping access, and comparing a current server fleet against an expected inventory to report both what’s missing and what’s unexpectedly extra. The common thread is that each of these is a single set operation instead of nested loops: required - installed for missing packages, sg1 & sg2 for shared ports, two differences run in both directions for a full inventory diff.”

Common Mistakes

  • Using nested for loops to compare two lists of servers or packages, instead of converting both to sets and using -, &, or ^ directly.
  • Reporting only expected - current for an inventory comparison and forgetting current - expected — the first shows what’s missing, the second shows what’s unexpectedly extra; a complete audit usually needs both.
  • Deduplicating IP addresses or package names with a set, then needing the original order back for a report — sets discard order, so keep (or re-sort) a separate ordered structure if the sequence matters downstream.

Add More Questions to This Guide

Know a question that should be here? Share it and help the community!

Open Google Form