如何在Amazon EC2/Google Cloud免费服务中隐藏Python模块源码供他人使用?
Hey there! Let's walk through how you can share your Python modules with others while keeping your source code completely private—using free tiers on AWS or GCP. These are practical, cost-free ways to get your functionality out there without exposing your hard work:
AWS Lambda's free tier includes 1 million monthly requests and 400,000 GB-seconds of compute time—plenty for personal or small-scale use. Here's how to set it up:
- Hide your source code first: Use Cython to compile your core Python logic into a binary
.sofile (unreadable as plaintext Python). Create a simplesetup.pylike this:
Runfrom setuptools import setup from Cython.Build import cythonize setup( ext_modules=cythonize("your_core_module.py", compiler_directives={'language_level': "3"}) )python setup.py build_ext --inplaceon a Linux machine (Lambda uses Linux) to generate the.sofile. - Build a Lambda handler: Write a lightweight wrapper script that calls your compiled module and handles input/output. Example:
import your_core_module # Imports the compiled .so file def lambda_handler(event, context): input_data = event.get("input", "") result = your_core_module.process_data(input_data) return {"statusCode": 200, "body": result} - Deploy & expose the API: Package the handler script and
.sofile into a zip, upload it to Lambda. Then add an API Gateway trigger to create a public HTTP endpoint. Users call this endpoint to use your module—they never see the underlying code.
GCP's Cloud Functions free tier offers 2 million monthly requests and 400,000 GB-seconds of compute time. The workflow is nearly identical to Lambda:
- Compile your code: Same Cython step as above to generate a Linux-compatible
.sofile. - Write a function entry point: Create a script that handles HTTP requests and calls your compiled module:
import your_core_module def process_request(request): request_json = request.get_json() input_data = request_json.get("input", "") result = your_core_module.process_data(input_data) return {"result": result} - Deploy: Upload the entry script and
.sofile via the GCP Console orgcloudCLI. Cloud Functions will generate a public HTTP endpoint for users to interact with your module.
If you need a persistent service (e.g., a TCP server or always-on web API), use AWS's free t2.micro instance (750 hours/month—enough for one full-time instance):
- Set up the instance: Launch a t2.micro Linux instance, install Python and any dependencies your compiled module needs.
- Deploy your service: Upload the
.sofile and a lightweight web server script (e.g., using FastAPI):from fastapi import FastAPI import your_core_module app = FastAPI() @app.post("/process") def process_data(input_data: str): result = your_core_module.process_data(input_data) return {"result": result} - Secure & expose: Configure the EC2 security group to allow traffic only on your service port (e.g., 8000). Start the server with
uvicorn main:app --host 0.0.0.0 --port 8000. Users can call your service via the instance's public IP, with no access to your source code.
- Never include uncompiled
.pyfiles in your deployment packages or EC2 instance—only keep the.sobinary and wrapper scripts. - Add API key authentication to your endpoints (via API Gateway or middleware in your web server) to prevent unauthorized use and avoid hitting free tier limits unexpectedly.
- Test your compiled
.sofile on the target platform (Linux x86_64) before deploying—binary files are architecture-specific.
内容的提问来源于stack exchange,提问作者jdoe

