Hosting Files with Python HTTP Server in Practical DevSecOps Labs
A common task in the Practical DevSecOps labs is saving files from the DevSecOps Box to your local machine. The simplest way is to start a Python HTTP server and access the files through your browser.
Table of Contents
Starting the HTTP Server
Python 3 includes a built-in HTTP server module. You can start it from any directory to serve the files in that directory.
On port 80
python3 -m http.server 80 &
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
On port 8000 (default)
python3 -m http.server &
Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/) ...
The
&at the end runs the server in the background, keeping your terminal available.
Note: For Python 2, use
python -m SimpleHTTPServer. The labs use Python 3.
Creating a test file
cat > home_page.html <<EOL
<html>
<body>
<p>Welcome to the home page!</p>
</body>
</html>
EOL
Accessing the Server
First, find your DevSecOps Box hostname:
hostname
devsecops-box-$STUDENT_ID
Then access the files via:
| Port | URL |
|---|---|
| 80 | https://devsecops-box-$STUDENT_ID.$LAB_DOMAIN_URI |
| 8000 | https://devsecops-box-$STUDENT_ID-8000.$LAB_DOMAIN_URI |
Click on a file (e.g., home_page.html) in the browser to view or download it. Right-click and choose "Save As" to save files locally.
Important: Only files in the directory from which you started the HTTP server are accessible.
Common Questions
| Question | Answer |
|---|---|
| How do I stop the HTTP server? | Use kill %1 to stop the background job, or pkill -f "http.server". |
| Can I serve files from a specific directory? | Yes, cd to that directory first, then run python3 -m http.server. |
| Why use port 80 vs 8000? | Port 80 is the default HTTP port, making the URL cleaner. Port 8000 is the Python server's default and avoids potential port conflicts. |
| Is this a secure way to transfer files? | No, this is for lab use only. The HTTP server does not provide authentication or encryption. |
| Can I access subdirectories? | Yes, the server serves the entire directory tree from the current working directory. |
Wrap-Up
The Python HTTP server is the quickest way to download files from the DevSecOps Box during labs. Remember to note the command, as you'll use it throughout the courses to save scan results, scripts, and other important files. Practice this skill regularly to build confidence.