Chapter 30Lesson 05~360 minutes

Checkpoint Lab — Capstone: Build and Operate a Production Cross-Browser Automation Platform

Deliver the complete platform, execute a cross-browser/matrix run, exercise parallel/Grid capacity, inject at least three failures, diagnose from evidence, recover cleanly, and produce a final production-readiness review.

CheckpointFailure drillReadiness reviewGovernanceOperationsCourse completion

Learning objectives

  • Run the final readiness drill with predictions, matrix execution, parallel/capacity evidence, and three injected failures.
  • Produce an evidence packet containing versions, capabilities/session identifiers, DOM/URL state, test output, diagnostics, and incident conclusions.
  • Recover each injected failure using a least-destructive correction and preserve the original evidence.
  • Score security, reliability, capacity, maintainability, observability, and governance readiness.
  • State the production operating rules that complete the Selenium course.

1. Checkpoint contract

The final lab combines the course into an operating review. The mandatory path remains local and free: use the generated capstone workspace, one live browser if available, a second live browser or simulated lane, optional private local Grid, and the deterministic readiness-packet generator. Hosted browser clouds remain optional.

Authorized targets only

The checkpoint uses loopback/synthetic targets and identities. Do not substitute production accounts, public Grid endpoints, MFA/CAPTCHA bypasses, or real customer data.

2. Preflight and exact assumptions

  • Selenium Python/Grid baseline: 4.47.0.
  • Python: 3.10+ supported by current Selenium Python; local validation may use a newer interpreter.
  • Local driver resolution: Selenium Manager unless your environment explicitly supplies managed binaries.
  • Primary live lane: a supported installed browser (examples use Chromium-family Chrome semantics).
  • Second lane: Firefox if available, otherwise the documented simulated capability lane.
  • Optional container Grid image: selenium/standalone-chrome:4.47.0-20260808, private/loopback published port and adequate shared memory.
  • All identities/data: synthetic, disposable, test-only.

3. Predict before execution

Write at least two predictions before running. Required examples: (1) increasing workers from two to four while Grid capacity stays at two will create queue pressure rather than linear speedup; (2) a shared synthetic identity will collide while unique identities remain independent; (3) a production-like URL will be rejected before WebDriver session creation. Predictions turn observation into causality.

4. Run the browser/matrix path

Start the loopback AUT, run the Chrome lane, run Firefox if available, and inspect evidence/*-session.json. Verify Selenium version, session ID, browser name/version, platform, URL/title, and final DOM state. If Firefox is unavailable, save the simulated matrix output and mark it simulation—not compatibility certification.

5. Exercise parallel/Grid capacity

If you have a private local Grid, run a small controlled parallel experiment at 1, 2, then a higher worker count while recording matching slots, queue delay, wall time, CPU/RAM, and failure rate. If Grid is unavailable, the deterministic checkpoint simulation still teaches the invariant: concurrency above the safe slot/resource ceiling produces queueing/contention, not magical throughput.

6. Inject three failures and preserve first evidence

The required three failures are deliberately safe: shared synthetic identity collision, Grid-capacity queue pressure (live or simulated), and unsafe target blocked by allowlist. You may additionally exercise a stale-reference or BiDi feature-parity failure. For each, capture the symptom, layer, versions/context, first evidence, least-destructive correction, and one forbidden shortcut.

7. Generate the deterministic readiness packet

The following example makes the Generate the deterministic readiness packet behavior concrete. Read it with the stated assumptions, then compare its observable output or state changes with the explanation that follows.

# file: build_readiness_packet.py
from pathlib import Path
import json, hashlib, time

root=Path('capstone-readiness')
(root/'incidents').mkdir(parents=True, exist_ok=True)
(root/'evidence').mkdir(exist_ok=True)

predictions={
  'before': [
    'raising concurrency above the simulated safe Grid capacity will create queue pressure rather than linear speedup',
    'a shared synthetic identity will create a deterministic duplicate-state collision while isolated identities will not',
    'a non-loopback production-like target must be blocked before a browser session is created'
  ]
}
(root/'predictions.json').write_text(json.dumps(predictions,indent=2),encoding='utf-8')

# Controlled matrix/capacity simulation: deterministic, no paid/cloud dependency.
capacity_runs=[]
for workers in [1,2,4]:
    grid_slots=2
    queued=max(workers-grid_slots,0)
    wall_ms=round((600/max(min(workers,grid_slots),1)) + queued*180, 1)
    capacity_runs.append({'workers':workers,'grid_slots':grid_slots,'queued':queued,'wall_ms':wall_ms})
(root/'evidence'/'capacity.json').write_text(json.dumps(capacity_runs,indent=2),encoding='utf-8')

# Three independent incidents with first-failure evidence and least-destructive repair.
incidents=[
  {
    'id':'shared-test-identity', 'symptom':'second order returns duplicate',
    'layer':'AUT/test-data isolation', 'first_evidence':{'identity':'shared@example.test','status':'duplicate'},
    'repair':'allocate unique synthetic identity per test', 'forbidden_shortcut':'retry until green'
  },
  {
    'id':'grid-capacity', 'symptom':'new-session request queues when workers=4 and slots=2',
    'layer':'Grid capacity', 'first_evidence':{'workers':4,'slots':2,'queued':2},
    'repair':'cap runner concurrency at measured safe capacity or add measured private capacity',
    'forbidden_shortcut':'restart Grid'
  },
  {
    'id':'unsafe-target', 'symptom':'target guard blocks https://shop.example.com',
    'layer':'security/authorization', 'first_evidence':{'target':'https://shop.example.com','decision':'blocked'},
    'repair':'use authorized loopback/test environment; obtain explicit approval for any broader target',
    'forbidden_shortcut':'disable the allowlist'
  },
]
for item in incidents:
    (root/'incidents'/f"{item['id']}.json").write_text(json.dumps(item,indent=2),encoding='utf-8')

readiness={
  'security': {'score':5,'evidence':'target allowlist, fake identities, private Grid, redacted/minimized artifacts'},
  'reliability': {'score':5,'evidence':'explicit waits, isolated sessions/data, first-failure policy'},
  'capacity': {'score':4,'evidence':'measured worker/slot ceiling; expand only from data'},
  'maintainability': {'score':5,'evidence':'tests/pages/fixtures/diagnostics boundaries and review contract'},
  'observability': {'score':5,'evidence':'session/capability/test-id correlation plus optional BiDi'},
  'governance': {'score':5,'evidence':'version policy, budgets, owner/runbook, quarantine/deprecation rules'}
}
(root/'readiness-review.json').write_text(json.dumps(readiness,indent=2),encoding='utf-8')

runbook = '# Final operating runbook\n- verify target authorization and environment identity\n- record Selenium/browser/driver/Grid versions and session capabilities\n- run smallest smoke lane, then risk-based browser matrix\n- keep one independent driver/data/evidence namespace per concurrent test\n- preserve first failure before retries or infrastructure mutation\n- classify test/DOM/browser/Grid/CI/AUT/evidence layer\n- enforce measured concurrency and queue budgets\n- redact/minimize artifacts and expire them by policy\n- quarantine only with owner/reason/expiry; never hide incidents with retries\n- rehearse Selenium/browser/Grid upgrades before promotion\n'
(root/'runbook.md').write_text(runbook,encoding='utf-8')

manifest={}
for p in sorted(root.rglob('*')):
    if p.is_file() and p.name!='manifest.json':
        manifest[str(p.relative_to(root))]=hashlib.sha256(p.read_bytes()).hexdigest()
(root/'manifest.json').write_text(json.dumps(manifest,indent=2),encoding='utf-8')

expected_incidents={'shared-test-identity','grid-capacity','unsafe-target'}
actual={p.stem for p in (root/'incidents').glob('*.json')}
assert actual==expected_incidents
assert capacity_runs[-1]['queued']==2
assert all(v['score']>=4 for v in readiness.values())
print('incidents:', sorted(actual))
print('capacity:', capacity_runs)
print('readiness categories:', sorted(readiness))
print('manifest files:', len(manifest))

Run python build_readiness_packet.py. It creates three independent incident files, capacity evidence, predictions, a final runbook, a six-category readiness review, and a SHA-256 manifest. The script asserts that the expected incidents and queue signal are present.

8. Evidence packet checklist

The following table organizes the key choices and evidence for Evidence packet checklist. Use it together with the surrounding prose so the rows serve as a comparison aid rather than standalone rules.

Evidence Why it exists Privacy/correlation rule
Selenium/browser/driver versions + capabilities reproduce support state record exact returned values; no secret fields
session ID / Grid node or queue evidence trace execution placement scope to authorized private Grid
test output + assertion prove behavioral outcome preserve original failure
URL/title/targeted DOM state connect failure to browser/AUT state avoid broad page dumps by default
screenshot/log/BiDi event if needed diagnose UI/browser/network hypothesis redact/minimize; bounded retention
capacity timing/slots/workers separate saturation from flake record environment/hardware context
incident conclusion/runbook action make evidence operational name owner/layer and least-destructive repair

9. Production-readiness review

Score the platform on six dimensions. Security: authorized targets, least-privilege synthetic identities, private Grid, secret controls. Reliability: isolation, stable locators, explicit synchronization, failure-safe teardown. Capacity: measured concurrency/queue/resource budget. Maintainability: test/page/fixture/diagnostic boundaries and ownership. Observability: correlated evidence with optional BiDi. Governance: versions, budgets, upgrade rehearsal, quarantine/deprecation, incident review.

10. Final cleanup and rollback

Quit all sessions; stop the loopback AUT; stop/remove disposable Grid containers/networks/volumes; delete disposable profiles/downloads/test state; remove or retain evidence according to policy; revoke/rotate any accidental credential exposure; and return CI/runner configuration to its pre-lab state. Cleanup is part of the checkpoint result.

11. What the complete Selenium course now gives you

You can now reason from WebDriver session mechanics through locators, element state, waits, actions, contexts, modern DOM, files/session state, abstractions, data, assertions/flakes, compatibility, evidence, BiDi, Grid, containers, concurrency, CI, enterprise auth/network boundaries, security/privacy, capacity, IDE migration, framework bindings, incident diagnosis, and governance. The production operating model is the synthesis: reliable, secure, observable, maintainable browser automation that remains accountable as browsers and delivery systems evolve.

Course complete

Production cross-browser automation operating model complete

Use the course curriculum as the long-term reference map for design, diagnostics, security, capacity, and governance. Revisit the relevant chapter whenever the browser platform, Selenium release, application architecture, or delivery environment changes.

Official references and current-version notes

  • Selenium downloads — Current stable Selenium clients and Selenium Server/Grid 4.47.0, released August 10, 2026.
  • Selenium 4.47 release notes — Current Grid/BiDi/container-related release changes and version baseline.
  • Grid components — Router, New Session Queue, Distributor, Session Map, Event Bus, Nodes and session routing architecture.
  • Grid getting started — Current Grid prerequisites, capacity sizing guidance, and public-access security warning.
  • Grid CLI options — Current Node max-sessions, BiDi/CDP proxying and other version-specific Grid configuration.
  • Avoid sharing state — Current guidance on isolated data and a fresh WebDriver instance per test.
  • Page object models — Current guidance on UI service/locator centralization and keeping business assertions in tests.
  • WebDriver BiDi — Current bidirectional protocol guidance and evolving high-level browser observability/control surface.
  • Docker Selenium — Official images; current full tag examples use 4.47.0-20260808 and shared-memory guidance for browser containers.
Version and compatibility note

Version-sensitive statements in this lesson retain the pinned baseline used when the lesson was authored. Before changing Selenium, browser, driver, Grid, BiDi, container, or framework dependencies, compare that baseline with current primary documentation instead of silently substituting an unverified “latest” environment.

Knowledge checks

Name the three mandatory checkpoint incidents.

Why must predictions be written before the checkpoint actions?

What makes the second-browser simulation honest?

What are the six final readiness dimensions?

What is the final operating principle of the course?

Summary and next bridge

The capstone treats Selenium as one part of a governed browser-automation platform: explicit risk coverage, isolated sessions/data, current version evidence, measured Grid capacity, CI portability, privacy-aware diagnostics, secure boundaries, and evidence-driven incident/governance loops.

Next: Course complete — use the production-readiness runbook to operate and evolve the platform.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this address.