12.16 Sets in DevOps
Five places sets are the natural fit in infrastructure code -- deduplicating IP addresses from logs, comparing installed vs. required packages, diffing security group rules, flagging duplicate log lines, and comparing server inventories.
Five places sets are the natural fit in infrastructure code — specifically because deduplication and fast comparison matter, the same reason tuples show up in 11.12 Tuples in DevOps for fixed records and lists show up in 10.15 Lists in DevOps for ordered collections.
Unique IP Addresses
>>> log_ips = ["10.0.0.1", "10.0.0.2", "10.0.0.1", "10.0.0.3"]
>>> set(log_ips)
{'10.0.0.1', '10.0.0.2', '10.0.0.3'}
Installed Packages
Comparing what’s installed against what’s required with set difference — instantly reveals missing packages.
>>> installed = {"nginx", "redis", "curl"}
>>> required = {"nginx", "redis", "postgres"}
>>> required - installed # missing packages
{'postgres'}
Security Groups
Finding ports allowed by both of two security groups via intersection — useful when auditing overlapping rule sets.
>>> sg1 = {"22", "80", "443"}
>>> sg2 = {"80", "443", "8080"}
>>> sg1 & sg2
{'80', '443'}
Duplicate Log Detection
Tracking a running “seen” set while scanning lines to flag exact repeats — a lightweight duplicate-log detector.
seen, duplicates = set(), set()
for line in ["a", "b", "a", "c"]:
if line in seen:
duplicates.add(line)
seen.add(line)
>>> duplicates
{'a'}
Inventory Comparison
Comparing a current server fleet against the expected one — reporting what’s missing and what’s extra with two differences run in opposite directions.
>>> current = {"web01", "web02", "db01"}
>>> expected = {"web01", "web02", "web03"}
>>> print("missing:", expected - current)
missing: {'web03'}
>>> print("extra:", current - expected)
extra: {'db01'}
Quick Interview Answer
“Sets show up in DevOps tooling anywhere the question is ‘what’s unique,’ ‘what’s missing,’ or ‘what overlaps’ — deduplicating IPs pulled from a log file, diffing an installed-package set against a required one to find gaps, intersecting two security groups’ ports to audit overlapping access, and comparing a current server fleet against an expected inventory to report both what’s missing and what’s unexpectedly extra. The common thread is that each of these is a single set operation instead of nested loops:
required - installedfor missing packages,sg1 & sg2for shared ports, two differences run in both directions for a full inventory diff.”
Common Mistakes
- Using nested
forloops to compare two lists of servers or packages, instead of converting both to sets and using-,&, or^directly. - Reporting only
expected - currentfor an inventory comparison and forgettingcurrent - expected— the first shows what’s missing, the second shows what’s unexpectedly extra; a complete audit usually needs both. - Deduplicating IP addresses or package names with a set, then needing the original order back for a report — sets discard order, so keep (or re-sort) a separate ordered structure if the sequence matters downstream.
Add More Questions to This Guide
Know a question that should be here? Share it and help the community!
Open Google Form