Skip to content

PER-16377: retire the eu region in the CLI - #149

Merged
EliMoshkovich merged 3 commits into
mainfrom
eli/per-16377-retire-eu-region
Sep 29, 2026
Merged

EliMoshkovich merged 3 commits into
mainfrom
eli/per-16377-retire-eu-region

Conversation

@EliMoshkovich

Copy link
Copy Markdown
Contributor

Permit's EU region was torn down on 2026-09-28 (PER-16073 / PER-16377). All customers are on the US region, and every EU host (api.eu, app.eu, cloudpdp and pdp-statistics under eu-central-1) is gone. This removes eu from the CLI.

What changed

  • source/config.ts: PermitRegion is now just 'us' and the EU URL mappings are removed. The URL getters return the same US URLs as before. Each getter checks the configured region first and throws RetiredRegionError if it is eu (case-insensitive), so no URL, and so no request, can be built for it.
  • The unused CLOUD_PDP_URL / PERMIT_API_URL / ... constants computed at import time are removed. Their three callers (facts API, pdp run config fetch, pdp stats) now use the getters. The values are the same.
  • login: --region only documents us. --region eu prints the retirement message and exits 1 before the login flow starts.
  • AuthProvider: it used to swallow every loadRegion() failure and continue as US. Keychain read errors are still ignored, as before. A stored eu now stops with the error instead of going to the login flow or to US. This covers both the stored-token path and the --api-key path.
  • cli.tsx: PERMIT_REGION=eu is rejected at startup, before any command runs.
  • README: the EU examples are removed, and there is a short note on how to recover.
  • Terraform generators: they already get api_url from getPermitApiUrl() and had no EU values of their own, so they need no code change. They now always emit https://api.permit.io, or fail for eu.

What users with eu saved will see

The Permit EU region was retired on 2026-09-28 and its endpoints no longer exist. All Permit accounts are now served from the US region. Unset PERMIT_REGION if it is set to "eu", then run `permit logout` and `permit login` (without --region, or with --region us) to log in again.

The CLI then exits with code 1. permit logout clears the stored region, as before. It is only blocked if PERMIT_REGION=eu is still set in the environment, and the message covers that case.

Testing

  • npm run build, npm run lint (0 errors; the 8 warnings are all in files and lines this PR doesn't touch), npm run test:ts, and npm run test all pass: 117 files, 690 tests.
  • The tests that asserted EU URLs (tests/lib/config.test.ts, client-region.test.ts, auth-oauth-region.test.ts, auth.test.ts) are replaced. They now check that every getter returns the US URL, that eu throws in every getter, that useClient and browserAuth fail without calling createClient or opening the browser, and that a stored eu is rejected by loadRegion.
  • New tests/components/AuthProviderRetiredRegion.test.tsx: with eu in the keychain, both the stored-token and --api-key paths show the error, never call fetch and exit 1, and a stored us still reaches https://api.permit.io. I checked that these tests fail against the old AuthProvider.
  • New tests/loginRetiredRegion.test.tsx: login --region eu shows the error, makes no request and writes nothing to the keychain.
  • I also ran the built CLI by hand. PERMIT_REGION=eu permit env export terraform, PERMIT_REGION=eu permit logout and permit login --region eu all print the message and exit 1.

🤖 Generated with Claude Code

Permit's EU region was torn down on 2026-09-28; every EU host is gone.
Drop eu as a selectable region and remove its URL mappings. A saved or
passed eu (PERMIT_REGION, the keychain value, or --region eu) now fails
with a clear error before any request, instead of falling back to US
and sending the old EU credentials there. US URLs are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 28, 2026 19:54
@linear-code

linear-code Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

PER-16377

PER-16483

PER-16485

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

zeevmoney and others added 2 commits September 28, 2026 23:15
A user with eu saved in the keychain who ran `permit login` without
--region got a successful login, but the keychain kept eu, so the next
command failed again with the retired-region error. Login now saves us
after the token on every successful login, which replaces the stale
value. A keychain failure while saving it is shown as a login error
instead of an unhandled rejection.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Cover the cli.tsx fail-fast path: with PERMIT_REGION=eu the CLI prints
the retirement message and exits 1 before any command runs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 28, 2026 20:15

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@EliMoshkovich
EliMoshkovich merged commit 745e8a3 into main Sep 29, 2026
3 of 4 checks passed
@EliMoshkovich
EliMoshkovich deleted the eli/per-16377-retire-eu-region branch September 29, 2026 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants