Skip to content

fix: route CogIdP auth to dev instance for dev clusters (AUTH-4275) - #3172

Open
EliasBjorne wants to merge 1 commit into
mainfrom
eliasb/toolkit-555f5642
Open

fix: route CogIdP auth to dev instance for dev clusters (AUTH-4275)#3172
EliasBjorne wants to merge 1 commit into
mainfrom
eliasb/toolkit-555f5642

Conversation

@EliasBjorne

@EliasBjorne EliasBjorne commented Aug 28, 2026

Copy link
Copy Markdown

Summary

  • When PROVIDER=cdf, the OAuth token URL and CogIdP admin API base were hardcoded to the production CogIdP instance (https://auth.cognite.com), even for dev clusters.
  • After the Auth team's migration (AUTH-4275), cog-dev-* orgs on dev clusters (az-arn-dev-002, aws-dub-dev, gc-bru-dev-003) now require the CogIdP dev instance (https://auth-dev.cognitedata-development.cognite.ai).
  • This PR auto-detects dev clusters by checking whether the CDF_CLUSTER name contains -dev and routes accordingly — no env-var changes needed from the user.

Changed files

  • cognite_toolkit/_cdf_tk/utils/auth.pyidp_token_url now returns the CogIdP dev token URL for dev clusters
  • cognite_toolkit/_cdf_tk/client/config.pycreate_auth_url() now builds URLs against the CogIdP dev API base for dev clusters

Test plan

  • Unit test: EnvironmentVariables(CDF_CLUSTER="az-arn-dev-002", ..., PROVIDER="cdf").idp_token_url returns https://auth-dev.cognitedata-development.cognite.ai/oauth2/token
  • Unit test: EnvironmentVariables(CDF_CLUSTER="westeurope-1", ..., PROVIDER="cdf").idp_token_url returns https://auth.cognite.com/oauth2/token (no regression)
  • Unit test: config.create_auth_url("/principals/me") returns the correct base URL based on cluster
  • Manual: run cdf auth verify against a cog-dev-ai project on az-arn-dev-002

Context

Jeremy St. Ange flagged in Slack that the CLI breaks for users of the cog-dev-ai org after the Auth team switched dev clusters to CogIdP dev as primary source of truth. Related Jira: AUTH-4275.

Made with Cursor

When PROVIDER=cdf and the CDF_CLUSTER name contains '-dev'
(e.g. az-arn-dev-002, aws-dub-dev, gc-bru-dev-003), point the
OAuth token URL and admin API base at CogIdP dev
(https://auth-dev.cognitedata-development.cognite.ai) instead of
the production instance (https://auth.cognite.com).

This unblocks teams using cog-dev-* orgs after the Auth team migrated
dev clusters to CogIdP dev as their primary source of truth (AUTH-4275).

Co-authored-by: Cursor <cursoragent@cursor.com>
@EliasBjorne
EliasBjorne requested review from a team as code owners August 28, 2026 06:16
@gemini-code-assist

Copy link
Copy Markdown
Contributor
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant