During the 2026-09-01 simulation-entrypoint outage (PolicyEngine/policyengine-sim-api#674), the v1 API turned an upstream 429 Too Many Requests into a raw 500 shown verbatim in app-v2:
Society-wide calculation failed (500): {"status": "error", "message": "Client error '429 Too Many Requests' for url 'https://simulation.api.policyengine.org/versions/policyengine'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/429", "result": null}
Two hardenings in policyengine_api/libs/simulation_entrypoint.py (and the economy service around it):
- Bounded retry with backoff on 429/503 for the cheap control-plane calls —
resolve_app_name (GET /versions/policyengine, GET /versions/{country}) and job polling. These are tiny idempotent GETs; a 3-attempt exponential backoff (~0.5s/2s/8s, honoring Retry-After when present) would have ridden out the burst edges instead of failing user reports instantly. Do NOT retry job submission unconditionally (double-spawn risk).
- Error mapping: upstream 429/5xx should surface as a retryable "computing infrastructure is busy, try again shortly" status/message to clients, not an httpx exception string with an MDN link. The raw string ends up rendered in the app's report error card.
A versions-map cache (short TTL, e.g. 60s) in the v1 API would also remove the /versions/policyengine round-trip from the critical path of every economy calculation — it changes only on sim-api deploys.
During the 2026-09-01 simulation-entrypoint outage (PolicyEngine/policyengine-sim-api#674), the v1 API turned an upstream
429 Too Many Requestsinto a raw 500 shown verbatim in app-v2:Two hardenings in
policyengine_api/libs/simulation_entrypoint.py(and the economy service around it):resolve_app_name(GET /versions/policyengine,GET /versions/{country}) and job polling. These are tiny idempotent GETs; a 3-attempt exponential backoff (~0.5s/2s/8s, honoringRetry-Afterwhen present) would have ridden out the burst edges instead of failing user reports instantly. Do NOT retry job submission unconditionally (double-spawn risk).A versions-map cache (short TTL, e.g. 60s) in the v1 API would also remove the
/versions/policyengineround-trip from the critical path of every economy calculation — it changes only on sim-api deploys.