3 ms·
The distinguishing feature I see compared to other systems is the ACL ordering and consistency, which is indeed difficult to do at scale. Looks like Spanner is
by argd678 7y ago
The distinguishing feature I see compared to other systems is the ACL ordering and consistency, which is indeed difficult to do at scale. Looks like Spanner is doing most the heavy lifting, great use case for the database.
- cryptonector 7y agoIf you don't have negative ACL entries then ordering is not important.
- usaar333 7y agoGP means ordering with respect to time for snapshot reads, which is essential for correctness. (You might be thinking of ordering ACEs in the ACL which isn't even a concept in Zanzibar)
- usaar333 7y agoWell even more broadly it is how generalizable it is, while still providing ordering guarantees (though not necessarily perfect ones.. see my long sibling post) Using Windows style ACEs for ACLs is also perfectly scalable and consistent, (and more performant) so long as users don't end up in too many groups and objects only inherit ACLs from objects on the same shard. It's just no where as generalizable as Zanzibar which allows much more complex dependencies. There's always tradeoffs! But this is the best system I've seen for the general ACL evaluation against non recently updated objects.
- argd678 7y agoI’ve been part of similarly generalized ACL systems and it’s pretty straightforward and very similar to Zanzibar. Though we didn’t need n ACLs and could assume the list wasn’t too long, so we didn’t need a tree. If we did, then we’d have ended up in a similar place as Zanzibar I believe, there are a limited number of ways to solve that problem.