5 ms·
I don't know why a packaged solution (OSS or commercial) doesn't exists for this kind of Authorization. Many companies suffer in silence and cobble together som
by softveda 5y ago
I don't know why a packaged solution (OSS or commercial) doesn't exists for this kind of Authorization. Many companies suffer in silence and cobble together some home grow stuff. The last place I worked and looked at this exact problem the only standard that was available was XACML and it was too complex for our need within the project timeframe so we went with some simple DB based solution
- jitl 5y agoHere’s an open source Zanzibar implementation: https://github.com/ory/keto https://github.com/ory/keto Ory appears to offer a complete stack for the entire AuthN/AuthZ space: https://www.ory.sh https://www.ory.sh (I haven’t used or evaluated this software)
- bradleyjg 5y agoI remember reading the Zanzibar paper (highly recommended) and it depended heavily on spanner—-especially its consistency latency guarantees—-for its nice properties. This looks more like an (in progress) api compatible competitor than a open source clone.
- jakemoshenko 5y agoAt Authzed, our implementation builds on top of CockroachDB (inspired by spanner) to get those same latency and consistency guarantees. As you are someone else who has read the paper, we would love to get your feedback on how well we've captured the spirit.
- bradleyjg 5y agoDo you have a white paper or something? I saw some good blog posts, but I’m interested particularly in the differences with Zanzibar especially those that are the necessary result of the differences between cockroach and spanner.
- jakemoshenko 5y agoWe don't have a white paper. I wrote about my particular interpretation of the Zanzibar paper[1]. As far as the differences due to cockroach vs spanner. There are only a few minor ones. Without TrueTime cockroachdb relies on their hybrid logical clocks[2] which at the very least require more storage. The Zanzibar paper talks about separating tuples into separate databases by namespace, and shards [3§3.1.1]. We haven't had to do that yet, but we are far from operating at Google's scale. Finally, cockroachdb's CHANGEFEED API[4] combined with our single tuple table have allowed us to skip storing a separate changelog table (for now). [1]: https://authzed.com/blog/what-is-zanzibar/ https://authzed.com/blog/what-is-zanzibar/ [2]: https://www.cockroachlabs.com/blog/living-without-atomic-clocks/ https://www.cockroachlabs.com/blog/living-without-atomic-clo... [3]: https://research.google/pubs/pub48190/ https://research.google/pubs/pub48190/ [4]: https://www.cockroachlabs.com/docs/v20.2/changefeed-for.html https://www.cockroachlabs.com/docs/v20.2/changefeed-for.html
- rad_gruchalski 5y agoIt's not complete (no rewrites) and does not provide RBAC component out of the box. It has the pieces but one has to put stuff together themselves. I have written more about it: https://gruchalski.com/posts/2021-05-15-rbac-with-ory-keto/ https://gruchalski.com/posts/2021-05-15-rbac-with-ory-keto/.
- jakemoshenko 5y agoWe're working on just that at Authzed! After being bitten by inflexible authZ in the past, we decided to build a company to solve it. Take a look, we would love any feedback: critical or otherwise.
- FunnyLookinHat 5y agoSystem76 released one recently - https://github.com/system76/recognizer https://github.com/system76/recognizer You're right though - we have a home rolled one where I work that is very robust and could easily be generalized, but it's also fairly simple (to build). I suspect most engineers jump at the chance to get to build a project like this rather than vendoring in something external (whether FOSS or commercial).