3 ms·
Looks good. 1. How does this compare with Ory Keto? https://www.ory.sh/keto/docs/ 2. Can it be nativity (I can integrate in Postgres SQL) integrated with
by ipodopt 5y ago
Looks good.
1. How does this compare with Ory Keto?
https://www.ory.sh/keto/docs/
2. Can it be nativity (I can integrate in Postgres SQL) integrated with Row Level Security in Postgres?
3. Any interest in supporting TiDB as a backend?
Edit: Number questions.
- jzelinskie 5y agoDisclosure: Another founder of Authzed, here. Also, in case anyone was wondering, yes, SpiceDB is reference both Zanzibar and a popular sci-fi novel that will be in cinemas shortly. >1. How does this compare with Ory Keto? The blog post has a section dedicated to how SpiceDB improves on the Zanzibar paper[0]. Keto was originally a different project that has been rewritten to be Zanzibar-like. It is missing lots of the core functionality that I'd personally consider requirements to really be faithful to the paper: horizontally scalable, bounded staleness (Zookies), and userset rewrites, for example. ORY also develops a whole identity suite, while we're attempting to stay laser-focused on permissions and maintain vendor-neutrality. >2. Can it be nativity (I can integrate in Postgres SQL) integrated with Row Level Security in Postgres? We have been exploring the space between integrating deeply with Postgres from both entrypoints (SpiceDB->Postgres and Postgres->SpiceDB). For the former, we're playing with representing applications' Postgres databases as a read-only SpiceDB datastores. For the latter, we've checked out Postgres Foreign Data Wrappers, but they don't seem portable to the cloud hosted services like RDS. We're continuing to look for clever solutions, if anyone reading this bumps into any. >3. Any interest in supporting TiDB as a backend? I've created an issue for this[1]. [0]: https://authzed.com/blog/spicedb-is-open-source/#everybody-is-doing-zanzibar-how-is-spicedb-different https://authzed.com/blog/spicedb-is-open-source/#everybody-i... [1]: https://github.com/authzed/spicedb/issues/154 https://github.com/authzed/spicedb/issues/154
- ipodopt 5y agoThanks! :)
- mst 5y ago> For the latter, we've checked out Postgres Foreign Data Wrappers, but they don't seem portable to the cloud hosted services like RDS. My experience is that teams who want the full power of postgresql run their own compute nodes because of limitations like this. It's a trade-off, as almost everything is, but I suspect the sort of company who's buying in to things like RLS is also the sort of company who're reasonably likely to have already migrated off RDS in digust. I could easily be wrong, of course, but at the very least I think it's worth asking your users before assuming that excluding RDS would be a problem for the people who would want the feature in the first place.
- ipodopt 5y ago> For the latter, we've checked out Postgres Foreign Data Wrappers, but they don't seem portable to the cloud hosted services like RDS. We're continuing to look for clever solutions, if anyone reading this bumps into any. Probably off the mark here but... View -> Function -> Table (Atomic Permissions) - On Miss -> Rest Call to SpiceDB RLS: CREATE POLICY "Resources are updateble by certain groups of users." ON public.resources for UPDATE USING ( EXISTS ( SELECT FROM atomic_permissions_view WHERE (user_id = auth.uid()) and (action_enum = 'modify') and (resource_id = id) ) ); Where resources inherit from resources tables..
- jpgvm 5y agoRDS supports `postgres_fdw` on pretty much all versions of vanilla PG and Aurora PG. This should be sufficient to implement what you described. Though if you wanted to go one step further you could use `postgres_fdw` to connect to a bunch of stateless PG boxes running OSS PG and have those load non-supported FDWs in order to support all sorts of backends like `mysql_fdw` and friends. Adds a proxy hop but makes it possible to do all sorts of very cool things. Hit me up if you want to talk more PG/Zanzibar things. PS: I wrote this to get an idea of Zanzibar but I haven't used it in anger yet: https://github.com/josephglanville/zanzibar-pg https://github.com/josephglanville/zanzibar-pg