4 ms·
Yeah, although mostly variations on that basic premise. Airbnb Himeji: https://medium.com/airbnb-engineering/himeji-a-scalable-centralized-system-for-authoriza
by gkaemmer 5y ago
Yeah, although mostly variations on that basic premise.
Airbnb Himeji: https://medium.com/airbnb-engineering/himeji-a-scalable-centralized-system-for-authorization-at-airbnb-341664924574 https://medium.com/airbnb-engineering/himeji-a-scalable-cent...
Carta's AuthZ system: https://medium.com/building-carta/authz-cartas-highly-scalable-permissions-system-782a7f2c840f https://medium.com/building-carta/authz-cartas-highly-scalab...
Slack's architecture is a bit different, but solves some of the same challenges: https://slack.engineering/role-management-at-slack/ https://slack.engineering/role-management-at-slack/
I've also talked to a number of teams who just implemented pattern 3 internally with a custom service. Generally they've determined it's worth it to centralize all authorization data (like roles, groups, etc) into one place and perform ALL permission checks there.
There are also some companies building essentially Zanzibar clones, like Auth0, Authzed, Ory Keto, and a few more.