7 ms·
Show HN: Topaz: open-source authorization combining the best of OPA and Zanzibar
- janczukt 4y agoGreat to see an authz app building block based on a robust model as OSS. This is one of those things every app needs but so far most folks were building it in-house (as I can attest myself) instead of focusing on what really moves their app forward. I wish it was available a few years ago when we were starting.
- ogazitt 4y agoThanks! Let us know if you have any feedback!
- ogazitt 4y agoTwo years ago, we founded Aserto to simplify authorization for developers. Authorization is critical and hard to get right, yet isn't a source of differentiation for most applications. Google [1], Airbnb [2], Netflix [3], Carta [4], Intuit [5], and others have written about their authorization systems. It's clear that these are all significant undertakings by sizable teams. Most engineering organizations don't want to spend their precious cycles reinventing this wheel. Over the last two years, we've collected a set of best practices that are common across these projects. We call these the Principles of Authorization [6]. Our goal has been to democratize these principles into an authorization service, and save you time and effort. Topaz [7] is an open source authorization system you can use to start building robust authorization in minutes. It provides fine-grained, real-time, policy-based access control for modern cloud applications. You can deploy it as a sidecar or a microservice in your cloud, ensuring low latency to your application. Topaz combines the best ideas from two cloud-native authorization ecosystems: OPA and Zanzibar. Read our blog post [8] for more on why we built Topaz. Happy hacking! [1] https://research.google/pubs/pub48190/ https://research.google/pubs/pub48190/ [2] https://medium.com/airbnb-engineering/himeji-a-scalable-centralized-system-for-authorization-at-airbnb-341664924574 https://medium.com/airbnb-engineering/himeji-a-scalable-cent... [3] https://www.infoq.com/presentations/authorization-scalability/ https://www.infoq.com/presentations/authorization-scalabilit... [4] https://medium.com/building-carta/authz-cartas-highly-scalable-permissions-system-782a7f2c840f https://medium.com/building-carta/authz-cartas-highly-scalab... [5] https://medium.com/intuit-engineering/authz-intuits-unified-dynamic-authorization-system-bea554d18f91 https://medium.com/intuit-engineering/authz-intuits-unified-... [6] https://www.topaz.sh/docs/intro#principles https://www.topaz.sh/docs/intro#principles [7] https://github.com/aserto-dev/topaz https://github.com/aserto-dev/topaz [8] https://www.aserto.com/blog/topaz-oss-cloud-native-authorization-combines-opa-zanzibar https://www.aserto.com/blog/topaz-oss-cloud-native-authoriza...
- apoland 4y agoGreat work Aserto team. Exciting to see this code released to the community.
- ogazitt 4y agoThanks! :)
- bradhe 4y agoAh, super cool to see an implementation of Zanzibar out in the wild. The paper looked really interesting when it bubbled up on HN a while back. Wonder if there are planned integrations with any stacks? For instance, would be super cool to see how this could plug into Rails/ActiveRecord for a kind of out-of-the-box authorization experience.
- ogazitt 4y agoThanks! We do have Rack middleware [1], as well as a Rails integration [2]. Let us know what you think! [1] https://www.topaz.sh/docs/software-development-kits/ruby/middleware https://www.topaz.sh/docs/software-development-kits/ruby/mid... [2] https://www.topaz.sh/docs/software-development-kits/ruby/rails https://www.topaz.sh/docs/software-development-kits/ruby/rai...
- robertlagrant 4y agoOry [0] is also an OSS Zanzibar implementation. [0] https://ory.sh https://ory.sh
- Aeolun 4y agoTrying to set up Ory was really hard though. It’s like all these ostensibly OS libraries deliberately make it hard to set up to drive you to their paid offering.
- ogazitt 4y agoWould love any feedback you have on setting up Topaz, if you choose to give it a try! We built it to be useful completely standalone.
- rhamzeh 4y agoLove the growing number of OSS Zanzibar implementations, and congrats to the Aserto team for launching Topaz! Ory Keto's intro video @ SV IAM User Group [0] is worth a watch. Other OSS Zanzibar implementations: - https://github.com/authzed/spicedb https://github.com/authzed/spicedb - https://github.com/Permify/permify https://github.com/Permify/permify - https://github.com/openfga/openfga https://github.com/openfga/openfga [0]: https://www.youtube.com/watch?v=3vtTFLB_jDo https://www.youtube.com/watch?v=3vtTFLB_jDo [Disclaimer: On the OpenFGA team]
- jzelinskie 4y agoCongrats on the launch! Combining policy with Zanzibar is super cool and it's great to see the folks in the OPA ecosystem moving in this direction. Most of the novelty of the Zanzibar paper is about scaling ReBAC systems that might not be applicable in a system that starts with policy. Unfortunately, I found the website a little vague on technical details and had some questions: - I'm curious how this is different from using an API client in rego, which other projects like OpenFGA and SpiceDB support. - It seems like for the variety of projects in this space "Zanzibar" is used to mean many different things mentioned in the paper. Can you clarify which properties Topaz is inspired by? From the documentation, I can only find references to tuples and union rewrites[0]. Disclosure: I work on SpiceDB, an established open source project also "inspired by Zanzibar" that also has policy integrations with OPA and Google's CEL. [0]: https://www.topaz.sh/docs/directory/define-domain-model https://www.topaz.sh/docs/directory/define-domain-model
- gertd 4y agoWhen it comes to integration of external capabilities in OPA there are only two options: make a REST call, or add a built-in. We provide a set of OPA built-ins which enable the integration which are documented here: https://www.topaz.sh/docs/directory/built-ins https://www.topaz.sh/docs/directory/built-ins.
- jzelinskie 4y agoBoth REST and built-ins for OPA have been available for existing projects like OpenFGA[0] and SpiceDB[1]. In case of SpiceDB, the first built-in was actually available in June of last year[2]. Since there is a clear interest from the existing communities with mature solutions, it'd be awesome to collaborate for the graph layer. Speaking from the SpiceDB community, we'd be glad to welcome you -- this is what open source is all about! [0]: https://github.com/thomasdarimont/custom-opa-openfga https://github.com/thomasdarimont/custom-opa-openfga [1]: https://github.com/thomasdarimont/custom-opa-spicedb https://github.com/thomasdarimont/custom-opa-spicedb [2]: https://github.com/authzed/zed/pull/5 https://github.com/authzed/zed/pull/5
- 4y ago
- renszarv 4y agoYet another golang gRPC authorization framework... That couple of ms response time for a decision could be fine,if you only call a couple of time per request,but its quickly adds up
- gertd 4y agoWhich is exactly why using a middleware is an option and therefore a decision the implementor makes. Many people appreciate the middleware approach as it provides coverage for the API surface with minimal investment, so a great way to get started. But there is no free lunch
- lakomen 4y agoThat still doesn't change the fact of it increasing response times. That is not a solution to the problem the OP posted.
- fleddr 4y agoYou may have some SEO problems with a name like that. Topaz is a very popular suite of (AI-driven) photo editing tools.
- bdcravens 4y agoTopaz was also an implementation of Ruby written in Python https://docs.topazruby.com/en/latest/ https://docs.topazruby.com/en/latest/
- machiaweliczny 4y agoTopaz is also polish combat system
- Blokje5 4y agoI actually worked on an implementation based on the Zanzibar paper using OPA at the previous company I worked at. We actually used a Proxy running in front of the microservice to determine whether the request was authorized or not. We were working in Healthcare and the authorization requirements for healthcare are quite complicated. Every Microservice needed to handle 50 different roles and get the permissions right for each endpoint, so a more centralised approach made a lot of sense to prevent these types of mistakes Cool to see an open source implementation of the idea. Authorization in general is such a hard topic to get right in a microservice architecture. I'd be happy to take a look at the project and see if I can contribute as well!
- ogazitt 4y agoThanks! Would love to exchange ideas. Please feel free to join our community slack [0] or open an issue on the GitHub tracker [1]. We also accept PR's :) [0] https://www.aserto.com/slack https://www.aserto.com/slack [1] https://github.com/aserto-dev/topaz/issues https://github.com/aserto-dev/topaz/issues
- lakomen 4y agoIt looks interesting, but I would rather like a package I can import and use locally than running an independent service, because of latency/performance.