5 ms·
Curious what folks think about this versus cedar (https://www.cedarpolicy.com/ https://www.cedarpolicy.com/), the open source policy engine behind aws verified
by ipython 3y ago
Curious what folks think about this versus cedar (https://www.cedarpolicy.com/ https://www.cedarpolicy.com/), the open source policy engine behind aws verified permissions.
- biggestlou 3y agoOPA is much more wide ranging. You can use it for permissions, sure, but also just about anything else you can imagine. I think that makes it much more compelling as a technological investment.
- the_newest 3y agoI work in a highly regulated environment and evaluated using Cedar or OPA. The biggest advantage to OPA was the flexibility. This enabled not just an authorization decision, but the why behind it. No more questions of why did this person/system gain (or was denied) access, combing through dozens of rules to find the matching statements. Just pull up the log and read the results… This is incredibly useful during audits. Cedar could not provide that level of detail (or so I was told by AWS representatives selling their hosted version).
- grinich 3y agoIs that issue with Cedar related to their design or just the current way it's exposed by AWS?
- the_newest 3y agoIt's a cedar related issue. I like to know every check that was run for a policy and the result. Cedar will only provide the name of the policy that granted/denied.
- max2 3y agoSo you want list of all policies that have been considered, not just those that have been satisfied?
- charlieegan3 3y agoI detailed a comparison of OPA and Cedar with verified permissions here: https://www.styra.com/knowledge-center/opa-vs-cedar-aws-verified-permissions/ https://www.styra.com/knowledge-center/opa-vs-cedar-aws-veri...
- AgentOrange1234 3y agoSeems pretty damning. Why would someone choose Cedar? Is there some upside that isn’t captured here?
- jasonjayr 3y agoAWS uses it and the policy language is similar, and if you are all in on AWS, then it makes sense to keep it for consistency?
- max2 3y agoThere is actually pretty vibrant and diverse Cedar community. Check out their slack.
- i_play_stax 3y agohttps://docs.opal.ac/ https://docs.opal.ac/ Universally, people I've met and worked with (20-30) hate writing rego (OPA). I'm always skeptical of Styra's analysis; they are literally selling you something. AuthZed looks interesting and they have good "ride along" videos in YouTube, e.g. replicating GitHub auth. https://authzed.com/ https://authzed.com/
- sarahcec 3y agoThe benefit of Cedar mainly comes down to the language. Cedar was designed to sit in the middle of a runtime call, so it has reliably low latency (see comparison here: https://twitter.com/Sarah_Cecc/status/1766141060370329748 https://twitter.com/Sarah_Cecc/status/1766141060370329748) even at high scale. It's way more readable so it's easier to author and debug. And it's validated against formal methods proofs so certain properties of the language (like default deny) are mathematically proven. More about the benefits of Cedar here: https://cedarland.blog/design/why-cedar/content.html https://cedarland.blog/design/why-cedar/content.html