8 ms·
Show HN: CEL by Example
- d4mi3n 8mo agoI've seen but haven't used CEL. Anybody with experience with competing tech have any strong opinions? I've used OPA, know CEL used by GCP and Kyverno, but otherwise haven't seen anything compelling enough to move away from the OPA ecosystem.
- erdii 8mo agoThe kubernetes apiserver allows using CEL in CustomResourceDefinition validation rules: - https://kubernetes.io/docs/reference/using-api/cel/ https://kubernetes.io/docs/reference/using-api/cel/ - https://kubernetes.io/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definitions/#validation-rules https://kubernetes.io/docs/tasks/extend-kubernetes/custom-re... It also allows using CEL in ValidatingAdmissionPolicies: - https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/#validation-expression https://kubernetes.io/docs/reference/access-authn-authz/vali...
- mtrimpe 8mo agoCEL is much more computationally limited as it aims to keep evaluations in the microsecond range. With OPA you can easily create policies that take tens, hundreds or even thousands of millisecond. That comes at the expense of a lot of power though, so much of the complex logic that you can write in OPA simply isn't achievable in CEL.
- isacikgoz 8mo agoI think apples to apples comparison would be comparing against Rego. To me CEL is more appealing due to its simplicity.
- talideon 8mo agoAnd even then, I'm not sure it's apples to apples, at least if by Rego you're thinking of OPA. CEL and Rego take very different approaches, with CEL being quite procedural, while Rego is about constraint satisfaction, not unlike Prolog. At $WORK, Rego (in the form of OPA) gets used quite a bit for complicated access control logic, while CEL gets used in places where we've simpler logic that needs to be broken out and made configurable, and a more procedural focus works there.
- thayne 8mo agoRego is much more powerful, and can do things cel can't.
- hamandcheese 8mo agoDoes CEL have any way to import other files? i.e. could it serve as a general purpose config language like jsonnet?
- talideon 8mo agoIt's not really a configuration language like Jsonnet and CUE. It's an expression language for specifying things like conditions and policies. You _could_ abuse it as a configuration language, but it'd be overkill.
- progbits 8mo agoYup, it's really a good fit for simple constraints eg in IAM systems. Give user X permission to do Y, but subject to some CEL expression like date comparison (auto-expiring grants), resource path prefix or similar.
- simmonmt 8mo agoThat's an anti pattern, at least the way we use it. If you need to add complexity, you define custom functions. If that's not enough, CEL probably isn't the right choice, and you'd be doing yourself no favors banging it into that square hole.
- IshKebab 8mo agoIt seems weird to require an entirely new programming language for this tbh. They make the claim that it is special because it's not Turing-complete, but that's nonsense. Turing completeness is almost never a property that is important. I think in this case they're equating Turing incompleteness with "doesn't take a long time to execute" but that isn't really the case at all. The property you really want is "can be cancelled after a certain amount of compute time - ideally a deterministic amount", and you can obviously do that with Turing complete languages.
- joshuamorton 8mo agoWhat you really want is "can be completed after a certain amount of time", not "can be cancelled". You don't want iam policy rules to be skipped because they took too long.
- IshKebab 8mo agoWell CEL doesn't offer that guarantee. For any given "certain amount of time" you can write a CEL filter that takes longer.
- dilyevsky 8mo agoSee my other comment - you can refuse to accept CEL filters that take too long to begin with.
- joshuamorton 8mo agoCorrect, but you can also reject filters that will take longer statically. The point is not "any arbitrary CEL program will run in less than 10us", it's that I can encode "do not allow filters that take more than 10us to evaluate" an then have a very high degree of confidence that that will be true for any user provided filter that is accepted (and if I'm wrong it'll be...11us, not 5s) In the common use-cases for CEL that I've seen, you don't want to skip evaluation and fail open or closed arbitrarily. That can mean things like "abusive user gets access to data they should not be allowed to access because rule evaluation was skipped". You also may have tons of rules and be evaluating them very often, so speed is important.
- bossyTeacher 8mo agoI would love if languages like Scala, Swift or F# had something like Cel but running at compile time so your program was evaluated against those restrictions. I believe a language called Idris has something like this
- nivertech 8mo agoA better solution would be first-class metaprogramming, like in Zig or LISP. Maybe with some subset which guarantees to halt (I.e. no unbounded loops, no recursion, no FFI, known input size, hard time limits, etc.)
- yegle 8mo agoAre you suggesting to compile CEL into native code and run the compiled code at runtime (i.e. as a predicate function)? I think this is doable and I vaguely remember this was how it's implemented initially. But most use cases are treating CEL as a user provided config, which requires runtime parsing and execution.
- bossyTeacher 8mo agoI was thinking of something like this: type MyType{ myName: string where size > 8, year: number where number > 2000 } Then, whenever this type is used, at compile time, an evaluation is done to ensure that the type restrictions are enforced.
- madduci 8mo agoCEL is used a lot in FHIR as Path Expressions
- PantaloonFlames 8mo agoI did not know that. Path expressions for access control?
- madduci 8mo agoMostly for validating the FHIR Resources themselves
- yegle 8mo agoI think people commenting misunderstood what CEL offers. Remember the famous https://en.wikipedia.org/wiki/Greenspun%27s_tenth_rule https://en.wikipedia.org/wiki/Greenspun%27s_tenth_rule? > Any sufficiently complicated C or Fortran program contains an ad hoc, informally-specified, bug-ridden, slow implementation of half of Common Lisp. CEL is a well specified, reasonably fast "embeddable" language with familiar syntax. I'm sure there are other languages that fits the description though.
- ivaniscoding 8mo agoShameless plug, but if you want to try CEL in your browser: https://celq-playground.github.io/ https://celq-playground.github.io/ I wrote the playground and I should link to your website in my docs. This is neat.
- bhawks 8mo agoCEL is useful for any custom computation you want to do on your critical path without having that blow out in a ridiculous fashion. Yes you can embed other languages however constraining evaluation costs is not a first class feature.