Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alex-olivier
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
alex-olivier
3y ago
OPA and its derivative projects really brought the idea of decoupled authorization as a viable option. It is a very powerful tool which can be applied to many layers of the architecture - from Kubernetes Admission Controllers being based on
2.
▲
by
alex-olivier
3y ago
tldr
3.
▲
by
alex-olivier
4y ago
(Disclaimer: I work for Cerbos[1]) When we started working on Cerbos[1] the very first external bit of tooling we released was the Cerbos Playground[2] which does exactly what you say - allows you to see the requests and responses as they m
4.
▲
by
alex-olivier
4y ago
When it comes to Authentication and Authorization, these are both core components of a system but undifferentiated building blocks so wouldn’t recommend building them yourself. Typically using something like Auth0, Cognito, Firebase Auth, F
5.
▲
by
alex-olivier
4y ago
Not the only permissions issue at GitHub https://cerbos.dev/blog/githubs-inconsistent-access-control
6.
▲
by
alex-olivier
5y ago
Disclaimer: I work for Cerbos[0]. Whilst this is a very good approach when all your data is stored in a single datastore, as applications grow it is common to start breaking out into more optimised data stores eg you may have few relational
7.
▲
How to Incrementally Adopt New Authorization Systems
(cerbos.dev)
1 points
by
alex-olivier
5y ago
|
0 comments
8.
▲
by
alex-olivier
5y ago
(I lead product at Cerbos[1]) Certainly agree and we have seen a lot of cases of JWT tokens getting bloated with more and more authorization data. Using JWTs to hold the autheNtication information is a standard now but consuming that and ap
9.
▲
The Case Against Token-Based Authorization
(cerbos.dev)
9 points
by
alex-olivier
5y ago
|
3 comments
10.
▲
The never-ending product requirements of user authorization
(twitter.com)
1 points
by
alex-olivier
5y ago
|
0 comments
11.
▲
The Case Against Token-Based Authorization
(cerbos.dev)
3 points
by
alex-olivier
5y ago
|
0 comments
12.
▲
Startups that show how open source ate the world in 2021
(venturebeat.com)
1 points
by
alex-olivier
5y ago
|
0 comments
13.
▲
Homegrown security scales and works, if you have a full time dedicated team
(cerbos.dev)
1 points
by
alex-olivier
5y ago
|
0 comments
14.
▲
by
alex-olivier
5y ago
Thanks for the feedback - are are working on adding more comparisons of technologies onto https://cerbos.dev and will certainly make sure to include OAuth
15.
▲
by
alex-olivier
5y ago
We are working through the priority list of SDKs. You can find them all on https://github.com/cerbos/ Node, Java and Go are already available and other languages are coming very soon.
16.
▲
by
alex-olivier
5y ago
Author of the article here. This is a very common question we get. OAuth is great for when the permissions can be modelled as a set of roles/scopes which apply uniformity. Where that breaks down as described in the article is when ther
17.
▲
by
alex-olivier
5y ago
What help do you need? It's free and open source - https://cerbos.dev/
18.
▲
by
alex-olivier
5y ago
Disclaimer: I am Product Lead @ Cerbos[0] - an open-source authorization service This article is a great summary of exactly why this area is rife for innovation and we love seeing different approaches to solve the headache of authz. Coincid
19.
▲
by
alex-olivier
5y ago
Thank you! Every bit of feedback is appreciated
20.
▲
by
alex-olivier
5y ago
Having wasted a couple of engineers time a year on building and managing permissioning systems, the challenge and complexity really rings true This is especially painful in B2B businesses where your customers have their own set of requireme
21.
▲
by
alex-olivier
5y ago
RBAC can get you a long way, but there comes a time when you need even more granular permissions that are context aware (eg is the user an owner of the thing they are accessing and are they accessing from an internal IP address) https:
22.
▲
by
alex-olivier
5y ago
I hear you! Ended up building such a system so many times, so much we've built an open-source, self-hosted system to do it out of the box! https://cerbos.dev Would love your feedback!
23.
▲
by
alex-olivier
5y ago
...and by that I mean authorization is the next big challenge especially in a multi-tenant/multi-enterprise SaaS type platform
24.
▲
by
alex-olivier
5y ago
I tend to fall in the trap of once you have authenticated the person and passing tokens around that can hold claims/role for authorization, you will eventually reach the point where the tokens are getting so bloated due to the complexi
25.
▲
by
alex-olivier
6y ago
yes!
26.
▲
Static site hosting on GCP with SSL for basically free with Cloudflare
(alexolivier.me)
3 points
by
alex-olivier
6y ago
|
2 comments
27.
▲
by
alex-olivier
7y ago
The 'official' method is programmatically DIY! https://cloud.google.com/billing/docs/how-to/notify#cap_disa...
28.
▲
by
alex-olivier
7y ago
Don't have an exact time, but the bulk of the time is app startup vs container scheduling
29.
▲
by
alex-olivier
7y ago
Do-able today with GCP Billing
30.
▲
by
alex-olivier
7y ago
Definitely something I look out for, but the advantage over something like Cloud Functions, which would be an alternative, is that a Cloud Run service handles multiple requests per instance so it isn't 1:1 with request rate.
More ›