Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ogazitt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
ogazitt
4y ago
Auto-scaling for ML workloads, integrated with the TF workflow - very cool!
32.
▲
by
ogazitt
4y ago
The playground is cool. The time-travel component is really neat!
33.
▲
by
ogazitt
5y ago
Disclaimer: I work on Aserto [0] (one of those new dev authorization systems). First, it seems like we both agree that having the flexibility to extend a base model is a good thing, whether that base model is OPA or Zanzibar. I wouldn'
34.
▲
by
ogazitt
5y ago
Did you represent user -> role mappings in your postgres db, or did you model ACLs for every object?
35.
▲
by
ogazitt
5y ago
In the "Zanzibar [0] vs OPA [1]" debate, the pragmatic answer is "both". [0] https://research.google/pubs/pub48190/ [1] https://www.openpolicyagent.org/
36.
▲
by
ogazitt
5y ago
We have based our entire deployment pipeline on GHA. Works great when it works... and after all the outages of the past month, we're working on an exit strategy.
37.
▲
by
ogazitt
5y ago
I love that design decision. How about authorization? :) disclaimer: I am a co-founder of Aserto [0], an authorization platform for developers. I think it would be awesome to explore how to grow the authorization model from a simple set of
38.
▲
by
ogazitt
5y ago
Congrats! It's nice to see that authentication and authorization are handled in the framework from day 1. This is often overlooked, but such a critical part of building new applications.
39.
▲
by
ogazitt
5y ago
Very much agree that authorization is a more domain-specific problem than authentication... but there are some common patterns that are emerging, and can help reduce how much wheel reinvention has to happen. There are (at least) three of us
40.
▲
by
ogazitt
5y ago
Great article! Disclaimer: I'm a co-founder of Aserto [0], where we're building a platform for API / microservices authorization. I couldn't agree more that the question of how to get the data to the policy decision poin
41.
▲
by
ogazitt
5y ago
You do need to have a strategy for how to load the resource mappings into the OPA engine. If they don't change very much you could embed them in the data.json file of the OPA policy itself. But more often than not, that data is changed
42.
▲
by
ogazitt
5y ago
This was meant to be a "Show" of an unauthenticated experience (i.e. no account required) for creating OPA policies, different than the thread you referenced (which linked a public beta blog post).
43.
▲
by
ogazitt
5y ago
You can use the OPA CLI [0] or the policy CLI [1] to build and run the policies. [0] https://www.openpolicyagent.org/docs/edge/cli/#opa-build [1] https://github.com/opcr-io/policy
44.
▲
by
ogazitt
5y ago
By convention, we generate a package for every API definition in the OpenAPI spec. But the calling application can decide which package to use when authorizing an operation, so you can use a single policy for multiple endpoints.
45.
▲
by
ogazitt
5y ago
Authorization is a must-have for every application, but most teams have to build it from scratch. The Open Policy Agent [0] is a good place to start for creating an OSS-based solution, but you still need to build a lot of stuff yourself. Th
46.
▲
Show HN: RBAC for your REST API in 2 minutes
(aserto.com)
21 points
by
ogazitt
5y ago
|
12 comments
47.
▲
by
ogazitt
5y ago
It would kind of be nice to understand who is behind this. Where's the repo where the website is built from? Who are the devs in the organization? Otherwise, it just feels like an advocacy site for a large company that is not Apple.
48.
▲
by
ogazitt
5y ago
Having written server software that had to work in both places, I always loved the simplicity of fork(2) / vfork(2) relative to Windows CreateProcess. Threading models in Win32 were always a pain. Which only got worse with COM (remembe
49.
▲
Measuring Developer Relations
(swyx.io)
4 points
by
ogazitt
5y ago
|
0 comments
50.
▲
by
ogazitt
5y ago
That approach could definitely work if all you need for authorization is context about the user. Sometimes that context does get large, and it's hard to put it all in an HTTP header. This is a common problem for SaaS products that bake
51.
▲
by
ogazitt
5y ago
It's definitely a good paper :) Denormalization has been around since Date/Codd invented 6NF and relational databases, and then we all realized that most applications have to precompute some joins in order to execute in a performa
52.
▲
by
ogazitt
5y ago
Yes, flattening the graph is essential to getting reasonable performance. A separate (difficult) problem is to keep all the tuple data consistent with the data in your store (often these contain duplicate info).
53.
▲
by
ogazitt
5y ago
Welp, you know you're solving a hard problem when two other founders drop links in your HN thread :) More seriously, I agree that there are a number of challenges, and different use-cases tend to require different approaches. Over time
54.
▲
by
ogazitt
5y ago
You bring up a good point with respect to the "Google for everyone else" technologies. The fact is that very few organizations are the size of Google (or have the SRE team / expertise that Google does). Zanzibar works at Goog
55.
▲
by
ogazitt
5y ago
Authorization is really about "defense in depth". In a ZTA model, your access proxy, authentication system, API gateway, application middleware, and data layer all provide additional levels of protection [0]. Using your DB's
56.
▲
by
ogazitt
5y ago
Thanks for the kind words! Maybe next time you look at evolving your authorization model, we can chat :)
57.
▲
by
ogazitt
5y ago
RBAC is simple to get started with, but indeed pretty limited. We tend to use the term because it's more recognizable than ABAC or ReBAC. The {subject,relation,object} tuples do provide a convenient way to express an ACL-based system.
58.
▲
by
ogazitt
5y ago
This is indeed one of the benefits of the policy-as-code approach. And Rego syntax is much easier to grok than other "-as-code" approaches (read: wall-of-yaml)
59.
▲
by
ogazitt
5y ago
That's indeed why authorization is a harder problem than authentication - because much of it is domain-specific. Still, there are many things an authorization system can help with. For example, the service/organization affiliation
60.
▲
by
ogazitt
5y ago
Great question. There are two scenarios that are relevant for authorization: 1. Gating the operation (whether it's retrieving a single resource, or creating / updating / deleting a resource). In this scenario, the application
More ›