Главная
Study mode:
on
1
intro
2
preamble
3
about alex
4
authn ≠ authz
5
let's scale a company
6
stage 1 - the blissful days of roles
7
stage 2 - let's change our product packaging
8
stage 3 - let's sell into another region
9
stage 4 - let's sell to 'enterprise' organisations
10
stage 5 - new ciso: let's get iso27001 / soc2
11
stage 6 - we need microservices!
12
a new approach
13
authorizaion-as-a-service?
14
code to policy
15
rise of sidecars
16
in practice
17
advantages, challenges
18
about cerbos
19
thanks
Description:
Explore the evolution of authorization systems in this conference talk from Conf42 DevSecOps 2023. Dive into the journey from basic role-based access control to advanced attribute-based access control (ABAC) as companies scale and face new challenges. Learn about the distinctions between authentication and authorization, and follow a hypothetical company's growth through six stages of increasing complexity in access management. Discover a new approach to authorization, including the concept of authorization-as-a-service and the transition from code-based to policy-based systems. Examine the rise of sidecar patterns in microservices architectures and their impact on authorization. Gain insights into practical implementation, advantages, and challenges of modern authorization systems. Conclude with an introduction to Cerbos, an open-source authorization solution.

Modernizing Authorization: From Basic Roles to Decoupled ABAC

Conf42
Add to list
0:00 / 0:00