Google Zanzibar Through Our Eyes
authzed.com
authzed.com
You can go directly to the annotated paper here[0]. It's got all kinds of goodies like the ability to direct link from anywhere and generate OpenGraph previews (e.g. [1]).
Coolest of all, it's entirely open source[2] built on NextJS.
> SpiceDB is an open source database system for managing security-critical application permissions inspired by Google's Zanzibar paper
[1] https://developer.squareup.com/blog/books-an-immutable-doubl...
Also I can't decide whether this paper is more interesting or the tech they built to annotate it, I keep thinking of papers I'd want to do this with now.
Yes! The team over at Authzed keeps seeing this, too!
While SpiceDB is fully embracing its primary use-case for permissions, you could also use it to solve many other problems that boil down to "the existence of a path on a graph". For example, we've considered using it for storing update graphs for automating software updates for our Kubernetes operator[0]
The wonderful Kris Nova has also made this realization and considered SpiceDB for dependency resolution for an init system designed to replace systemd[1].
[0]: https://github.com/authzed/spicedb-operator
[1]: https://docs.google.com/document/d/1dA591eipsgWeAlaSwbYNQtAQ...
A real go at this with postgres and logical decode could be made though.
In SpiceDB [0] schema this can be represented like so:
definition group {
relation member: user | group#member
}
Here `member` allows a relationship to itself, which allows writing a relationship saying that every member of one group is a member of the containing group.I threw together an example in our playground [1], if you'd like to try it out!
[0]: https://github.com/authzed/spicedb [1]: https://play.authzed.com/s/9D5h9I7mE9mK/schema
CanAccessAmericanSecrets = AllSREs - EmployeesInEnemyState
(or whatever)In addition, there is `tupleset_to_userset` [0], which can be thought of as an arrow (which is also how its defined in SpiceDB [1]).
[0]: https://zanzibar.tech/2D0HKhvxH0:0.IoJK1g_7i:4L~ses~0~1 [1]: https://docs.authzed.com/reference/schema-lang#--arrow
I was in that misled camp for quite some time. One day it clicked, but only after realizing that the namespace config pseudo-code from section 2.3. IS what defines relationships: https://gruchalski.com/posts/2022-10-22-zanzibar-with-prolog.... Not the fancy object#relation@subject. That’s just the query language.
One of the features our project supports that could not be done in Google Docs is having multiple sets of annotations. We could add another that assumes you know nothing about the space and helps provide a lot more context.
https://github.com/authzed/zanzibar-annotated is very slick too!
Is there any way to attribute an annotation to a set of authors (sans git history)?