Cedar is an open source policy language and evaluation engine
github.com
github.com
Pros
1. Cedar is great and very expressive and fits many many use case.
Cons
1. The price. Was too expensive for our scale
2. As another commenter has pointed, Cedar/AVP expects you to send all the contextual data as part of the Authz request. It only persists the policy.
3. There is no concept of role based lookup. E.g I cannot query who has what access
C2a: think of the use case around a centralized policy & identity store with lots of independent services consuming that. The services dont know or care how individual users create/store/update their policies. Nor how other services perform authorization. Each service is the only source of truth for that services requests, and must supply the necessary API request context etc. C2b In addition you could certainly build a “cedar service” that owned identity policy and identity context then joined that with the services context to perform the access evaluation. C2c: Conversely if your service is much more monolithic, with no central trust or trusted peers, you could do all of the above inside your mono-service. But batteries are not included here.
C3: I actually dont know how to feasibly accomplish this with a capability based system. As youve mentioned authorization is very dependent on context, which is typically dynamic. Eg it might include time checks, source/dest network address, or even things like the machine identity that sent the request. It seems youd need to populate all the potential context to perform an evaluation, and a simple index/enumeration doesnt fit. Very interested if you have counter examples.
Unfortunately, there doesn't seem to be much of a story here to solve authz-aware searching/listing for object/row level access. Since Cedar/AVP doesn't come with an entity store, it seems I'd have to send my entire database(s) on each call so that the policies have the right data to evaluate. If that's true, then it seems like this would be only be useful on small data sets.
I'm struggling to come up with use cases for "fine-grained permissions and authorization" (what AVP bills itself as) that don't involve some sort of listing or searching of things.
Can you speak to the point about latency? I wasn’t aware it made performance guarantees
The foremost benefit of Cedar is that the implementation is formally proven. Which means that you are extremely unlikely to have to deal with unexpected behavior! Of course, the modeling needs to be reviewed manually for completeness, but the verifier can tell if the model is buggy or inconsistent.
Went through a big Ory Keto implementation to get stuck on not being able to do this last crucial bit, so we ended up implementing our own role based access control
Hmmm. What's an example of this?
Activity: Alice (a supervisor), raises a transaction >X, Bob is a supervisor, Eve is not.
Problem: “Who can approve the transaction?”
(As humans the answer is obviously Bob, but for typical implementation approaches to AuthZ policy, this is challenging to determine. Typically it’s done out of band and then makes a decision when requested by Bob (allow) or Eve (deny))