Policy.schema.json

Policy Structure Overview

This document outlines the format and structure of a Cerbos policy representing permissions and roles for API resources.

API Version

The schema defines the API version to ensure backward compatibility and structured development.

Metadata

Use this section to define metadata such as descriptions and identifiers related to the policy:

Principal Policy

The principal policy provides definitions for user roles and their access rights.

Structure of Principal Policy

Example:

{
  "principal": "user123",
  "rules": [
    {
      "resource": "resourceName",
      "actions": ["read", "write"]
    }
  ],
  "scope": "global"
}

Resource Policy

The resource policy defines the actions and controls associated with specific resources.

Structure of Resource Policy

Example:

{
  "resource": "document",
  "rules": [
    {
      "actions": ["view", "edit"],
      "effect": "EFFECT_ALLOW"
    }
  ]
}

Role Definitions

Define roles and their inheritance to facilitate a structured access control mechanism.

Structure of Role Definition

Example:

{
  "name": "admin",
  "parentRoles": ["user"]
}

Variables

Variables provide a mechanism to define dynamic elements within policies, allowing for flexible policies that can adapt to various contexts.

Structure of Variables

Conclusion

This structured overview provides a path for creating detailed and robust access policies using the Cerbos framework, thus ensuring that defined permissions adhere to organizational security policies.