Cerbos Community #announcements
Channels
# announcements
Emre (Cerbos)
07/25/2022, 3:01 AM
Hi @Jamie Shepherd Welcome to the Cerbos Community 👋 How did you hear about Cerbos?
Luca Carangella
09/05/2022, 11:38 AM
We are introducing NestJS in our system, and obviously, we will make it work with Cerbos! 🤘
🤘 3
12/23/2022, 4:49 AM
https://twitter.com/cerbosdev/status/1606225548828479488 We spoke to @EnginBainAC, the Head of Product and Growth, and Co-Founder of @Debite_io, to understand why Debite implemented Cerbos — and how Debite was able to ship their products faster and GTM very quickly, through said partnership.
#authorization https://t.co/rSwWpj8HUO Twitter
12/26/2022, 10:01 AM
https://twitter.com/cerbosdev/status/1607391078168285188 Cerbos is completely open-source & easy to get up and running. You are also able to self-host it.
Allowing Cerbos to be self-hosted enables you to operate more efficiently because the response times are within milliseconds.
#OpenSource #TechTwitter #authorization #OSS #SaaS Twitter
01/03/2023, 4:00 AM
https://twitter.com/cerbosdev/status/1610199482859245569 Cerbos is completely #stateless & works with #cloudservices & multiple languages.
You can run it straight on a VM with a binary, in a #Kubernetes cluster. You can even run it in ECS. It can run wherever you can execute containers in a server state.
#TechTwitter #authorization Twitter
GitHub
01/09/2023, 4:27 AM
Release - v0.24.0 New release published by github-actions[bot] Cerbos 0.24.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.24.0.html Changelog Features
• 47a635e feat!: Include metadata in decision logs ( #1385) • 2159cc9 feat: Support for filtering decision logs ( #1387)
Enhancements
• 13e27ab enhancement(helm): Annotations for deployment and service ( #1363) • 6d9fb62 enhancement(helm): Optional cert-manager integration ( #1365) • 8b37e58 enhancement: Add wrapper function for
sqlx.Connect
call, incorporating basic retries ( #1405)
Bug fixes
• c3ae703 fix(planner): R.id unresolved ( #1371) • 065b147 fix: Fix handling of the SIGUSR1 on Windows ( #1401) • 32bc32d fix: Flaky query plan test ( #1364) • 6601401 fix: Handle principal-policy-only cases ( #1406) • b344001 fix: Reject duplicate tests ( #1412)
Documentation
• ac2e665 docs: Add excludeMetadataKeys and includeMetadataKeys to audit page on docs ( #1383) • 28a6142 docs: Add policy best practices section ( #1361) • 6988a23 docs: List available SDKs ( #1366) • 2619857 docs: Port SQLAlchemy integration guide from blog to docs ( #1378) • a7fb799 docs: Remove unstable warning from Linux packages ( #1368) • 3739fe9 docs: Update Prisma recipe to bring in line with demo repo ( #1386)
Chores
• 5be75a8 chore(ci): Add CodeQL analyzer ( #1396) • 97707f9 chore(ci): Disable Renovate go.mod Go version update ( #1359) • 8547126 chore(ci): Use token with Buf setup action ( #1413) • 176eb49 chore(deps): Update bufbuild/buf-push-action action to v1.1.0 ( #1393) • 0729e96 chore(deps): Update bufbuild/buf-setup-action action to v1.11.0 ( #1409) • 5d8d4c4 chore(deps): Update github actions deps ( #1399) • 3bcacd5 chore(deps): Update go deps ( #1356) • 7f52f1b chore(deps): Update go deps ( #1367) • 7e32c7c chore(deps): Update go deps ( #1382) • 60e5a50 chore(deps): Update go deps ( #1392) • b2d2069 chore(deps): Update go deps ( #1398) • 5d68a19 chore(deps): Update go deps ( #1404) • 1c54170 chore(deps): Update go deps ( #1408) • c4cbcc1 chore(deps): Update google-github-actions/setup-gcloud action to v1 ( #1357) • 2fc6774 chore(deps): Update module helm.sh/helm/v3 to v3.10.3 [security] ( #1395) • 89266e2 chore(release): Add 0.23.1 release notes ( #1375) • 5571c97 chore(release): Add 0.24.0 release notes ( #1415) • 6368d3b chore(release): Prepare release 0.24.0 • 8d6aea6 chore(test): Exercise audit log filtering in E2E tests ( #1388) • 6de575d chore(version): Bump version to 0.24.0 • c8b4afa chore: Update copyright notice ( #1407) cerbos/cerbos
01/13/2023, 11:07 AM
https://twitter.com/cerbosdev/status/1613930654101835778 If you're a developer or tech enthusiast looking to centralize & improve your application's authorization layer and logic, and gain a deeper understanding of access controls and abstraction of permissions - check out this link! https://t.co/7KOmSvfRxI @alexolivier #accesscontrol Twitter
01/23/2023, 6:17 AM
https://twitter.com/cerbosdev/status/1617481616825241602 We think that stateful authorization is an anti-pattern...
Read our latest blogpost by @alexolivier to see a comparison of stateless & stateful authZ. Then, let us know: do you agree with us? 🧐
#authorization #stateful #stateless @CloudNativeFdn Twitter
01/31/2023, 5:00 AM
https://twitter.com/cerbosdev/status/1620361245697138689 Have you registered for #CloudNativeSecurityCon?
You can here: https://hubs.ly/Q01zf-Nz0
We’ll also be there! Come and chat with us on February 1-2 at booth S5!
We look forward to seeing you there!
#CloudNative #Security #opensource https://t.co/GHMksdL03U Twitter
01/31/2023, 11:00 AM
https://twitter.com/cerbosdev/status/1620451845452840963 #CloudNativeSecurityCon starts tomorrow! There is still time to register, don’t miss out on this conference!
We're excited to be there and hope that you come and see us at booth S5 on February 1-2!
#CNSCon #Security #opensource Twitter
02/01/2023, 5:00 AM
https://twitter.com/cerbosdev/status/1620723636666499074 #CloudNativeSecurityCon starts today!
We are excited to be here! Stop by booth S5 on February 1-2 to say hi!
#CNSCon #Security #opensource https://t.co/moB1x3gymU Twitter
02/01/2023, 12:14 PM
https://twitter.com/cerbosdev/status/1620833054989365250 👋 Stop by booth S5 at #CloudNativeSecurityCon to chat with @emre and @alexolivier & see what Cerbos can offer for your authorization needs.
We're here to help you make your authorization system more scalable and secure! 📈
#authorization #opensource https://t.co/oZZoqyCirF Twitter 1199x1200px image
02/02/2023, 4:26 AM
https://twitter.com/cerbosdev/status/1621077570543579136 🚀Celebrating Our Milestone: 1000 Stars on GitHub!
Thanks to our amazing users who trust us to make their authorization systems more scalable and secure! We're honored to be a part of your journey.
Here's to many more milestones together! #opensource #authorization #1000stars https://t.co/5p2ioy3DTD Twitter
02/03/2023, 6:39 AM
https://twitter.com/cerbosdev/status/1621473379881553923 We had an amazing time at the #CloudNativeSecurityCon conference in Seattle. @emre and @alexolivier met so many interesting people and had some great conversations! https://t.co/1jVqIFu78K Twitter
02/06/2023, 5:00 AM
https://twitter.com/cerbosdev/status/1622535572240613378 Are you attending Civo Navigate February 7-8?
@alexolivier will be there giving a talk of “Solving the ending requirements of authorization” on February 8th!
Check out the full list of speakers and schedule here!
Hope to see you there!
#CivoNavigate Twitter
02/06/2023, 7:17 AM
https://twitter.com/cerbosdev/status/1622570229619388417 🎙️ @alexolivier joined @tjvantoll on the @reactroundup podcast to talk all things authorization!
Learn how authorization can help your business scale and meet regulatory req's & discover the process of testing and setting up Cerbos: https://t.co/LnJ4cY6KGx
#authorization Twitter
02/06/2023, 10:00 AM
https://twitter.com/cerbosdev/status/1622611072069910528 Civo Navigate is happening tomorrow!
@alexolivier will be there giving a talk of “Solving the ending requirements of authorization” on February 8th!
Check out the full list of speakers and schedule here!
Hope to see you there!
#CivoNavigate Twitter
02/07/2023, 5:18 AM
https://twitter.com/cerbosdev/status/1622902589464485888 🙌 Discover the power of self-service custom roles!
We previously released a blog post exploring the topic of mapping business requirements to authorization policies.
Now, we dive into the implementation of self-service custom roles: https://t.co/ur1fvzlaVJ
#authorization Twitter
02/07/2023, 11:00 AM
https://twitter.com/cerbosdev/status/1622988600555061248 How Cerbos helped Nook build secure & extensible roles and permissions
Check out Nook's success story, now available on our site, to see why Nook selected Cerbos as an #authorization solution & the remarkable results that came out of the collaboration.
https://t.co/riQmzcZIQh https://t.co/81c2pXldos Twitter
02/08/2023, 9:00 AM
https://twitter.com/cerbosdev/status/1623320751771201539 Civo Navigate has been great so far!
We hope that you can join @alexolivier today at 3pm, as he will be giving a talk on the topic of “Solving the ending requirements of authorization”!
See you there!
#CivoNavigate #authorization Twitter
02/08/2023, 10:41 AM
https://twitter.com/cerbosdev/status/1623346197334265863 🚨 Learn about #authorization from @alexolivier at the #CivoNavigate Rooftop today at 3pm EST
Alex's talk will cover: ✅ Implementing permissions ✅ Stages in the evolution of a company where authorization needs to change ✅ Gitops-based example of scaling policy
@CivoCloud https://t.co/wqrg6EULhu Twitter
02/10/2023, 5:26 AM
https://twitter.com/cerbosdev/status/1623991733238304771 Cerbos have been named one of Europe’s top 100 early stage B2B SaaS/Cloud companies in The @NotionCapital Cloud Challengers Report! 🚀 https://t.co/5Wo6RfKYpO
We are honored to be part of this list! Big thanks to our users and amazing team!
#NotionCapitalCloudChallengersReport Twitter
GitHub
02/13/2023, 4:35 AM
Release - v0.25.0 New release published by github-actions[bot] Cerbos 0.25.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.25.0.html Changelog Features
• 31a474b feat: Add Cerbos version to response headers ( #1448) • 840a417 feat: Admin API endpoint to disable policy(s) ( #1426)
Enhancements
• dfb42e9 enhancement!: Return number of schemas deleted, and don't error if none ( #1445) • 49ccfb3 enhancement: Add DeleteSchema RPC to the SDK AdminClient ( #1459) • 6b6ea4c enhancement: Prevent scoped policies being disabled ( #1441)
Bug fixes
• 4630a08 fix: Evict disabled policy from the cache ( #1436) • 5fc9861 fix: Evict policies that are changed in-place ( #1439) • b40303f fix: Fix erroneous check in the Disable command ( #1447) • 986d3d0 fix: Fix typo in policy metadata field ( #1454) • 49c9405 fix: Fix typo in policy metadata field ( #1458)
Documentation
• 4297ad5 docs: Add note on resource-led policy design in
Best practices
section ( #1423) • eb8bf6d docs: Add policyVersion example to tests ( #1430) • 20b0052 docs: Clarify how to provide blob store credentials ( #1433)
Chores
• a7a542c chore(ci): Improve caching ( #1446) • c2628e2 chore(ci): Update gcloud auth ( #1420) • f7ecc84 chore(ci): Use Go 1.20 in CI ( #1440) • e458fd2 chore(deps): Bump helm.sh/helm/v3 from 3.11.0 to 3.11.1 ( #1450) • e6450bd chore(deps): Revert update of github.com/jackc/pgx/v4 to v5 ( #1425) ( #1427) • c7bf926 chore(deps): Update bufbuild/buf-setup-action action to v1.12.0 ( #1422) • 860d4c0 chore(deps): Update github actions deps ( #1429) • 9003411 chore(deps): Update go deps ( #1416) • d20bb6e chore(deps): Update go deps ( #1421) • 60b07ae chore(deps): Update go deps ( #1424) • 5dad5ce chore(deps): Update go deps ( #1428) • e02ad24 chore(deps): Update go deps ( #1437) • 142c44c chore(deps): Update go deps to v2 (major) ( #1417) • 09d538f chore(deps): Update google-github-actions/setup-gcloud action to v1.1.0 ( #1438) • 349afb1 chore(deps): Update module github.com/jackc/pgx/v4 to v5 ( #1425) • 7e10fc6 chore(deps): Update module go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.39.0 [security] ( #1452) • 4555737 chore(release): Add 0.25.0 release notes ( #1460) • 6b5a051 chore(release): Prepare release 0.25.0 • bee90fc chore(version): Bump version to 0.25.0 • 2059326 chore: Add licence file for pjbgf/sha1cd ( #1418) • 3c888cc chore: Upgrade Otel semconv version ( #1444)
Others
• fa28609 revert: Fix typo in policy metadata field ( #1454) ( #1456) cerbos/cerbos
02/13/2023, 6:33 AM
https://twitter.com/cerbosdev/status/1625095841315782656 Follow along over the next few days as we compare user permissions strategies, to help you figure out which strategy may work best for your organization’s services! ⬇️ 💡
#cerbos #permissions #SaaS #authorization #microservice https://t.co/v1nYbiQp3C Twitter
02/16/2023, 12:09 PM
https://twitter.com/cerbosdev/status/1626267622831431681 📣 Check out the latest updates from Cerbos in our monthly newsletter! [https://cerbos.dev/subscribe#Past%20Issues](/content/subscribe#Past%20Issues ""/index.html)
This month, we talk about: ✅ v0.25 of Cerbos ✅ upcoming launch of Cerbos Cloud ✅ recent milestones ✅ podcasts the Cerbos team was on ✅ and more
#cerbosnewsletter #authorization https://t.co/Cl9TnVsMCh Twitter
02/17/2023, 6:05 AM
https://twitter.com/cerbosdev/status/1626538377964126209 🥳 Happy user raising seed round! Congratulations, @CommandKDev ! Twitter Lightspeed backs CommandK's mission to become the go-to enterprise security command center https://tcrn.ch/3lHuZ7G by @JagmeetS13 Twitter
02/20/2023, 7:00 AM
https://twitter.com/cerbosdev/status/1627639202077630465 Our own @alexolivier was on the @reactroundup podcast talking about Cerbos and what it can offer users!
He also takes time to go over testing and setting Cerbos up.
Check it out here: https://t.co/vV6w0koADM
#podcast #authorization #Cerbos Twitter
02/20/2023, 7:05 AM
https://twitter.com/cerbosdev/status/1627640572956577793 Tips on how to run your software startup more effectively, from Charith Ellawala, Co-Founder & CTO at Cerbos ➡️ https://t.co/20XrXCkHtX
#cerbos #startup #startupfounder #startupstrategies #software #authorization Twitter
02/22/2023, 5:42 AM
https://twitter.com/cerbosdev/status/1628344359052607488 👉 Check out our playground to write, test, and debug Cerbos policies in your browser [https://cerbos.dev/playground](/content/playground ""/index.html)
And if you're not sure where to start - try some of the provided pre-built examples!
#cerbos #authorization #policies Twitter
02/24/2023, 6:39 AM
https://twitter.com/cerbosdev/status/1629083468024975360 🔒Worried about the security your cloud-native apps? Watch the @CloudNativeFdn webinar on cloud-native app authZ with @alexolivier, Product Lead at Cerbos.
➡️Fine-grained access controls ➡️Observability w/ #OpenTelemetry #Prometheus ➡️Git-ops with #Argo Twitter
02/24/2023, 9:18 AM
https://twitter.com/cerbosdev/status/1629123484692381696 🚀 Learn how to create dynamic and secure web experiences with @nextjs, @prisma, and Cerbos!
Check out the demo code and read the full text here: https://t.co/MLXf39M8wJ
#Nextjs #Prisma #Cerbos #authorization #integration #webdev Twitter
02/28/2023, 7:00 AM
https://twitter.com/cerbosdev/status/1630538304427835392 Did you know you can supercharge your policy rules with self-service custom roles using Cerbos?
We've got you covered in this blog written by Sam Lock: https://t.co/Ig7Gp1I3vc
#customroles #authorization #Cerbos Twitter
03/03/2023, 7:00 AM
https://twitter.com/cerbosdev/status/1631625469593255936 It's always great when you can free the development team to focus on the business logic.
Cerbos allows you to implement an authorization mechanism as a global shared provider.
Read more about how to do that here: https://t.co/iSveGIWEWs
#authorization #Cerbos Twitter
03/03/2023, 8:55 AM
https://twitter.com/cerbosdev/status/1631654474824515587 Choosing the right architectural style is critical when building an IT infrastructure 🤔 #REST or #gRPC?
REST: ✅simple ❌can lack consistency
gRPC: ✅powerful ❌complex
Which one to choose? Find out here: https://t.co/CvBnNG43xF
#cerbos #authorization @TechBullion Twitter
03/06/2023, 10:50 AM
https://twitter.com/cerbosdev/status/1632770529948999681 Let's discuss service-to-service authorization & how to do it right ✅
Let’s start with non-user principals. They are identities that you tie to objects: servers and microservices. Why would you want to do that?
#cerbos #authorization #SaaS #enterprise #scale https://t.co/7ENWz57lPZ Twitter
🙌 1
03/07/2023, 9:24 AM
https://twitter.com/cerbosdev/status/1633111464151056386 Reduce latency & ensure security with Cerbos
Cerbos requires no cloud service or any external dependancies of any kind: https://t.co/i29RFIT68K
#cerbos #authorization https://t.co/5DttOQRlDj Twitter
03/08/2023, 6:12 AM
https://twitter.com/cerbosdev/status/1633425434405642243 Happy 2nd birthday Cerbos! 🎉🎂
2 years ago, we launched with the mission to make authZ simpler to implement and manage & free up product teams to focus on building their core product. Thank you to our amazing community for helping us grow and improve!
#Cerbos Twitter
03/09/2023, 12:02 PM
https://twitter.com/cerbosdev/status/1633876020519653376 📣 Check out the latest updates from Cerbos in our monthly newsletter! [https://cerbos.dev/subscribe#Past%20Issues](/content/subscribe#Past%20Issues ""/index.html)
✅ Cerbos anniversary ✅ upcoming launch of Cerbos Cloud ✅ @nextjs + @prisma integration ✅ @remix_run integration ✅ webinars the Cerbos team was on ✅ and more
#cerbosnewsletter https://t.co/K0jeR0CeGH Twitter
03/10/2023, 8:04 AM
https://twitter.com/cerbosdev/status/1634178375940964355 Struggling with the complexity of modern software? ⭐Decoupling components can be the solution you need
Learn how it can help with performance, cost optimization & feature development. Details here: https://t.co/oy6Jgg1WBE
#softwaredevelopment #decoupling #authorization #Cerbos Twitter
GitHub
04/17/2023, 3:48 AM
Release - v0.26.0 New release published by github-actions[bot] Cerbos 0.26.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.26.0.html Changelog Features
• a38efe6 feat: Add JUnit output format for test results ( #1508) • 52f0daf feat: Cerbos Cloud bundle store driver ( #1530) • 4a440e9 feat: Kafka audit log ( #1499)
Enhancements
• 06c514d enhancement!: Group test results by test name ( #1498) • 1a949a1 enhancement!: Make config flag optional ( #1462) • 138a1cd enhancement: Add includeDisabled to Admin API and schema deletion to cerbosctl ( #1463) • a5c1dc3 enhancement: Add principal, resource and action as properties of JUnit output ( #1520) • f38a10e enhancement: Add support for reading archive files for the disk driver ( #1473) • a5c6b10 enhancement: Audit error metric ( #1513) • ad0dbb2 enhancement: Enable auth on API explorer page ( #1464) • 22fff65 enhancement: Enable disabled policies ( #1472) • eb0d3da enhancement: Report audit close error ( #1501)
Bug fixes
• b6fdc81 fix: Fix passing tests not being visible in JUnit test output ( #1534) • f40a8a8 fix: Kafka async produce context cancellation ( #1516) • a9e540d fix: Kafka async publish fails when the API request returns ( #1510) • b6756b0 fix: Prevent default config from being turned into a path ( #1533)
Documentation
• 4fddbfb docs: Add Kafka audit backend docs ( #1506) • 80e7360 docs: Add resource ID to test examples ( #1488) • e5dbcb5 docs: Document /api/server_info ( #1469) • 27a2211 docs: Document CEL string.format function ( #1528) • 397d626 docs: Fix README snapshot.yml badge ( #1497) • 53c6a41 docs: Fix name of test output format flag ( #1481) • a1a6143 docs: Fix typo in 04_testing-policies.adoc ( #1477)
Chores
• 5fa9390 chore(api): Remove api/x/plan/resources endpoint ( #1471) • 92725a9 chore(ci): Add timeouts to workflows ( #1505) • 7507b68 chore(ci): Increase snapshot build timeout ( #1509) • 52d990c chore(deps): Bump github.com/docker/docker from 20.10.23+incompatible to 20.10.24+incompatible ( #1517) • 5831556 chore(deps): Bump github.com/docker/docker from 23.0.2+incompatible to 23.0.3+incompatible in /tools ( #1518) • f2a2b8f chore(deps): Bump github.com/opencontainers/runc from 1.1.2 to 1.1.5 ( #1507) • 682f41b chore(deps): Bump golang.org/x/net from 0.5.0 to 0.7.0 ( #1465) • bf08b73 chore(deps): Bump golang.org/x/net from 0.5.0 to 0.7.0 in /tools ( #1466) • dcaf942 chore(deps): Update bufbuild/buf-setup-action action to v1.15.0 ( #1484) • 215c4ee chore(deps): Update bufbuild/buf-setup-action action to v1.16.0 ( #1512) • c11163b chore(deps): Update bufbuild/buf-setup-action action to v1.17.0 ( #1522) • f19a9f3 chore(deps): Update github actions deps ( #1475) • 19e7e0b chore(deps): Update github actions deps ( #1494) • bd60c15 chore(deps): Update github actions deps to v4 (major) ( #1495) • a72e752 chore(deps): Update go deps ( #1474) • bbc795d chore… cerbos/cerbos
🎉 1
Charith (Cerbos)
06/07/2023, 6:39 AM
We just released Cerbos 0.27.0 with support for user-defined outputs from policy evaluation and a new
overlay
storage driver for fault tolerance. Checkout the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.27.0.html
🎉 9
d
- 2
- 2
GitHub
07/18/2023, 9:50 AM
This channel will receive notifications from cerbos/cerbos for:
releases
a
Aldin Kiselica
07/18/2023, 9:57 AM
A couple of hours ago we've released Cerbos v0.29.0. cerbie🎉 You can now define your variables in a dedicated file and import them into any of the other policies to reuse common values and expressions across your policy repo. Additionally, a new globals object is available to policies at runtime to read environment-specific values. For example, you might want to grant additional permissions to a role in your staging environment, without creating separate policy versions for different environments.
There are some more interesting novelties. To see all the changes and read full release notes, check https://docs.cerbos.dev/cerbos/latest/releases/v0.29.0.html
🙌 4
r
- 4
- 4
z
Zapier
08/22/2023, 8:32 AM
RT @CivoCloud: Big thank you to @cerbosdev for being a Silver Sponsor for Navigate Europe 2023 and helping to make the event possible 💙
G…
z
Zapier
08/22/2023, 8:38 AM
RT @ThisDotMedia: 🔐 Ever get #Authentication and #Authorization mixed up? Think of it like a concert 🎵: Authentication is your ticket in, A…
z
Zapier
08/29/2023, 5:13 AM
Introducing #Mongoose #Adapter for #Cerbos Query Plans 🚀
Now, implementing result filtering based on policies is super easy. Simply pass the plan to the adapter & include the resulting conditions in the find method of your models🌟
#Authorization https://twitter.com/cerbosdev/status/1696450950641103036
z
Zapier
08/29/2023, 5:18 AM
RT @boxyhq: We want to express a huge thank you to each of the panelists of the "Future of Authorization" - discussion at the Developer-Fir… https://twitter.com/cerbosdev/status/1696451440355484081
z
Zapier
08/29/2023, 12:47 PM
@emre emphasizes data security as a startup's opportunity, not just a need 👉 https://t.co/Y8wXuuePFr
🔑 Embrace "zero trust": Verify all 🔑 Understand your processes & data 🔑 Use MFA, encryption & audits
#DataSecurity #ZeroTrust #Cerbos #Authorization https://twitter.com/cerbosdev/status/1696565140085264565
z
Zapier
08/30/2023, 7:33 AM
🚀 #Cerbos will be at #CivoNavigateEU, Booth 7!
Facing authorization challenges? Stop by, let's chat. & Grab some Cerbos merch! 👕
Don't miss Alex's talk on "Modernizing #Authorization" on 5th Sept, 1415 1440BST. Dive deep into decoupled #ABAC 🛡️
#CivoNavigate @CivoCloud https://t.co/FaIEUQP7X2https://twitter.com/cerbosdev/status/1696847395596726408
z
Zapier
08/30/2023, 10:28 AM
RT @CivoCloud: Security is a hot topic this year at Navigate Europe with talks from Oliver Pinson-Roxburgh, @alexolivier, @rajeshmuthusamy,… https://twitter.com/cerbosdev/status/1696892100606841050
a
Aldin Kiselica
08/31/2023, 4:08 AM
removed an integration from this channel: twitter
n
News Alerts
09/04/2023, 10:59 AM
@cerbosdev: ⚠️ Access Denied! ⚠️ Keep your authZ policies fine-tuned to protect sensitive information, simplify workflows, and safeguard against malicious activity. #Cerbos #Authorization
n
News Alerts
09/05/2023, 7:00 AM
@cerbosdev: 🚀 Day 1 of #CivoNavigateEU! Visit #Cerbos at Booth 7. Need help with #authorization? Chat with us! & Grab exclusive Cerbos merch 👕Don't miss @alexolivier's talk today on "Modernizing Authorization" 1415 1440BST @ Queen Charlotte 🛡️@CivoCloud #ABAC @cerbosdev: @alexolivier @CivoCloud @alexolivier @fzn_sam
n
News Alerts
09/05/2023, 11:00 AM
@cerbosdev: 🚀 THANK YOU to everyone who's visited us at Booth 👉 #7 👈 at #CivoNavigateEU so far! We're inspired by all the insightful conversations and the passion of the attendees.Keep the discussions coming; we're here and eager to connect 💬 😊 #Cerbos #Authorization @CivoCloud
n
News Alerts
09/06/2023, 6:04 AM
@cerbosdev: 🚀 Having amazing conversations at #CivoNavigateEU! If you've yet to visit, swing by Booth 👉 #7 👈. Let's dive into authorization solutions tailored for your needs.@CivoCloud #Cerbos #Authorization @cerbosdev: Our mission❓ Streamline & empower the #authorization process, helping businesses adapt & thrive. 🔺 #Cerbos, the open-source authorization layer, addresses role & permission complexities in evolving apps, ensuring secure & adaptable management.#OpenSource #AdaptableBusiness @cerbosdev: 💡Inspired by @KelseyHightower's talk today. Valuable insights for juniors, open source's current state, & the idea of “resetting the game” with each new role (like the game Metro 😂). Eager for more talks & chats with you all!#CivoNavigateEU @CivoCloud @alexolivier @fzn_sam
n
News Alerts
09/06/2023, 7:02 AM
@cerbosdev: 💡Inspired by @KelseyHightower 's talk today. Valuable insights for juniors, open source's current state, & the idea of “resetting the game” with each new role (like the game Metroid 😂). Eager for more talks & chats with you all! #CivoNavigateEU@CivoCloud @alexolivier @fzn_sam @cerbosdev: We have a spare ticket for #DevRelCon in London, Sept 7-8 🎟 that we'd like to give away to one of you, or your devrel team member 😊Please respond& let us know whether you’d be interested in the ticket. The first person who responds will get the ticket. @cerbosdev: P.S. Once we confirm the person who will be receiving the ticket, we will send you a private message asking for some additional information required for us to assign the ticket to this individual.
n
News Alerts
09/06/2023, 10:02 AM
@cerbosdev: Why is the #Cerbos Query Plan API such a beneficial feature? Find out in our new blog post: #QueryPlan #Policies #Authorization
GitHub
09/13/2023, 4:04 AM
Release - v0.30.0 New release published by github-actions[bot] Cerbos 0.30.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.30.0.html Changelog Features
• 304586b feat!: Check variable references at compile time ( #1772) • b9228f6 feat(client): Add options for intercepting gRPC operations ( #1724) • 24cb3e4 feat: Add cerbosctl command to export policies and schemas from store ( #1686) • 9652c90 feat: Audit log rotation support ( #1766)
Enhancements
• 8fd1ac8 enhancement!: Use
.cerbos.yaml
as conventional name for config file ( #1755) • 5dce9a9 enhancement(helm): Add ability to set clusterIP ( #1707) • 3fbd95e enhancement(helm): Allow an image digest to be provided instead of a tag ( #1735) • 1f6ba2c enhancement: Better error messages from compile command ( #1750) • e2c7af0 enhancement: Clean-up store resources ( #1749) • 4e7d22c enhancement: Compile and run tests from an archive ( #1721) • 6582c70 enhancement: Configurable time skew for JWT validation ( #1790) • 1130d12 enhancement: Configuration to disable API explorer ( #1767) • 4d5d0c5 enhancement: Relax naming conventions for resource kinds, principals and roles ( #1762)
Bug fixes
• 0b7a189 fix(docs): Typo in Calling Cerbos ( #1726) • 6b09c62 fix(planner): Lambda body can be a field selection ( #1720) • 91a0d48 fix: Evict policies from cache after disable or enable ( #1711) • a29a992 fix: Ignore invalid expressions ( #1799) • 7bfa52a fix: Normalize Git store subdirectory config to handle leading
./
correctly ( #1774)
Documentation
• c7c5f37 docs(sdk): Update SDK examples ( #1731) • 34f6859 docs: Add testdata schema URLs ( #1779) • eaaed3d docs: Caveats of sharing a DB with multiple instances ( #1743) • a8ad220 docs: Fix typo in 03_calling-cerbos.adoc ( #1714) • b606512 docs: Remove deprecated endpoint/rpc ( #1734) • 4fbbe36 docs: Stop building docs for older versions ( #1716) • a2cf9c9 docs: Update examples for handling expressions beginning with quote ( #1739)
Chores
• 4a690fd chore(ci): Always run
upload-test-times
after
test
( #1756) • 2b7c99b chore(ci): Create PRs for Homebrew formula updates ( #1704) • 98de402 chore(ci): Debug logging for server tests ( #1791) • 711844a chore(ci): Increase timeout for client tests ( #1793) • bc1a4d5 chore(ci): Publish prerelease images tagged by commit hash ( #1736) • 5691a1b chore(ci): Split snapshots job ( #1796) • 2479397 chore(ci): Switch to Coveralls ( #1751) • b3c81ff chore(ci): Upload test coverage from snapshot builds ( #1764) • fdf5f2e chore(ci): Use experimental 'loopvar' released with Go 1.21 ( #1738) • 3738d7c chore(deps): Bump github.com/cyphar/filepath-securejoin from 0.2.3 to 0.2.4 in /tools ( #1788) • e7aff6e chore(deps): Downgrade pterm to v0.12.66 ( #1787) • 81122c6 chore(deps): Update actions/checkout action to v4 ( #1795) • 0959bda chore(deps): Update bufbuild/buf-setup-action action to v1.25.0 ( #1709) • e4410ce chore(deps): Update bufbuild/buf-setup-action action to v1.25.1 (<https://github.com/cerbos/cerbos/pu… cerbos/cerbos
🙌 2
j
- 3
- 2
GitHub
10/31/2023, 4:08 AM
Release - v0.31.0 New release published by github-actions[bot] Cerbos 0.31.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.31.0.html Changelog Features
• 3ec2930 feat!: Make
runtime.effectiveDerivedRoles
available in CEL expressions ( #1778) • 111c4a3 feat: Reload certificates when they change on disk ( #1841)
Enhancements
• d4c39c9 enhancement(api): Separate Go module for API definitions ( #1801) • 0d63f1e enhancement(api): Use toolchain to manage Go version used ( #1804) • 56f7683 enhancement(helm): Add support for defining topology spread constraints ( #1821) • c8af11b enhancement(security)!: Configure gRPC max concurrent streams ( #1853) • 055e476 enhancement: Allow parsing JWTs with legacy keysets ( #1823) • 0624962 enhancement: Deprecate client package ( #1815) • 7123a67 enhancement: Expose Index interface from private ( #1847) • 21315fe enhancement: Expose private Check API ( #1843) • 90bd6cd enhancement: Lenient scope search in tests ( #1838) • dff2dcc enhancement: Migrate to protovalidate ( #1800)
Bug fixes
• d135222 fix(docs): Correct link to resources test fixture schema ( #1829) • c6a158a fix(test): Fix resource kind in test ( #1813)
Documentation
• 25ba555 docs: Remove unstable warning from Admin API ( #1835) • 85e4eac docs: Update Neovim yamlls configuration section ( #1824)
Chores
• ff152ce chore(deps): Bump github.com/docker/docker from 24.0.6+incompatible to 24.0.7+incompatible ( #1856) • 12dc45a chore(deps): Bump github.com/docker/docker from 24.0.6+incompatible to 24.0.7+incompatible in /tools ( #1855) • 4edc6d6 chore(deps): Bump golang.org/x/net from 0.15.0 to 0.17.0 in /api/genpb ( #1830) • e494600 chore(deps): Bump golang.org/x/net from 0.15.0 to 0.17.0 in /tools ( #1831) • ab81d8e chore(deps): Bump golang.org/x/net from 0.16.0 to 0.17.0 ( #1833) • f134903 chore(deps): Bump google.golang.org/grpc from 1.58.0 to 1.58.3 in /tools ( #1848) • 0707972 chore(deps): Update actions/checkout action to v4 ( #1806) • 01a6016 chore(deps): Update amannn/action-semantic-pull-request action to v5.3.0 ( #1819) • 58d2969 chore(deps): Update bufbuild/buf-lint-action action to v1.1.0 ( #1840) • ce03553 chore(deps): Update bufbuild/buf-setup-action action to v1.27.0 ( #1827) • 42e6e61 chore(deps): Update bufbuild/buf-setup-action action to v1.27.1 ( #1844) • 8fb0092 chore(deps): Update bufbuild/buf-setup-action action to v1.27.2 ( #1851) • ecb6b49 chore(deps): Update github actions deps to v3 (major) ( #1807) • f74ecf8 chore(deps): Update go deps ( #1805) • bba5a64 chore(deps): Update go deps ( #1816) • d2affcb chore(deps): Update go deps ( #1818) • e8aa142 chore(deps): Update go deps ( #1826) • 49bfbe0 chore(deps): Update go deps ( #1839) • 1295185 chore(deps): Update go deps ( #1845) • 5f6b938 chore(deps): Update go deps ( #1852) • 81f2745 chore(deps): Update goreleaser/goreleaser-action action to v5 ( #1808) • 4512ca7 chore(docs): Add link to Laravel SDK ( #1810) • <https://git… cerbos/cerbos
🙌 3
GitHub
11/30/2023, 3:51 AM
Release - v0.32.0 New release published by github-actions[bot] Cerbos 0.32.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.32.0.html Changelog Features
• ce425d9 feat!: Switch metrics to OpenTelemetry and add support for push metrics ( #1887) • 1722454 feat: Better support for OTLP ( #1886)
Enhancements
• e87b533 enhancement(ci): Mirror Cerbos image to Docker Hub ( #1867) • f2ff20d enhancement: Detect and warn about invalid test suites ( #1868) • c055d13 enhancement: Include expected effect and outputs for successful tests ( #1881)
Bug fixes
• 12354c3 fix: Ignore empty files in policy repository ( #1882)
Documentation
• 5e254ae docs: Remove outdated playground section ( #1864)
Chores
• c62c562 chore(ci): Replace deprecated GoReleaser
--skip-publish
flag ( #1893) • 9fe252a chore(deps): Bump github.com/sigstore/cosign/v2 from 2.0.3-0.20230523133326-0544abd8fc8a to 2.2.1 in /tools ( #1869) • da82249 chore(deps): Bump go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc from 0.45.0 to 0.46.0 ( #1871) • e028281 chore(deps): Update amannn/action-semantic-pull-request action to v5.4.0 ( #1862) • fd30cac chore(deps): Update bufbuild/buf-setup-action action to v1.28.0 ( #1873) • 72f67c3 chore(deps): Update github actions deps ( #1884) • ebb56d2 chore(deps): Update go deps ( #1863) • 4662108 chore(deps): Update go deps ( #1874) • d51d9c9 chore(deps): Update go deps ( #1885) • 23de714 chore(deps): Update go deps ( #1888) • fef22d1 chore(release): Prepare release 0.32.0 • 8f52e1e chore(test): Fix Kafka integration tests ( #1878) • 7a72711 chore(version): Bump version to 0.32.0 • 761a3dc chore: Access to check options from custom checkers ( #1861) • 16f081b chore: Add pre-cache API to TestFixtureGetter ( #1866) • cf21eb0 chore: Add tests to check fixture loading from testdata ( #1877) • eba4b3f chore: Allow LoadTestFixture to continue on error ( #1859) • d51f597 chore: Enable Otel interceptor for grpc-gateway client ( #1892) • 3dc5ff8 chore: Fix legacy OTLP exporter initialization ( #1891) • 7dd5d0c chore: Simplify residual expression ( #1876) • 77e836e chore: Upgrade to CEL 0.18 ( #1860) cerbos/cerbos
GitHub
01/16/2024, 3:53 AM
Release - v0.33.0 New release published by github-actions[bot] Cerbos 0.33.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.33.0.html Changelog Features
• 323bbf2 feat: Add audit call ID to API responses ( #1911) • f6b9d06 feat: Produce output if condition fails ( #1932) • e66df40 feat: Record policy source attributes in audit log ( #1889)
Enhancements
• d2d7fe0 enhancement!: Drop support for tracing configuration block ( #1898) • a594f90 enhancement!: Remove deprecated client package ( #1904) • 8226beb enhancement(helm): Add podLabels to the chart ( #1912) • af85ff2 enhancement: Add Admin API update timestamp to policy ( #1903) • ddcc341 enhancement: Configurable database connection retries ( #1926) • 66e01b8 enhancement: Pass all HTTP headers through unmodified from gRPC-Gateway ( #1934)
Bug fixes
• 3ace137 fix(planner): Query planner doesn't use stable time ( #1949) • 89dcf2c fix(planner): Query planner must (pre)evaluate expressions with resource kind ( #1921) • 6352365 fix: Don't forward connection-specific headers via gRPC-Gateway ( #1938) • cb06545 fix: Restore
User-Agent
header aliasing ( #1941)
Documentation
• 2db232f chore: Revert "docs: Fix image URLs ( #1943)" ( #1951) • cfa36ef docs: Add policy variable examples ( #1940) • 5072b93 docs: Fix image URLs ( #1943) • 4194f6e docs: Fix incorrect policy rule in tutorial ( #1930) • 7affa69 docs: Remove older versions ( #1942)
Chores
• b40cf5a chore(deps): Bump github.com/cloudflare/circl from 1.3.3 to 1.3.7 ( #1935) • 015f51a chore(deps): Bump github.com/cloudflare/circl from 1.3.5 to 1.3.7 in /tools ( #1936) • d9d22e5 chore(deps): Bump github.com/go-git/go-git/v5 from 5.7.0 to 5.11.0 in /tools ( #1925) • d871844 chore(deps): Bump golang.org/x/crypto from 0.15.0 to 0.17.0 in /tools ( #1916) • 002b035 chore(deps): Downgrade github.com/chigopher/pathlib ( #1924) • e7d6014 chore(deps): Tidy dependencies ( #1899) • 24acf48 chore(deps): Tidy dependencies ( #1907) • 7c43413 chore(deps): Update actions/setup-go action to v5 ( #1906) • 7f098db chore(deps): Update github actions deps to v3 (major) ( #1915) • 5d2264b chore(deps): Update github actions deps to v4 (major) ( #1923) • 852cfff chore(deps): Update go deps ( #1896) • 6a5f22b chore(deps): Update go deps ( #1905) • a939aa0 chore(deps): Update go deps ( #1914) • d79fa22 chore(deps): Update go deps ( #1922) • 73e1971 chore(deps): Update go deps ( #1928) • ca453c7 chore(deps): Update go deps ( #1933) • e128d4a chore(deps): Update go deps ( #1950) • 288e33c chore(deps): Update google-github-actions/auth action to v2 ( #1897) • 39b39be chore(deps): Update google-github-actions/setup-gcloud action to v2 ( #1929) • 9c6b6d9 chore(deps): Update module golang.org/x/crypto to v0.17.0 [security] ( #1917) • a45ddc2 chore(docs): Readme updat… cerbos/cerbos
🙌 2
r
Rohit Ghumare
01/29/2024, 5:00 AM
Hello Everyone👋,
I'm the DevRel Manager at [Cerbos.dev](/content/ ""/index.html), and excited to share the fantastic news with you. We're thrilled to announce the launch of Cerbos Hub: Simplifying Authorization for Developers !!
Extend Policy Decision Point (PDP) with centralized authorization
cerbie Cerbos is excited to announce their public beta launch for Cerbos Hub and two new features to simplify the lives of developers and teams when managing their authorizations! -> Sign up for a free Cerbos Hub account
💥 New feature #1
Embeddable authorization policies via WebAssembly
• Cerbos Hub also provides an embeddable version of the policies that allow for taking authorization decisions on-device, at edge, and in environments where it is not possible to run a service. • The Cerbos Hub CI/CD pipeline will produce bundles, keeping them in sync with your policies on every change. • The access to be facilitated in applications will be via the Cerbos SDKs. And they handle auth checks without needing a roundtrip to the backend service. 🚀 Check out the documentation for more 🚀
💥 New feature #2
Write and test policies in the Cerbos Hub's IDE Collaborative Playground
• For those who are familiar with Cerbos’ open source product, Cerbos PDP, the [Cerbos Playground](/content/features-benefits-and-use-cases/cerbos-playground ""/index.html) is going to be a familiar concept. • It is an interactive space where users can write, test, and simulate Cerbos policies in real time. • Cerbos Hub now has a full-featured collaborative IDE - Cerbos Hub Playground, to develop, iterate, and test policy. • It comes with instant feedback on changes, It comes with an automated test runner, it integrates into your git-based workflow, Play with the capabilities of Cerbos without any setup or installation with included sample policies. 🚀 Read the documentation for more 🚀
📃Resources📃 • Cerbos Hub - [Start for free](/content/product-cerbos-hub ""/index.html) • Cerbos Hub documentation • Join our Slack Community to be in the know of the latest developments • We want to help build or review your first policy. Book a 30-minute free workshop • Cerbos PDP is open source. Feel free to browse or contribute, and don't forget to drop a star ⭐ 💡️Note: I am here to assist you. Feel free to contact me anytime with questions or concerns at #C02A364JYMQ
🎉 1
r
Rohit Ghumare
01/31/2024, 4:00 AM
🤔 Simplify Access Control & Reduce Security Vulnerabilities In Node.js, React and Serverless Apps 🤔
Find out how Cerbos Hub simplifies access control in Node.js, React, and serverless apps and reduces security vulnerabilities
Maintaining roles, permissions, and authorization policies within your JavaScript front-end and full-stack apps creates technical debt and security vulnerabilities. What if you need to replicate those same policies in an additional Express.js or Next.js app? Do you build and maintain separate codebases, creating an even more significant threat?
👋 Join @Alex Olivier (Cerbos), Cerbos Chief Product Officer, and Wesley, presenter of the popular ByteGrad Youtube channel, as they demonstrate how easy it is to author permissions and policy changes using Cerbos and deploy those changes without changing any other code.
🔗 Join here to register for the webinar 🚀
🤯 In this 45-minute session, you will learn to: • Set up a free policy repository on Cerbos Hub and define roles and permissions for your app. • Instantly synchronize policy changes across your entire app portfolio - front-end React and Next.js apps, mobile, APIs, and back-end Node.js services. • Use WASM libraries to operate and synchronize access control on front-end frameworks like React, across any cloud providers, and in serverless functions and architectures.
Copy code
We'll also have live Q&A, so bring your questions! 🎙️
r
Rohit Ghumare
02/05/2024, 4:00 AM
Hello, Connections👋, We're hosting a webinar on 8th Feb 2024 with Wesley from Bytegrad, and we're excited to extend our FREE seats to you! Please register for the event today to avoid consequences later. 🚀
** **Simplify Access Control in Your Apps with Cerbos Hub & Eliminate Months of Coding** ** We’ll also have live Q&A, so bring your questions!
🔗 Join here to register for the webinar `Speakers`: @Alex Olivier (Cerbos), Chief Product Officer Alex Olivier is the CPO and Co-founder at Cerbos. He has designed enterprise solutions from the ground up as an engineer, tech lead, and product manager, always with an eye on the developer experience. At Microsoft, Qubit, and many startups, he designed platforms that helped teams move faster at scale, focusing on core components like authorization, data management, and security.
Wesley, Founder @ByteGrad Wesley is the driving force behind the popular ByteGrad YouTube channel that demystifies programming for developers at every experience level, with over 85k subscribers and 1 million total views. Wesley has also authored popular courses such as "Professional React & Next.js," further solidifying his reputation as a leading voice for the developer community.
Click here👇 🔗 Join here to register for the webinar
GitHub
02/20/2024, 4:17 AM
Release - v0.34.0 New release published by github-actions[bot] Cerbos 0.34.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.34.0.html Changelog Features
• 4591b0d feat: Add tests filtering ( #1977) • 42e8442 feat: Better diagnostic error messages for policy issues ( #1960)
Enhancements
• 36b0e6d enhancement(ci): Sign release artifacts ( #1959) • 5db9ab0 enhancement(ci): Validate Helm chart in CI ( #1957) • 90f198a enhancement: Better compilation errors ( #1968) • 707278f enhancement: Detailed load errors in REPL ( #1985)
Bug fixes
• 4f90a5c fix: Record HTTP remote address as peer address for HTTP requests ( #1964)
Documentation
• 4afdc2f docs: Fix branch filter ( #1958)
Chores
• 05ef26b chore(ci): Add correct permissions to snapshot job ( #1962) • f24bec2 chore(ci): Add cosign to snapshot build job ( #1961) • 8db9898 chore(ci): Fix workflow permissions ( #1963) • cfed07f chore(ci): Use master version of govulncheck ( #1967) • b89c2c7 chore(deps): Bump github.com/opencontainers/runc from 1.1.5 to 1.1.12 ( #1971) • 7918e5e chore(deps): Bump helm.sh/helm/v3 from 3.14.0 to 3.14.1 ( #1986) • 5cf243a chore(deps): Update actions/cache action to v4 ( #1955) • dc8cf7f chore(deps): Update actions/setup-go action to v5 ( #1990) • 5574e85 chore(deps): Update github actions deps ( #1973) • e510788 chore(deps): Update github actions deps ( #1983) • 58a915c chore(deps): Update go deps ( #1954) • e683b1d chore(deps): Update go deps ( #1974) • 9bc3226 chore(deps): Update go deps ( #1984) • f151096 chore(deps): Update go deps ( #1989) • 0c095fc chore(deps): Update module github.com/goreleaser/goreleaser to v1.24.0 [security] ( #1976) • 9cf901b chore(docs): Readme update ( #1965) • aad2e98 chore(docs): Readme update ( #1966) • e5c7bef chore(docs): Update header to have tabs for PDP and Hub ( #1975) • c9d468d chore(release): Add 0.34.0 release notes ( #1991) • 8534c79 chore(release): Prepare release 0.34.0 • 563bec1 chore(version): Bump version to 0.34.0 • e4ebc88 chore: Add JSON test cases for parser ( #1952) • 0dd8dad chore: Add ability to parse well-known types ( #1972) • c253d87 chore: Copy metadata to runtime policies ( #1981) • bc84737 chore: Handle invalid YAML files containing unterminated strings ( #1970) • b10b139 chore: Move compiled policies annotations to *PolicySet ( #1988) • 4798453 chore: Reduce Docker healthcheck interval ( #1978) • 03f95ec chore: Remove start-period from Docker health check ( #1979) • 353aa08 chore: Switch workspace mode off for vulnerability check ( #1953) • 199ae8d chore: Update test filtering logic ( #1992) • d022db1 chore: Use Go 1.22 ( #1982) cerbos/cerbos
a
Anna Paykina
02/27/2024, 5:40 AM
Hello, everyone! We just published a [blog post, summarising the insights shared by Cerbos’ CEO and Co-Founder, Emre Baran, and Co-Founder and CPO, Alex Olivier, on the Jamstack Radio podcast](/content/blog/jamstack-radio-podcast-revolutionizing-access-control ""/index.html). 💡😊 Check out the episode to learn how Cerbos is simplifying complex access control challenges, and fostering a more secure and efficient development environment
👍 2
a
Anna Paykina
03/04/2024, 5:31 AM
Hey, Cerbos community 👋
We recently published a [blog post, exploring the importance of authorization layers in increasing your system’s security](/content/blog/the-importance-of-authorization-layers ""/index.html). 🛡️
Please feel free to check it out and let us know what you think 😊
✅ 1
m
- 2
- 1
r
Rohit Ghumare
03/11/2024, 5:00 AM
📣 Attention all Open Source Contributors and Devs! 📣
We've hit a milestone at Cerbos and we're excited to share the big news with our community. 🎉
_ _Cerbos_ _
and
_ _cerbosctl_ _
are now available as npm packages! 🚀
Gone are the days of managing Docker containers for your authorization needs. With Cerbos directly accessible via
npm
, you can effortlessly integrate it into your projects with a simple ``npx cerbos`` command or by adding it as a script in your
package.json
.
What’s in it for you? • 🛠️ Smooth integration into your workflows. • 🧾 Verifiable package integrity, giving you peace of mind about the code you use. • 🔒 Enhanced supply-chain security, making your development process safer than ever. This is more than just a release; it’s a step forward in secure and transparent software development. Head over to
npm
to see the new provenance tick and get your hands on the latest from Cerbos.
Keep building amazing things, with trust and security right at your codebase. 🛡️💻
👌 2
r
Rohit Ghumare
03/14/2024, 5:00 AM
🚀 Calling all KubeCon + CloudNativeCon 2024 Europe Participants! 🚀
Team Cerbos is heading to Paris! 🇫🇷 We're thrilled to announce that we'll be at KubeCon + CloudNativeCon Europe this year. 🎉
📍 Find us at _ _booth #E32_ _ where we're set to showcase how Cerbos is simplifying authorization for developers.
🔐 Tired of wading through complex permission layers? We've got you covered. With Cerbos, embrace a world where managing permissions is easy, so you can focus on what you do best: building great software.
Don't miss the chance to: • Get a firsthand look at our innovative approach to authorization. • Meet the minds behind Cerbos and learn how we can help streamline your security protocols. • Discover tips and tricks to implement fine-grained, context-aware permissions with ease. We can't wait to meet you there and explore how Cerbos can simplify and secure your development life. See you at booth #E32!
🙌 1
cerbie 6
☸️ 3
🧑💻 3
🇫🇷 6
r
Rohit Ghumare
03/28/2024, 3:15 PM
Hey,
Cerbos community
! 🎉
Great news! The ebook from Flagsmith that @Alex Olivier (Cerbos), our CPO, contributed to is officially out! 🚀📚 It's packed with insights into modern development practices in banking, and we're thrilled to be a part of it.
We'd love your support in spreading the word! If you could like and share our posts on LinkedIn and Twitter, it would mean the world to us: • LinkedIn: Modern Development Practices in Banking • Twitter: Check out the ebook feat. Alex Olivier For those keen to dive in, we've attached the ebook PDF here for your convenience. 📖
Don't miss out on exploring this valuable resource: Download the ebook
Huge thanks to Flagsmith for collaborating on this initiative. 🙏
Let's keep pushing the boundaries of what's possible in banking development together!
⌨️ 4
🚀 5
🤯 4
cerbie 7
🎉 6
🔐 5
🙌 7
GitHub
04/09/2024, 3:45 AM
Release - v0.35.1 New release published by github-actions[bot] Cerbos 0.35.1
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.35.1.html Changelog Chores
• e5b322b chore(ci): Output signature from cosign ( #2089) • 0dfd432 chore(release): Prepare release 0.35.1 • 4c9c159 chore(version): Bump version to 0.36.0 cerbos/cerbos
🚀 3
cerbos 4
a
Anna Paykina
04/11/2024, 6:34 AM
Hello, Cerbos community! 😊 Our April newsletter went out a few days ago, and we wanted to share the highlights with you.
Since our last update, we’ve released Cerbos PDP v0.35.1, took a deep dive into building secure applications in a collaborative [piece with Microsoft Entra](/content/blog/building-secure-applications-key-insights-on-authentication-and-authorization-from-cerbos-and-microsoft-entra?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--hbTmk7B4r8Qhv6p00gHci7M9ZgShWAwY0HUZycngV9cC0EdXwGZQYaLeGfmmVEda838pDzUgkeygcFn3pZGLDjAuILgF1lZe1z-jrK_eQC-HK4S4 ""/index.html), discussed the importance of [embracing WebAssembly](/content/blog/embracing-web-assembly-in-authorization?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--hbTmk7B4r8Qhv6p00gHci7M9ZgShWAwY0HUZycngV9cC0EdXwGZQYaLeGfmmVEda838pDzUgkeygcFn3pZGLDjAuILgF1lZe1z-jrK_eQC-HK4S4 ""/index.html) in authorization, examined [authorization APIs](/content/blog/what-is-an-authorization-api?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--hbTmk7B4r8Qhv6p00gHci7M9ZgShWAwY0HUZycngV9cC0EdXwGZQYaLeGfmmVEda838pDzUgkeygcFn3pZGLDjAuILgF1lZe1z-jrK_eQC-HK4S4 ""/index.html), and shared a piece on how Cerbos is designed to [redefine how permissions and access control](/content/blog/cerbos-why-and-what?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--hbTmk7B4r8Qhv6p00gHci7M9ZgShWAwY0HUZycngV9cC0EdXwGZQYaLeGfmmVEda838pDzUgkeygcFn3pZGLDjAuILgF1lZe1z-jrK_eQC-HK4S4 ""/index.html) are implemented within applications.
Our co-founder, Emre Baran, was featured on the [From the Ground Up](/content/blog/from-the-ground-up-podcast-reshaping-the-landscape-of-dev-ops-through-innovative-authorization-solutions?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--hbTmk7B4r8Qhv6p00gHci7M9ZgShWAwY0HUZycngV9cC0EdXwGZQYaLeGfmmVEda838pDzUgkeygcFn3pZGLDjAuILgF1lZe1z-jrK_eQC-HK4S4 ""/index.html) podcast, sharing insights from his entrepreneurial journey, and the inception of Cerbos.
If you’d like to be the first to receive Cerbos updates, you can [subscribe to our newsletter here](/content/subscribe ""/index.html).
💡 4
cerbie 6
🎉 8
🙌 5
🙌🏻 1
📰 5
r
Rohit Ghumare
04/15/2024, 4:00 AM
🎥 New Video Alert: Revolutionize Your Authorization with Cerbos!
Dive into our comprehensive video demo with Bytegrad to see how you can transform your authorization practices. This video provides a step-by-step guide to effectively using Cerbos to secure your applications. 🎉
🔗 Check it out here: [Revolutionize Your Authorization with Cerbos - Watch Now!](/content/blog/revolutionize-your-authorization-with-cerbos-a-comprehensive-video-demo-bytegrad ""/index.html)
💡 Got questions or want to discuss the video? Drop your thoughts in this thread!
cerbie 1
🙌 2
👀 1
👍 1
h
Heidi Hokanson
04/17/2024, 9:03 AM
Hi Cerbos Community! On May 7 we’re hosting a webinar featuring one of our Hub users, @Edgar Rivera, CTO at 4G Capital. This a great opportunity to hear from an expert on how authorization and Cerbos fit into his overall cloud strategy. And we’d love to see our community members there!
Edgar will share how 4G Capital: • Saved over $260k in costs by modernizing their architecture and authorization strategy • Increased feature velocity and reduced technical debt with a scrappy team • Ensures secure access across the frontend, backend, and APIs to protect data privacy. Take a look at the details and register here.
r
Rohit Ghumare
04/19/2024, 6:03 AM
Cerbos - 2500 Stars 🌟
Hey everyone, we’ve just crossed
2,500 stars
on GitHub for Cerbos! This is a huge milestone for us and it couldn’t have been possible without the hard work and dedication of everyone in this community. Thank you all for your contributions, support, and for believing in the power of open-source.
Let’s take a moment to celebrate our collective achievement and set our sights on even bigger goals. 🌟🚀
Here’s to many more stars and successes in our future! Feel free to share the news and let everyone know about our amazing community!
🙌 3
cerbie 2
🎂 1
🎉 2
🌟 3
r
Rohit Ghumare
04/23/2024, 4:00 AM
🌟 ** **New Podcast Episode Alert in The Scripting Den!** ** 🌟
Hey everyone! 🚀 Dive into the latest episode of "*The Scripting Den*" podcast, where @Alex Olivier (Cerbos), Co-Founder and CPO of Cerbos, shares invaluable insights on the evolution of security as products transition from MVP to mature offerings.
What to Expect: • Strategies on enhancing security during the scaling phase. • Tips on selecting the right tools to save resources and focus on innovation. • Understanding the importance of scalability and user feedback in product development.
This episode is a treasure trove for developers, product managers, and tech entrepreneurs focused on refining their product post-MVP. Don't miss out on these expert strategies to ensure your product is secure, scalable, and set up for success!
🎧 Listen to the full episode here for a deeper understanding: [The Scripting Den Podcast](/content/blog/the-scripting-den-podcast-exploring-the-evolution-of-security-post-mvp-cerbos ""/index.html).
Happy listening, and let’s discuss our thoughts here! What did you find most valuable? 💭
cerbie 3
🙌 3
🚀 2
a
Anna Paykina
04/30/2024, 6:26 AM
Join us for an exclusive look into Cerbos, the cutting-edge authorization technology that’s reshaping how developers, product teams, and security teams implement authorization solutions. 🛡️ https://www.linkedin.com/events/episode10-cerbosdeepdive7189030118256738305/
🎙️ Identerati Office Hours Episode 10: Cerbos Deep Dive 📅 Today, 3pm CEST | 9am EDT
Our CEO and co-founder, Emre Baran, will guide you through the innovative world of Cerbos. Discover the origins of Cerbos, its core strengths, what sets it apart in the authz landscape, and the visionary path ahead.
💡 What’s in it for you?
- Understand the Edge: Explore how Cerbos uses YAML over Rego for easier and faster policy definition.
- Speed and Efficiency: Learn about Cerbos’ stateless PDP architecture that ensures rapid response times without compromising security.
- Enterprise Ready: Gain insights into the enterprise control plane which is crucial for compliance and scaling in business environments.
This session is a must for anyone involved in or interested in authorization technologies. Whether you’re looking to enhance your current systems or exploring new solutions, you’ll find valuable insights and practical takeaways.
cerbie 3
🙌 2
🎉 2
👏 2
👀 2
h
Heidi Hokanson
04/30/2024, 2:27 PM
TOMORROW at 11am ET - Join @Alex Olivier (Cerbos) on Cloud Native Live to learn about using GitOps for testable, versionable and auditable authorization.
📽️ Cloud Native Live: GitOps for Application Authorization 📅 May 1, 11am ET | 3pm GMT
Description The authorization logic for determining whether a user can do an action on a specific resource inside of the application code is some of the most sensitive and impactful if it isn't correct. Using modern GitOps approaches for testable, versionable and auditable authorization removes many of the barriers around user permissions and improves your security posture
🎉 4
👍 4
cerbie 3
😎 3
🙌 4
h
Heidi Hokanson
05/02/2024, 8:57 AM
Hi <!channel>! 5 days to go until our live talk next week with @Edgar Rivera and @Alex Olivier (Cerbos) on future-proofing your back-end architecture. Edgar will share his experience designing an application that meets core fintech app requirements like regulatory compliance, clear audit logs, and fine-grained access control. Would love to see you all there! Here are the details:
📽️ Future-proofing Fintech in the age of Cloud and Microservices 📅 May 7, 1pm ET | 8pm CET
🔗 Register here to get access to our live stream and a recording of the webinar emailed to you afterward.
🎉 1
💡 1
a
Anna Paykina
05/03/2024, 6:27 AM
Hello, <!channel>! 😊 Our May newsletter went out a few days ago, and we wanted to share the highlights with you.
Since our last update, we’ve put together a [demo](/content/blog/introducing-enhanced-test-management-in-cerbos-hub-search-filter-and-view-test-results-easily?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--vQPY68TtxEk_ulcUirTetkUUpGSwyCU4uBYTnzQmPUYTc0sH52ydz5Z46SGPsbLdU-FALOfYeOK5cqgt9u0zyo_WLTCNZy2J8Tl4CVhcb4i8ZjYs ""/index.html) on the enhanced test management capabilities of Cerbos Hub, as well as thorough guides for [Next.js](/content/blog/a-complete-guide-to-next-js-authorization?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--vQPY68TtxEk_ulcUirTetkUUpGSwyCU4uBYTnzQmPUYTc0sH52ydz5Z46SGPsbLdU-FALOfYeOK5cqgt9u0zyo_WLTCNZy2J8Tl4CVhcb4i8ZjYs ""/index.html) and [React JS](/content/blog/how-to-implement-authorization-in-react-js?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--vQPY68TtxEk_ulcUirTetkUUpGSwyCU4uBYTnzQmPUYTc0sH52ydz5Z46SGPsbLdU-FALOfYeOK5cqgt9u0zyo_WLTCNZy2J8Tl4CVhcb4i8ZjYs ""/index.html) authorization, examined the [importance of authorization](/content/blog/importance-of-authorization-in-transition-from-monolithic-to-microservices-architecture?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--vQPY68TtxEk_ulcUirTetkUUpGSwyCU4uBYTnzQmPUYTc0sH52ydz5Z46SGPsbLdU-FALOfYeOK5cqgt9u0zyo_WLTCNZy2J8Tl4CVhcb4i8ZjYs ""/index.html) in transition from monolithic to microservices architecture, and explored the evolution of security post-MVP on [The Scripting Den podcast](/content/blog/the-scripting-den-podcast-exploring-the-evolution-of-security-post-mvp-cerbos?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--vQPY68TtxEk_ulcUirTetkUUpGSwyCU4uBYTnzQmPUYTc0sH52ydz5Z46SGPsbLdU-FALOfYeOK5cqgt9u0zyo_WLTCNZy2J8Tl4CVhcb4i8ZjYs ""/index.html).
Join us on May 7th for a webinar featuring our customer, 4G Capital, on the topic of 🔊💻*”Future-proofing fintech security in the age of cloud & microservices”*. If you would like to learn about scaling your business with cloud and microservices, while ensuring stringent data security and audit requirements, and discover how 4G Capital slashed costs by over $260k through strategic modernization of their architecture and authorization strategies - register here. If you’d like to be the first to receive Cerbos updates, you can [subscribe to our newsletter here](/content/subscribe ""/index.html).
cerbie 6
🙌 5
👍 4
📰 3
👍🏻 1
🙌🏻 1
a
Anna Paykina
05/08/2024, 10:41 AM
, please check out our upcoming webinar: “Feature Flags & Authorization - Key Tools for Modern Development”
📅 Date & Time: May 22, 2024, 5:00 PM CEST \ 11 AM EDT 🔗 Register here 🔗 👥 Speakers: Alex Olivier, Ben Rometsch ⏺️ PS. Can’t join us live? Register to receive the link to the recording in your inbox.
Join Cerbos and Flagsmith for a 1 hour webinar that dives deep into the integral roles of feature flags and authorization in software development, and includes demos of both solutions. Whether you’re looking to enhance user experience, streamline product releases, or bolster security, this webinar will equip you with the knowledge to leverage both feature flags and authorization effectively in your projects.
Why attend? 🔸 Insights from Flagsmith: Discover how feature flags can revolutionize the way you deploy features and manage your testing environments, making your releases smoother and more controllable. 🔸 Insights from Cerbos: Learn about the critical importance of robust authorization systems in protecting resources and ensuring your business scales securely and efficiently. 🔸 Live Q&A: Get direct access to our experts, ask your questions, and gain deeper understanding of how these technologies can benefit your projects.
See you there! 👋
💻 5
👀 6
🎉 4
🙌 6
cerbie 5
😊 5
👍 3
a
- 2
- 1
GitHub
05/09/2024, 4:08 AM
Release - v0.36.0 New release published by github-actions[bot] Cerbos 0.36.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.36.0.html Changelog Features
• e98d5f1 feat: Add cerbosctl hub epdp list-candidates command ( #2078) • 7ba383d feat: Add cerbosctl inspect policies command ( #2101)
Enhancements
• cdf2589 enhancement: Add audit log filtering to Hub backend ( #2073) • b11597e enhancement: Apply perf patch to YAML parser ( #2132) • 2e335d5 enhancement: Write audit logs asynchronously ( #2104)
Bug fixes
• 4929745 fix: Eagerly establish gRPC connection to avoid initial delay ( #2105) • ea039c4 fix: Handle folded strings and indented newlines in YAML correctly ( #2128) • 8aac976 fix: Ignore context cancellation when writing audit log entries ( #2113) • a88733f fix: Include implicit
EFFECT_DENY
in test failure details ( #2117) • 68fcdfa fix: Kafka TLS using system CA ( #2120) • 61addb0 fix: Mark tests with missing expectations as errored ( #2116) • 0c755f2 fix: Stop blocking Kafka audit publishing when an outage occurs ( #2122)
Documentation
• b022d25 docs: Add documentation for Dagger Cerbos module ( #2106) • 31897e0 docs: Document Hub features ( #2133) • 1a04715 docs: Document how to verify cosign signatures ( #2094)
Chores
• 36d3681 chore(ci): Check results of npm package tests ( #2098) • 82f774d chore(ci): Fix E2E tests combining the host address with extra colon ( #2114) • 55b6826 chore(ci): Remove unmaintained Netlify action ( #2093) • c95f50f chore(ci): Update storage type for Jaeger chart ( #2096) • 2001128 chore(deps): Bump github.com/docker/docker from 26.0.0+incompatible to 26.0.2+incompatible in /tools ( #2108) • f74f372 chore(deps): Bump github.com/sigstore/cosign/v2 from 2.2.1 to 2.2.4 in /tools ( #2097) • e2b73f0 chore(deps): Bump golang.org/x/net from 0.21.0 to 0.23.0 in /api/genpb ( #2110) • 5ac1c32 chore(deps): Update github actions deps ( #2125) • e7d828a chore(deps): Update go deps ( #2099) • 5f96e64 chore(deps): Update go deps ( #2111) • a40093a chore(deps): Update go deps ( #2124) • 38c0f24 chore(deps): Update go deps ( #2135) • 236ab29 chore(deps): Update go deps ( #2139) • 56a29ba chore(deps): Update go deps to v2 (major) ( #2138) • 394cfa0 chore(deps): Update golangci/golangci-lint-action action to v5 ( #2127) • 70db704 chore(deps): Update golangci/golangci-lint-action action to v5.3.0 ( #2136) • c862740 chore(deps): Update node.js deps ( #2100) • cd4894a chore(deps): Update node.js deps ( #2126) • 4e40af6 chore(deps): Update node.js deps ( #2137) • 603d0ef chore(deps): Update pnpm to v9.0.5 ( #2112) • 8f7af37 chore(deps): Update to go1.22.3 ( #2143) • a5d835b chore(deps): Use latest Cerbos SDK ( #2140) • d797ebb chore(docs): Update cloud-platforms.adoc ( #2109) • 531e896 chore(release): Add 0.35.1 release notes ( #2090) • 80e10c1 … cerbos/cerbos
r
Rohit Ghumare
05/09/2024, 5:46 AM
🌟 Hey everyone! Just wanted to share some exciting insights from the recent CNCF demo where our CPO, Alex Olivier showcased the power of
GitOps for application authorization
. 🚀
👉 Main Takeaways: • Simplify Authorization: Move from complex code to straightforward, versionable policies. • Enhanced Scalability: Enjoy the benefits of a stateless, scalable architecture perfect for cloud-native setups. • Security and Compliance: With centralised audit logs, every decision can be tracked for better compliance and monitoring. 🎥 For those who missed it, you can watch the full demo [here](/content/blog/gitops-for-application-authorization ""/index.html) to see how these strategies can streamline your development workflow and enhance security measures.
💬 Please share your thoughts or how you might apply these GitOps principles in your projects! Let’s get the conversation going! 🌐
a
Anna Paykina
05/21/2024, 5:43 AM
Hey, <!channel>! There’s just 1 day left until our webinar with Flagsmith! (PS. Exclusive registration bonus included)
📅 Date & Time: May 22, 2024, 05:00 PM CEST / 11:00 AM EDT 🔗 Secure Your Spot Now 🔗
🧩 Learn from Alex Olivier of Cerbos and Ben Rometsch of Flagsmith about leveraging feature flags and robust authorization to enhance your software development. 🧩 See these technologies in action and understand how they can be applied to your projects. 🧩 Have your specific questions answered by our experts in real-time.
💡 Exclusive Registration Bonus💡 When you register, you’ll gain access to specialized guides designed to take your skills to the next level: 👉 From Cerbos: Receive an in-depth guide on implementing effective authorization models to secure your applications. 👉 From Flagsmith: Get a comprehensive manual on transitioning your project or company to using feature flags, paving the way for more controlled and flexible deployments. As well as as a playbook on modern development practices in banking.
Register today to ensure you don’t miss out on these exclusive resources that will empower you to streamline product releases and bolster security within your projects.
🙌 3
😊 2
💻 3
💡 3
g
- 2
- 2
a
Andre Du Plessis
05/21/2024, 6:34 AM
Thank you for the reminder, Anna. Could you perhaps indicate whether we will have access to the webinar recordings for future reference, please. I keep track of these (dedicated bookmark sets in my browser) for cases I want to go back to see and hear specific topics that were discussed.
a
- 2
- 2
GitHub
06/18/2024, 4:03 AM
Release - v0.37.0 New release published by github-actions[bot] Cerbos 0.37.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.37.0.html Changelog Features
• f2ad52f feat(repl): Autocomplete for REPL directives, and a small fix for filenames ( #2169) • 89e6ee9 feat: Add filtering by policy IDs to InspectPolicies RPC ( #2160) • 2efb5e5 feat: List local and imported variables in the policy with InspectPolicies ( #2141)
Enhancements
• 7de21d8 enhancement(helm): Allow deploying as a DaemonSet ( #1658) • 57cf574 enhancement: Add policy id parameter to inspect command ( #2174) • 9a6450e enhancement: Context for YAML syntax errors ( #2151) • b6f9a61 enhancement: Ensure git protocol matches the URL ( #2163) • 3ea1ea0 enhancement: Formatting options for cerbosctl inspect command ( #2179) • 04f0373 enhancement: InspectPolicies lists derived roles in the policy ( #2186) • 90bae03 enhancement: Revise API limits ( #2161)
Bug fixes
• df62cb6 fix(docs): Wildcard action wording ( #2178) • f69dfc0 fix: Detect incorrectly indented YAML ( #2153) • c8edda5 fix: Work around gRPC-Gateway bug in
X-Forwarded-For
handling ( #2152)
Chores
• 7cd8ffd chore(ci): Clear disk space for npm build ( #2149) • 5ec9716 chore(ci): Clear disk space for release workflow ( #2145) • 27df29e chore(ci): Increase timeout for npm build stage ( #2150) • 342e93b chore(ci): Upgrade to GoReleaser v2 ( #2184) • af7a526 chore(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.5.1 to 1.6.0 in /tools ( #2185) • c7e7860 chore(deps): Bump github.com/goreleaser/goreleaser from 1.26.0 to 1.26.1 in /tools ( #2154) • f567f6e chore(deps): Update bufbuild/buf-setup-action action to v1.32.1 ( #2164) • c1c49f7 chore(deps): Update bufbuild/buf-setup-action action to v1.32.2 ( #2170) • bea6ccc chore(deps): Update bufbuild/buf-setup-action action to v1.33.0 ( #2188) • b6d97dd chore(deps): Update go deps ( #2147) • 99c09ef chore(deps): Update go deps ( #2165) • d38b920 chore(deps): Update go deps ( #2171) • a059dd3 chore(deps): Update go deps ( #2181) • 85c4161 chore(deps): Update go deps ( #2187) • 2b69f59 chore(deps): Update go deps to v2 (major) ( #2167) • f55a92e chore(deps): Update golangci/golangci-lint-action action to v6 ( #2173) • cc94282 chore(deps): Update node.js deps ( #2148) • be936f2 chore(deps): Update node.js deps ( #2166) • c5dc261 chore(deps): Update node.js deps ( #2172) • 32e6336 chore(deps): Update node.js deps ( #2182) • 10b0f0c chore(docs): Redirect old versions with correct status code ( #2168) • ae7cfca chore(release): Add 0.37.0 release notes ( #2189) • bf41e87 chore(release): Prepare release 0.37.0 • c1c4049 chore(version): Bump version to 0.37.0 • a1a7010 chore: Migrate to Buf configuration v2 ( #2180) • 7fdc055 chore: Remove workaround for fixed gRPC-Gateway bug in
X-Forwarded-For
handling ( #2157) • 1a25664 chore: Update error message for invalid expression (<https… cerbos/cerbos
a
Anna Paykina
06/18/2024, 6:57 AM
Hey, <!channel>! 💻 🔉 Join us for a live webinar: “ Business Case for Externalized Authorization”!
📅 Date: June 24th ⏰ Time: 5pm CEST / 11am ET 📍 Duration: 45 minutes (including a 15 min Q&A)
As businesses grow, managing user permissions becomes a maze of complexity, often leading to security risks and inefficiencies. In this session, we’ll dive deep into the challenges and solutions for robust authorization within a scaling business.
👥 Speakers: • Alex Olivier, Cerbos CPO & Co-Founder: Expert in enterprise solutions, authorization, data management, and security. Previous roles at Microsoft, Qubit, and various startups. • Daniel Maher, Cerbos Sr DevRel Manager: Seasoned systems engineer and DevOps advocate with a rich background at Ubisoft, Mozilla, and Datadog. 🎯 What you’ll learn: 1. The internal drivers for robust authorization: compliance mandates, user role management, and secure access controls. 2. The emerging concept of external authorization: decoupling access control logic from applications for a scalable and flexible solution. 3. How external authorization can streamline operations, enhance security, and support compliance, providing a robust foundation for sustainable growth. There will also be a live Q&A session to engage directly with our experts!
⏺️ Can’t make it live? Register anyway to receive the recording link in your inbox.
👉* Register here\* 👈
cerbie 9
👀 3
🚀 4
👌 1
👏 1
🙌 8
💡 5
👏🏻 1
a
Anna Paykina
06/24/2024, 5:14 AM
happy Monday, everyone!
🚨 There’s only a few hours left until our “Business Case for Externalized Authorization” webinar! Don’t miss out! 😊
Join us today, June 24th, at 5pm CEST / 11am ET to discover how to manage roles and permissions, streamline security, and scale your business effectively.
🔵 Register here 🔵
PS. Can’t make it live? No worries! Register anyway to receive the recording in your inbox.
🙌 1
cerbie 4
📣 5
a
Anna Paykina
06/25/2024, 4:10 AM
Hey everyone! We have some more exciting news - Cerbos PDP v0.37.0 is now live 🚀
The v0.37 release of Cerbos PDP adds support for autocomplete when using the Cerbos REPL, new Kubernetes deployment options and updates to the AdminAPI. You can check out a [summary blog post here](/content/blog/cerbos-pdp-v-0-37-0-release-highlights-repl-autocomplete-kubernetes-daemon-set-and-more ""/index.html).
To discover all the details & view the full release notes, click here 👈
🚀 4
💫 2
cerbie 3
🙌 3
a
Anna Paykina
06/25/2024, 5:03 AM
And here are some more news for today 😊cerbie We’re thrilled to share [part 2 of our collaborative series with Microsoft](/content/blog/navigating-authentication-and-authorization-harnessing-the-power-of-microsoft-entra-external-id-and-cerbos-for-enhanced-application-security ""/index.html)!
🔒 This guide, co-authored by Martin Gjoshevski, Senior Customer Engineer at Microsoft, and Alex Olivier (Cerbos), CPO and Co-Founder at Cerbos, simplifies the complexities of integrating Microsoft Entra External ID with Cerbos to ensure your applications are not only secure but also adhere to best practices in user management and access control.
👉 Here’s what you’ll learn: 1. Setup and configuration: Step-by-step instructions on setting up an External ID tenant and registering your application. 2. User flow and permissions: Insights on creating user flows for sign-in/sign-up processes and managing permissions effectively. 3. Implementing Cerbos for authorization: Techniques to define and enforce dynamic access controls. 4. Practical integration: Real code samples and a comprehensive tutorial to empower you to implement these strategies in your projects. 🌐 [Read the full blog here](/content/blog/navigating-authentication-and-authorization-harnessing-the-power-of-microsoft-entra-external-id-and-cerbos-for-enhanced-application-security ""/index.html)
🔜 Looking ahead: Don’t miss our upcoming third piece of the series, where we explore advanced features of Microsoft Entra External ID and Cerbos for managing SaaS users and enhancing security postures.
🚀 5
🌟 4
cerbos 4
🙌 2
👀 2
🔐 2
h
Heidi Hokanson
06/27/2024, 11:58 AM
Hi All. Cerbos is sponsoring We are Developers World Congress this year and that means we get to give out discount codes for tickets! 🤑 The event is in Berlin, July 17-19. Use our discount code, WWC24_CERBOS_FRIENDS for 15% off.
@Sam Lock (Cerbos), @Andrew Haines (Cerbos), @Alex Olivier (Cerbos), and @Emre (Cerbos) will be at booth A46. Stop by and say hi if you're in the area! We will have some goodies for you to say thanks for being part of our community. 💛
🇩🇪 7
✈️ 4
cerbos 5
🎉 5
🙌 3
🚀 2
👀 3
👏 3
🤓 2
a
Anna Paykina
07/09/2024, 10:30 AM
😊 Hey <!channel>!
📰 Our July newsletter is out, and we wanted to share the highlights with you.
Since our last update, we’ve released [Cerbos PDP v0.37.0](/content/blog/cerbos-pdp-v-0-37-0-release-highlights-repl-autocomplete-kubernetes-daemon-set-and-more?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_NuUb9XwXE5Objmm0VwOywgCf_PgU2HJtBxT5pYrSxlwRnhewxI7J3HrK9CcRNFLTNBtPc ""/index.html), and introduced a guide which helps users navigate authentication and authorization using [Microsoft Entra External ID and Cerbos.](/content/blog/navigating-authentication-and-authorization-harnessing-the-power-of-microsoft-entra-external-id-and-cerbos-for-enhanced-application-security?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_NuUb9XwXE5Objmm0VwOywgCf_PgU2HJtBxT5pYrSxlwRnhewxI7J3HrK9CcRNFLTNBtPc ""/index.html) We have also published a blog post in which we examine the [differences between authentication and authorization](/content/blog/authentication-vs-authorization-understanding-the-difference?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_NuUb9XwXE5Objmm0VwOywgCf_PgU2HJtBxT5pYrSxlwRnhewxI7J3HrK9CcRNFLTNBtPc ""/index.html), and how they work together to secure applications.
If you’d like to be the first to receive Cerbos updates, you can [subscribe to our newsletter here](/content/subscribe ""/index.html).
💡 4
cerbie 5
👀 1
🙌 2
📰 1
💾 1
a
Anna Paykina
07/10/2024, 9:53 AM
, hello everyone!
We’ve just released a blog post (which includes a demo video), showcasing the new Cerbos Dagger module 🙌
Discover how it simplifies authorization testing, integrates with CI pipelines, and enhances security.
➡️ [Check out the blog post and watch the demo](/content/blog/cerbos-dagger-module-for-authorization-testing ""/index.html) ⬅️
🤝 3
cerbie 5
🗡️ 3
🙌 5
🙌🏻 1
d
- 2
- 1
a
Anna Paykina
07/18/2024, 8:14 AM
🎉 We are thrilled to announce that Cerbos Hub has successfully transitioned from Beta to General Availability! cerbie
A huge thank you to our community for your support, and to 500+ organizations that have put their trust into Cerbos Hub! You have been instrumental in reaching this milestone. We look forward to continuing this journey with you!
👉 [What Cerbos Hub is, why it's useful & how it solves some of the hardest challenges with externalizing authorization](/content/news/cerbos-hub-is-now-generally-available ""/index.html) 👈
🚀 Try Cerbos Hub 🚀
💫 4
cerbos 5
💥 4
🚀 12
🎉 7
🌟 5
cerbie 5
👏 1
🙌 1
a
Anna Paykina
07/23/2024, 7:50 AM
happy Tuesday, everyone!
We’ve published a new blog that dives into the essentials of implementing Role-Based Access Control in JavaScript 💡
Here’s what you’ll learn
- Integrating RBAC: Add robust authorization to your JS apps.
- Using Cerbos: Implement fine-grained access control with ease.
- Best Practices: Follow key guidelines for secure and scalable RBAC policies.
And why the piece could be worth your time 🔑
- Enhanced security: Protect sensitive data with precise access control.
- Scalability: Seamlessly manage growing user bases.
- Efficiency: Simplify role management and policy enforcement.
👉 [Curious? Dive into the full blog + tutorial](/content/blog/role-based-access-control-in-javascript ""/index.html)
💻 3
🙌 6
cerbie 6
💡 7
a
Anna Paykina
07/24/2024, 9:27 AM
hey, community! <!channel>
As well as celebrating the launch of Cerbos Hub going GA last week, we have also been busy working away adding many requested features from our users 🚀
These include: 🔵 Selective policies compilation for Embedded PDP 🔵 Detailed build errors 🔵 Playground templates 🔵 User profile management
[You can learn more here](/content/blog/cerbos-hub-july-product-updates ""/index.html)
cerbie 7
🌟 4
💪 3
💥 1
a
Anna Paykina
07/31/2024, 7:54 AM
Hello, Cerbos community! <!channel>
Cerbos’ CEO and Co-Founder, Emre Baran, recently appeared on 🎙️ The Cloud Gambit podcast to share his journey from co-founding Yonja, Turkey’s largest social network, to leading Cerbos.
This episode would be relevant for those of you interested in hearing about scaling successful startups, tech innovation, and the strategic decisions behind Cerbos.
👉 [You can check out the full blog post and listen to the podcast episode here](/content/news/the-cloud-gambit-podcast-cerbos-ceo-emre-baran-talks-startup-growth-and-shares-cerbos-insights ""/index.html)
Have a great rest of your day! 💪
🙌 3
🙌🏼 1
👏 4
🗣️ 1
cerbie 2
cerbos 2
a
Anna Paykina
08/06/2024, 7:32 AM
hey, everyone! 😊
Understanding the difference between 401 Unauthorized and 403 Forbidden errors is crucial for developers and security experts.
📚 Which is why we put together a blog post on this topic, where you can learn: • The distinct causes behind each error. • How to troubleshoot and resolve these common issues. • Best practices to avoid these errors in your applications. 👉 [https://www.cerbos.dev/blog/401-vs-403-error-whats-the-difference](/content/blog/401-vs-403-error-whats-the-difference ""/index.html) 👈
🌟 6
💡 8
🐛 3
💪 6
j
- 2
- 2
a
Anna Paykina
08/06/2024, 10:30 AM
Some more news to share with you all 🙂
📰* Our monthly newsletter\* went out earlier today! Here’s what we covered in there:
• [Cerbos Hub being released into general availability](/content/news/cerbos-hub-is-now-generally-available?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html). • New [features added to Cerbos Hub](/content/blog/cerbos-hub-july-product-updates?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html) • [Cerbos Dagger module](/content/blog/cerbos-dagger-module-for-authorization-testing?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html) for authorization testing • Guides on implementing [role-based access control in JavaScript](/content/blog/role-based-access-control-in-javascript?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html) and [authorization in Gorilla applications](/content/blog/gorilla-authorization?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html) • Steps to reducing risks associated with [authorization failure](/content/news/decrease-the-cost-of-failure-in-authorization?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html) • Our Co-Founder and CEO, Emre Baran, on [The Cloud Gambit podcast](/content/news/the-cloud-gambit-podcast-cerbos-ceo-emre-baran-talks-startup-growth-and-shares-cerbos-insights?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_WL6qLSturbkN9a0xz624ywAMsbJ4ufsPS2uw1uX6BGoVW8c6D5g4nnplj653n1Lob09QVbEcwgjHrI_1UC8_1IxXpSSeAdvcPw9xY6Xrf5mDYf_M ""/index.html), sharing his experience building and scaling successful startups You can always [subscribe to our newsletter](/content/subscribe ""/index.html) to get future updates as soon as they come out
💡 4
🌟 6
cerbie 6
🪶 2
🚀 3
GitHub
08/07/2024, 4:13 AM
Release - v0.38.1 New release published by github-actions[bot] Cerbos 0.38.1
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.38.1.html Changelog Chores
• 3284851 chore(ci): Remove AWS dev and latest container tags ( #2256) • 87cda73 chore(release): Add 0.38.1 release notes ( #2257) • a56ff6b chore(release): Prepare release 0.38.1 • d124b93 chore(version): Bump version to 0.39.0 cerbos/cerbos
💾 1
a
Anna Paykina
08/08/2024, 11:29 AM
Happy Thursday, Cerbos community! We hope you all are having a great week ☀️💪
We wanted to let you know that Cerbos PDP v0.38.1 has been released [If you’re interested, you can check out the details here](/content/blog/cerbos-pdp-v0-38-1-release-highlights-policy-variables-sbom-support-improved-error-messages-and-helm-updates ""/index.html)
🙌 3
cerbie 4
🚀 3
cerbos 2
🎁 1
a
Anna Paykina
08/30/2024, 9:50 AM
Hey, <!channel>! 😊👋
We wanted to let you know that, Alex Olivier recently sat down with Twain Taylor on the Amazic Podcast to talk about what’s new at Cerbos, especially after the [GA launch of Cerbos Hub](/content/news/cerbos-hub-is-now-generally-available ""/index.html).
They dug into some real-world challenges around authorization—how to manage policies at scale, what’s happening with standardization in the space, and even a bit about our journey from idea to product.
We’ve summarized the key takeaways in a new blog post. If you’re interested - give it a read and check out the full episode for even more details. 👉 [https://www.cerbos.dev/news/unveiling-the-future-of-authorization-with-cerbos](/content/news/unveiling-the-future-of-authorization-with-cerbos ""/index.html)
🙌 3
💫 1
💥 2
🌟 3
cerbie 6
💯 5
cerbos 1
a
Anna Paykina
09/03/2024, 8:44 AM
Hey <!channel>!
We’re happy to announce that [Cerbos Hub Audit Logs are live in beta!](/content/blog/cerbos-hub-audit-logs-live-in-beta ""/index.html) 🎉
Cerbos Hub Audit Logs offer a comprehensive, centralized solution for capturing and analyzing authorization decisions across all your PDP instances. Whether you’re a developer, security engineer, or product manager, this feature will make security and compliance easier to achieve.
👉 By configuring your PDPs to send audit logs to Cerbos Hub, you get an immediate log aggregation to securely collect, store, and query audit logs from across your fleet. • Are you looking for a simple way to manage and analyze your audit logs? Every request, every decision, every bit of metadata—and all of this is fully customized for your needs! • Are you only interested in denies? You got it. • Are you in a regulated environment and you need to mask certain fields? Not a problem. And, since everything is natively Cerbos, the audit logs interface in Hub takes full advantage of the context of each log entry. This means you can deep dive into every decision to understand why it was made, and even which version of the policy was active at the time.
If you’d like to learn more - check out our latest blog post for all the details and start exploring the potential of Cerbos Hub today. We’d love for you to try it out and share your feedback with us! 😊
[Read the blog post](/content/blog/cerbos-hub-audit-logs-live-in-beta ""/index.html) [Try Cerbos Hub](/content/product-cerbos-hub ""/index.html)
Happy logging! 🙌
🙌 5
cerbie 5
🎉 3
🌟 3
🚀 5
🪵 4
a
Anna Paykina
09/04/2024, 8:03 AM
Hey everyone! Here’s some more fun news 🙂 ⬇️
We have a new blog post out, discussing the best solution for user authorization: PBAC vs. Zanzibar
Option 1️⃣ PBAC with Cerbos: Flexible, scalable, and stateless – ideal for real-time access control decisions. Option 2️⃣ Zanzibar: Centralized, fine-grained control for static, high-volume resources.
👉 [Check out the full blog to learn more](/content/blog/pbac-vs-zanzibar-finding-the-right-fit-for-your-application ""/index.html) 👈
cerbie 3
🚀 2
💡 6
🙌 3
cerbos 3
GitHub
10/01/2024, 3:08 AM
Release - v0.39.0 New release published by github-actions[bot] Cerbos 0.39.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.39.0.html Changelog Features
• 2dcf619 feat: Add Role policies ( #2192) ( #2260) • 7bd0a2d feat: Add public API for running a PDP in-process ( #2297)
Enhancements
• 8bcd411 enhancement: Add more trace spans to engine ( #2324) • e2da55c enhancement: Atomic refreshes for blob storage ( #2263) • 7add5fe enhancement: Change how blob storage creates work directories and add metric for the last store refresh ( #2284) • 1f532ca enhancement: Display attributes in the cerbosctl inspect policies command ( #2301) • f4afc44 enhancement: Get/put cerbosctl role policy support ( #2274) • 259eeb0 enhancement: Improvements to atomic refreshes for blob storage ( #2283) • 4a9830c enhancement: Keep cached files under base64 encoded directory for blob storage ( #2292) • 25bd4c2 enhancement: Remove eager log initialisation from schema validation ( #2287)
Bug fixes
• 3ac50c4 fix(docs): Update Helm doc ( #2278) • 670b3fe fix(helm): Allow overriding listen addresses ( #2289) • 86cf020 fix(helm): Fix schema definition of initContainers ( #2305) • 955a0c4 fix(schema): Support TLS with reverse proxy ( #2300) • f901abd fix: Move runtime role policy proto scope level ( #2321)
Documentation
• bfbef28 docs: Add role policies sections ( #2253) ( #2261) • 05917f2 docs: Document the Cerbos Nix flake ( #2309) • 28902c6 docs: Fix missing default value for
storage.hub.remote.disableAutoUpdate
( #2298) • 335a8f2 docs: Spell Datadog properly ( #2270)
Chores
• 494db09 chore(ci): Clear disk space for cache workflow ( #2268) • 4291df1 chore(ci): Clear disk space for upload workflow ( #2269) • 943078e chore(ci): Clear disk space for vulnerability check ( #2271) • 95a39cb chore(ci): Clear disk space on PR run ( #2266) • 07d83f6 chore(ci): Set SQL Server image pull policy for E2E tests ( #2304) • 607d08c chore(ci): Trust SQL Server certificate ( #2307) • 6fb7cf8 chore(deps): Bump github.com/docker/docker from 27.1.0+incompatible to 27.1.1+incompatible in /tools ( #2277) • cdd71fe chore(deps): Bump github.com/opencontainers/runc from 1.1.13 to 1.1.14 ( #2306) • 7bdbbe7 chore(deps): Update bufbuild/buf-setup-action action to v1.37.0 ( #2286) • fd8f19f chore(deps): Update bufbuild/buf-setup-action action to v1.38.0 ( #2296) • 07fec41 chore(deps): Update bufbuild/buf-setup-action action to v1.39.0 ( #2302) • bc56290 chore(deps): Update bufbuild/buf-setup-action action to v1.41.0 ( #2311) • 9b307d2 chore(deps): Update bufbuild/buf-setup-action action to v1.42.0 ( #2320) • 6c10a02 chore(deps): Update github actions deps ( #2275) • 21c5bc6 chore(deps): Update go deps ( #2276) • 5508335 chore(deps): Update go deps ( #2285) • ba7bad9 chore(deps): Update go deps ( #2295) • 2481b79 chore(deps): Update go deps ( #2303) • 0b79e26 chore(deps): Update go deps ( #2310) • <https://github.com/cerbos/cerbos/commit/a1f40a7d6ba872664e40443103… cerbos/cerbos
🆗 2
h
Heidi Hokanson
10/08/2024, 7:47 AM
Hey <!channel> 👋
Some new features have just landed in Cerbos Hub Playground! These features are designed to help speed up your workflow and improve your testing experience.
⚡ RBAC Policy Generator: This public playground feature is now available in your Hub playgrounds. Define RBAC policies using a no-code wizard that automatically populates your Playground with YAML policies and generates test data for them.
⚡ API Request Simulator: Also a public playground feature migrating to Hub that you can use for debugging and understanding how your policies work in real-world scenarios.
⚡️ Connect a PDP - Exclusive to Cerbos Hub: Connect a local PDP in a development environment to the Playground and see real-time results as you work. No need to download files or reconfigure the PDP for each change.
Links to more information: 🔗 📺
Video demo of each new feature▾
by @Alex Olivier (Cerbos) 📰 [Our new feature announcement on the Cerbos Blog](/content/news/new-tools-for-effortless-policy-creation-and-testing-in-cerbos-hub ""/index.html). 📖 Updated documentation for the Cerbos Hub Playground.
Jump into Cerbos Hub and give these new features a try! As always, feel free to share your feedback or ask any questions here—we’re excited to hear what you think.
🎉 7
cerbos 5
🌟 5
👍 5
🙌 5
🚀 4
cerbie 3
🥳 1
a
Anna Paykina
10/09/2024, 6:42 AM
Hey, Cerbos community 😊 <!channel>
📰* Our monthly newsletter\* went out earlier this week! Here’s what we covered in there:
• New features in the [Cerbos Hub Playground](/content/news/new-tools-for-effortless-policy-creation-and-testing-in-cerbos-hub ""/index.html) are now available • Cerbos PDP v0.39.0 has gone live • Guide to help you implement [externalized authorization](/content/blog/the-technical-complexities-of-externalized-authorization ""/index.html) in the right way • [Zero trust authorization](/content/blog/zero-trust-authorization ""/index.html) and its importance in app security • Emre Baran on the [Front End Happy Hour podcast](/content/news/front-end-happy-hour-podcast-leadership-startups-and-gtm-with-emre-baran?utm_campaign=monthly%20newsletters&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_W2He5v8bcbxV00EKG__YRRl59ctFCnlKUEeuZE6Al2MUrpVNSxLF7MaiWIs2SIGVx7IRmWncatCT-EQX_nDdbRfdSJfy2W96dpRa1LIaAibkeHZw ""/index.html), discussing the realities of scaling a business PS. You can always [subscribe to our newsletter](/content/subscribe ""/index.html) to get future updates as soon as they come out
cerbie 6
🎉 4
🙌 4
🚀 4
cerbos 2
d
Daniel Maher
10/09/2024, 10:18 AM
👋 Hi @channel! My name is Dan, and I’m one of the engineering folks here at Cerbos. As you might have noticed in the monthly newsletter that just went out, we’ve got lots of fun and interesting things planned for our Slack community, and I’m genuinely excited to get things started. Very briefly, our calendar kicks off on 16 October with a Policy Chillout livestream, followed on 22 October with an open source Q&A, and then an interactive presentation about stateless architecture on 30 October. Lots of stuff to come, including AMAs, hack sessions, and more!
I’ve posted way more details in #C028A53GAJE. Really looking forward to meeting you all! 😄
cerbie 7
🙌 2
a
Anna Paykina
10/15/2024, 6:43 AM
Hey, <!channel>! 😊👋
We just published a new blog post explaining:
• What authorization is, and why it’s a key component of secure systems. • Different models, like Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and more. • Why understanding these concepts is crucial for building secure, scalable applications that balance flexibility and protection. 👉 [Check out the piece to learn more](/content/blog/what-is-authorization ""/index.html) 👈
💡 3
🙌 4
👍 3
🔒 1
a
Anna Paykina
10/15/2024, 1:28 PM
Some more exciting news 💫
Join our “Policy Chillout” livestream on 16 October at 14:00 UTC 🧑💻🛠️
Hang out with the Cerbos engineers as we talk shop, write policies, and dive into test cases. We’d love for you to bring your design questions—or just enjoy the vibes and relax with a nice mug of YAML 😉
👉 Watch live: https://www.youtube.com/live/6A7Wa5exC3Y
🎉 8
💡 5
😊 5
👌 1
a
Anna Paykina
10/22/2024, 11:00 AM
hey <!channel> :))
If you want to get more involved in open source, but you’re not sure where to start ➡️ Join us today, 22 October at 17:00 UTC, for our livestream “Everything you wanted to know about Open Source” 📅
We’ll cover what open source is, how to get started, and tips for staying healthy as an OSS contributor or maintainer.
👉 Watch live: https://lnkd.in/dhmJ7igM 👉 Ask questions in Slack
See you in 2 hour!
💡 4
cerbie 3
😊 2
🌟 2
💾 2
cerbos 1
a
Anna Paykina
10/23/2024, 5:51 AM
Happy Wednesday, <!channel>! We have a fun livestream coping up later today, featuring our CPO, Alex Olivier, which we wanted to share with you 😊
📅 Date: October 23, 6pm CEST / 12pm EDT 🔍 Topic: Beyond the black box - implementing robust authorization in RAG-based AI systems
As more companies adopt AI agents with RAG architectures, a key security challenge arises: how to effectively implement and manage authorization within these complex systems? This talk explores the intricacies of overlaying authorization logic on AI agents, particularly within RAG architectures, and presents a context-aware solution using externalized authorization.
📍 Register here PS. you can’t attend live - no worries. The recording will be available 😊
🌟 4
📹 4
cerbie 5
🤖 1
a
Anna Paykina
10/23/2024, 6:14 AM
And in others news, we’ve also recently published a guide, where we demonstrate how to implement authorization using Cerbos in Go (Echo) 💻
By the end of the guide, you’ll know how to set up a secure RESTful API in Go and enforce access control policies using Cerbos.
👉 [You can check it out here](/content/blog/how-to-implement-authorization-in-go ""/index.html) 👈
cerbie 6
🙌 3
🚀 1
a
Anna Paykina
10/24/2024, 12:40 PM
Hey, <!channel>! 👋
We just published a guide on using Cerbos with JWT! 💻 💡
➡️ [Feel free to check it out](/content/blog/json-web-tokens-authorization-cerbos?utm_campaign=brand_cerbos&utm_source=linkedin&utm_medium=social&utm_content=&utm_term= ""/index.html) ⬅️
😊 3
cerbos 6
🙌 4
👀 2
a
Anna Paykina
10/30/2024, 6:39 AM
Hey <!channel>! Happy Wednesday :))
🙌 We’re excited to invite you to our new live stream today on stateless architecture and microservices — it’s happening at 5 pm UTC!
💻 Tune in here: https://www.youtube.com/live/t_Y90TZzx1Y 💬 Join the conversation on Slack: Leave your messages in the #C028A53GAJE channel (we’ll be answering your questions live)
See you soon!
_PS. We’ll be sharing some more, very exciting and secret (for now) news, in a few hours with you. So stay tuned_🚀cerbos
👏 3
cerbie 3
🎉 2
💡 3
👀 2
a
Anna Paykina
10/30/2024, 9:21 AM
Aaand hello again, <!channel>! Here’s the news we wanted to share!
🎉 We have just launched our eBook 📖➡️ “Monolith to microservices migration: 10 critical challenges to consider”
Transitioning from a monolithic architecture to microservices is an intricate, time-consuming task. It’s much larger than just a project... It’s a program to change the entire organization.
Which is why we put together this 10-part series 😊In it, we’ll guide you through the process of re-architecting both your tech stack and organizational structure when transitioning from a monolith to a microservice.
💡 If you’d like to download the eBook - please DM @Aram Andreasyan, and he will send it to you 💡
😊 🙏 If you have a moment, and find the eBook to be helpful, please support our launch by liking our LinkedIn announcement post! We would really appreciate it.
PS. Check out the comment under this thread if you want to get a glimpse into what we cover in each of the 10 chapters.
cerbie 6
👏 4
🙌 5
👀 3
cerbos 4
🎉 8
- 1
- 1
a
Anna Paykina
10/31/2024, 3:21 PM
Happy Halloween from Cerbos! 🎃
🎃 5
cerbie 4
💫 2
1️⃣ 1
😁 2
👻 1
a
Anna Paykina
11/05/2024, 5:39 AM
Hello, <!channel>!
Join us for tomorrow’s AMA 🙌
Details ⬇️
cerbie 3
💡 3
😊 1
💬 3
a
Anna Paykina
11/06/2024, 7:17 AM
Hey, Cerbos community 😊
📰* Our monthly newsletter\* went out earlier today! Here’s what we covered in there:
• CI pipeline updates in [Cerbos Hub](/content/product-cerbos-hub ""/index.html) • New guides on managing [RBAC in Kubernetes](/content/blog/guide-to-kubernetes-rbac ""/index.html), Java authentication and [authorization](/content/blog/authentication-and-authorization-in-java ""/index.html), implementing authorization using [Cerbos in Go](/content/blog/how-to-implement-authorization-in-go ""/index.html), using [Cerbos with JWT](/content/blog/json-web-tokens-authorization-cerbos ""/index.html), and [authorization in Express](/content/blog/implement-authorization-in-express ""/index.html) applications • Importance of thinking about both your [security and users](/content/blog/security-and-users-when-implementing-authorization ""/index.html) when implementing authorization • Why [granular, scalable control is a must](/content/blog/why-granular-scalable-control-is-a-must-for-every-cto ""/index.html) for every CTO • 🌟 Milestone alert 🌟 Cerbos PDP has surpassed 3,100 stars on GitHub! We’re grateful for the growing community support and trust. Check out our repository here. PS. You can always [subscribe to our newsletter](/content/subscribe ""/index.html) to get future updates as soon as they come out
🌟 3
📰 1
cerbie 1
a
Anna Paykina
11/06/2024, 10:11 AM
Also, check out our new guide on how to use ReactJS for secure RBAC 🙂 💡
[https://www.cerbos.dev/blog/how-to-use-react-js-for-secure-role-based-access-control](/content/blog/how-to-use-react-js-for-secure-role-based-access-control ""/index.html)
😊 1
💻 1
a
Anna Paykina
11/12/2024, 9:19 AM
Hey <!channel>! Happy Tuesday! 🙂
We have introduced a new use case - Securing access control for RAG and LLMs with Cerbos 🌟
The functionality is available natively as part of Cerbos PDP and Cerbos Hub. So if you’re looking for ways to install guardrails around your AI applications 👉 you can find the details here.
🙌 5
cerbie 6
🔒 4
💪 4
👀 2
🙌🏼 1
🙌🏻 1
🤖 2
a
Anna Paykina
11/13/2024, 6:18 AM
Hey community!
Happy to share that Cerbos is now in the running for the Hackernoon startups award (under cybersecurity -> access control) 🙂 ⭐
If you would like to support us, you can do so by clicking on Cerbos and giving us a vote 🙌 https://hackernoon.com/startups/europe/europe-london-england-uk?stup=66b3e24a34a7dea7f897aa3c
🙌 3
🙌🏼 1
a
Anna Paykina
11/19/2024, 5:59 AM
hey <!channel>!
If you’re using Supabase, do check out our [new demo Supabase + Cerbos](/content/blog/cerbos-supabase ""/index.html) 💡
cerbie 1
🌟 2
💡 1
🫶 1
🦸 1
a
Anna Paykina
11/20/2024, 8:45 AM
Hey <!channel> ! We have some news for you :) [Cerbos is now available on AWS Marketplace](/content/news/cerbos-aws-marketplace ""/index.html)! 🎉
For those of you already using Cerbos, this means even more flexibility and simplicity when managing your fine-grained access controls within your AWS environment.
If you’re just getting started with Cerbos, it’s the perfect time to dive in and take advantage of AWS integration! 🙌
As always, we’re here to help, answer any questions, and hear your feedback!
🙌🏼 1
🙌 3
☁️ 3
aws 3
a
Anna Paykina
11/25/2024, 10:03 AM
Hey, <!channel>!
We wanted to share a very interesting piece by Michael Westergaard with you 🙂
In his step-by-step guide, Michael goes through building authorization with Spring Security and Spring Data JPA. Feel free to check it out here 👉 https://westergaard.site/2024/11/towards-better-spring-support-for-cerbos/
😊 2
🙌 2
🌟 2
♨️ 4
☕ 2
GitHub
11/26/2024, 9:18 AM
Release - v0.40.0 New release published by github-actions[bot] Cerbos 0.40.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.40.0.html Changelog Features
• 18f8e37 feat(plan): Add support for role policies ( #2341) • 9ff41a4 feat: Allow default policy version to be configured in tests ( #2352) • 0ead3be feat: Define constants for use in condition expressions ( #2364) • 2856d7d feat: Multiple principals and/or resources in a test case ( #2338) • fcc3e75 feat: Support constants in
cerbosctl
( #2365) • ee13be0 feat: Use groups of principals and/or resources in test cases ( #2340)
Enhancements
• b2e1f04 enhancement!: Report an error if a test exercised time-based policy conditions without specifying
now
( #2354) • a5b7f8e enhancement(plan): Query plan scope permissions support for resource and principal policies ( #2361) • 886248a enhancement: Add user-agent to default allowed headers for CORS ( #2345) • debdefc enhancement: Introduce policy scope FALL_THROUGH_ON_ALLOW strategy ( #2325) • 018340b enhancement: Make
--verbose
less noisy in combination with
--run
( #2351) • c1d16b9 enhancement: Make
now
fully deterministic ( #2353) • d3a3448 enhancement: Make scopePermissions a required field on role policies ( #2333) • 2fb5853 enhancement: Role policies parent roles field ( #2349) • 8d92d97 enhancement: Validate fixtures files with JSON schemas to improve error messages ( #2346)
Bug fixes
• ba1ebf0 fix(helm): Remove whitespace chomp for priorityClassName so valid yaml is rendered ( #2337) • b7e5c77 fix(plan): A policy with only conditional DENY rule must produce
ALWAYS_DENIED
( #2369) • 6093dac fix: Command execution fails with
cerbos run
since v0.39 ( #2358) • 5c2d31e fix: Inspect policy output expressions ( #2392) • 9851460 fix: Populate path field of validation errors ( #2363)
Documentation
• f8b0a47 docs: Remove extraneous space that breaks rendering ( #2347) • 02141da docs: Update gRPC API section ( #2387)
Chores
• c95133d chore(ci): Increase E2E test timeout ( #2359) • 591d25d chore(deps): Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 in /tools ( #2378) • 0a49f42 chore(deps): Revert to upstream go-yaml ( #2383) • 40ca449 chore(deps): Update bufbuild/buf-setup-action action to v1.45.0 ( #2334) • c0fa72b chore(deps): Update bufbuild/buf-setup-action action to v1.47.2 ( #2382) • 91ca366 chore(deps): Update dependency node to v22 ( #2377) • d6203ed chore(deps): Update dependency verdaccio to v6 ( #2357) • 254d95a chore(deps): Update github actions deps ( #2332) • 3cc8070 chore(deps): Update github actions deps ( #2375) • 555e227 chore(deps): Update go deps ( #2331) • 6e20018 chore(deps): Update go deps ( #2335) • 04d11c5 chore(deps): Update go deps ( #2355) • f3539fe chore(deps): Update go deps ( #2360) • 576637c chore(deps): Update go deps ( #2367) • 3e47658 chore(deps): Update go deps ( #2376) • d9ca1ed chore(deps): Update go deps ( #2381) • e862e9a chore(deps): Update go deps (<https://github.com/cerbos/cerbos/pull/2385\|… cerbos/cerbos
a
Anna Paykina
12/02/2024, 10:08 AM
hey <!channel>! 🙂 Happy Monday!
We’re happy to share that chapter 5 of our “Monolith to Microservices Migration ebook” is now live on our blog!
👉 [https://www.cerbos.dev/blog/monitoring-and-observability-microservices](/content/blog/monitoring-and-observability-microservices ""/index.html) This week, we’re diving into the challenges of implementing monitoring and observability in microservices architectures & ways to overcome them.
PS. Next week we’ll publish the next post in the series: “Testing and deployment strategies in the microservices architecture”. Or, you can download the complete 10-part series in one e-book now: "Monolith to microservices migration: 10 critical challenges to consider".
📖 3
🙌 3
💡 2
cerbie 2
a
Anna Paykina
12/03/2024, 8:14 AM
Hey <!channel> ! We have some exciting news we want to share with you 🙂
🚀 We have introduced new features to Cerbos PDP! [Cerbos PDP](/content/product-cerbos-pdp ""/index.html) (our open source solution) enables our users to define powerful, context-aware access control in simple, intuitive, and testable policies. New updates include:
• 🆕 Support for policy versioning and scoping enabling per-tenant, per application policy design and iteration fitting into existing software development workflows. • 🆕 Policy inspection via cerbosctl inspect command and API endpoint provides programmatic access to an outline of policies, to drive UI and policy manipulation as well as supporting debugging. • 🆕 Detailed error reporting with concise policy test outputs and clear error descriptions along with contextual information, to help debug access policies issues faster. • 🆕 Artifact signing and SBOM generation. All Cerbos release artifacts, binaries and containers, are now signed using Sigstore, making them verifiable for end-to-end sof*tware supply chain security.* • 🆕 Local PDPs connected to Cerbos Hub Playgrounds enables developers to author policies and in real time see their impact in the application they are developing. Check out our latest release notes for more details. PS. We’re also happy to share that this week we surpassed 3333 stars on Github! Please support us with your star 🙏 😊
🚀 2
cerbie 4
cerbos 2
🌟 4
📈 1
a
Anna Paykina
12/09/2024, 7:07 AM
hey, Cerbos community! ☀️
We’re happy to share that chapter 6 of our “Monolith to Microservices Migration ebook” is now live on our blog! [https://www.cerbos.dev/blog/testing-and-deployment-strategies-microservices](/content/blog/testing-and-deployment-strategies-microservices ""/index.html) 📖
This week, we’re diving into the best practices for testing and deploying microservices & go though an example of how Netflix ensures durable deployment with rigorous testing.
PS. Next week we’ll publish the next post in the series: “Understanding the security and access control requirements of microservices environment”. Or, you can download the complete 10-part series in one e-book now: "Monolith to microservices migration: 10 critical challenges to consider".
📖 3
cerbie 2
🙌 1
💡 1
a
Anna Paykina
12/16/2024, 9:02 AM
hey <!channel>! Happy Monday! We’re happy to share that chapter 7 of our “Monolith to Microservices Migration ebook” is now live on our blog! [https://www.cerbos.dev/blog/security-and-access-control-microservices](/content/blog/security-and-access-control-microservices ""/index.html)
This week, we’re diving into the potential vulnerabilities of a microservices architecture, and how to safeguard against them.
PS. On January 13, 2025, we’ll publish the next post in the series, on achieving optimal performance and scalability in microservices architectures. Or, you can download the complete 10-part series in one e-book now: "Monolith to microservices migration: 10 critical challenges to consider".
🙌 2
📖 3
🎉 2
🙌🏼 1
❤️ 1
a
Anna Paykina
12/19/2024, 5:34 AM
Hey everyone! We recently published a new blog post “ [CRDTs and collaborative playgrounds](/content/blog/crdts-and-collaborative-playground ""/index.html)” 👀 💻
One of the tools we offer is a collaborative IDE and testing environment we nicknamed the “ [Playground](/content/features-benefits-and-use-cases/cerbos-playground ""/index.html)” (because access control should be a joy, not a chore). We saw real value in building the environment with collaboration in mind—both for efficiency in authoring policies and also as a tool for sharing knowledge or educating others.
But how does one make an app collaborative? There are several approaches, but we chose one that stands out for its elegance and efficiency. To enable this seamless collaboration, we’ve leveraged the power of Conflict-Free Replicated Data Types (CRDTs).
Check out the blog for a deep dive into how we use CRDTs.
🙌 1
cerbie 2
👀 1
💻 1
a
Anna Paykina
12/19/2024, 2:07 PM
hey everyone! Coming back to you with some more news 🙌
We’ve just published a blog post on [how to build an authorization system for your RAG applications with LangChain, Chroma DB and Cerbos](/content/blog/authorization-for-rag-applications-langchain-chromadb-cerbos ""/index.html) 🔒
Check it out if you’re interested in diving into: • A hands-on example of RAG applications and how to develop them in Python using the LangChain framework and Chroma DB. • Various security concerns for RAG architecture. • Overview of various authorization techniques. • Importance of authorization for RAG applications. • Implementing RAG authorization system using Cerbos, an open source authorization layer.
💪 2
cerbie 4
👍 1
👍🏻 1
🤖 1
a
Anna Paykina
12/20/2024, 10:52 AM
Happy Friday, Cerbos community! 😊
As 2024 comes to an end - we wanted to recap some of our highlights from the year 🌟
Over the course of 2024, our team members attended over 20 conferences, our founders appeared as guests on 15 podcasts, our open-source PDP reached over 3400 stars on GitHub, and our Slack community (you all!) grew to over 500 members! 💪 [More details here](/content/news/a-look-back-at-2024 ""/index.html) We thank all of you for being part of our community, and for showing us support!
Happy holidays! 🎄☃️
🌟 5
🎄 5
cerbos 5
❄️ 3
🎅 2
🍾 3
🎉 4
a
Anna Paykina
01/09/2025, 12:57 PM
Hey <!channel>! We hope you’ve all had a great start to the new year ☺️🎉
Happy to share that chapter 8 of our “Monolith to Microservices Migration ebook” is now live on our blog! [https://www.cerbos.dev/blog/performance-and-scalability-microservices](/content/blog/performance-and-scalability-microservices ""/index.html)
This week, we’re diving into the challenges of optimizing a microservices architecture for scalability and performance, and how to navigate them.
Or, you can download the complete 10-part series in one e-book now: "Monolith to microservices migration: 10 critical challenges to consider".
👋 2
🙌 3
📖 4
🌟 3
🙌🏻 1
cerbie 8
👋🏼 1
🙌🏼 1
a
Anna Paykina
01/13/2025, 7:22 AM
Hey <!channel>, happy Monday! Chapter 9 of our “Monolith to Microservices Migration ebook” is live! [https://www.cerbos.dev/blog/organizational-technical-challenges-migrating-monolith-to-microservices](/content/blog/organizational-technical-challenges-migrating-monolith-to-microservices ""/index.html)
This week, we’re examining how to navigate the associated cultural shift and challenges, when going through a monolith to microservices migration. Amazon example included 😊
📖 4
🙌 2
😊 3
🙌🏼 1
🚝 1
a
Anna Paykina
01/14/2025, 6:35 AM
Hello, Cerbos community! We have some exciting news we wanted to share with you all 🙂
Startups 100, the UK’s longest-running index of disruptive new startups, has unveiled its 2025 edition, and Cerbos proudly ranks 30th on the list! 🏅 🚀
If you’re interested in discovering the details - you [can check out our blog post on the news](/content/news/startups-100-cerbos ""/index.html).
🏅 5
🚀 5
cerbie 4
🙌 3
a
Anna Paykina
01/16/2025, 10:10 AM
Hey <!channel>! We wanted to share a new piece written by @Hasan Ayan with you 😊
The Backend for Frontend concept in Remix and its associated hooks such as useLoaderData or useFetcher are great tools for building dynamic pages. In most cases, these hooks provide a simple and reliable way of getting data from loaders. 🤔 However, there are some cases where this concept imposes certain limitations.
While working on our Audit Logs feature, we hit one of them. [In this article, Hasan Ayan shares more on that limitation and shows how we implemented a solution for ourselves](/content/blog/useasyncfetcher-implement-asynchronous-fetch-in-remix ""/index.html) 🔑
💡 3
🌟 2
cerbie 4
💪 2
🔑 2
💪🏻 1
💪🏼 1
a
Anna Paykina
01/20/2025, 6:55 AM
Hey <!channel>! 👋
The final chapter (10) of our “Monolith to Microservices Migration ebook” is now live on our blog! [https://www.cerbos.dev/blog/team-collaboration-and-code-ownership-microservices](/content/blog/team-collaboration-and-code-ownership-microservices ""/index.html)
This week, we’re diving into effective team collaboration and code ownership for managing microservices systems.
cerbie 4
👀 3
🌟 3
📖 4
a
Anna Paykina
01/22/2025, 8:58 AM
Hey everyone, wanted to share our latest blog with you 🙂⬇️
Auth0 is a popular platform when it comes to identity and access management services. However, the growing need for customizable, self-hosted solutions has led organizations to explore open source alternatives.
Our latest blog dives into six solid contenders: Keycloak, Gluu, Authentik, Authelia, SuperTokens, and FusionAuth.
🔗 Read the full article here & find the right fit for your next project [https://www.cerbos.dev/blog/auth0-alternatives](/content/blog/auth0-alternatives ""/index.html)
💡 2
🙌 1
a
Anna Paykina
01/22/2025, 10:38 AM
Hey again, <!channel>
We recently released a blog post + video on the [11 trends that will define the future of authorization](/content/blog/11-authorization-and-iam-trends-in-2025 ""/index.html) 💡
If you’re interested - feel free to check it out!
The piece is based on our expertise as an enterprise authorization provider, and insights from hundreds of conversations with architects, IAM leads, and CISOs we got a chance to speak with over the past year.
👀 3
🚀 3
😊 2
👏 2
👏🏼 1
a
Anna Paykina
01/29/2025, 8:24 AM
Hey, <!channel>!
We have rolled out an update to the Cerbos Hub Playground that’s tailored for those of you who are building more complex policies and want a development experience that mirrors real-world deployments more closely.
This update introduces Cerbos Hub Playground engine settings, letting you configure the Cerbos PDP engine used when evaluating policy during development, in a way that reflects your actual environment.
👉 [Get the details here](/content/blog/cerbos-hub-playground-engine-settings ""/index.html)
💡 3
cerbie 4
🚀 5
a
Anna Paykina
01/30/2025, 6:32 AM
Hey, Cerbos community! 👋😊
We just published a blog post discussing the core principles, advantages and disadvantages, and practical concerns of stateless architecture. [Feel free to check it out here](/content/blog/statements-about-stateless ""/index.html)
🙌 3
👀 3
cerbie 3
🙌🏼 1
💻 1
d
a
- 3
- 2
a
Anna Paykina
02/04/2025, 7:15 AM
Hey <!channel>!
Feel free to check out our latest blog post, it’s about implementing authorization and access control in Flask
👉 [https://www.cerbos.dev/blog/authorization-in-flask](/content/blog/authorization-in-flask ""/index.html) 👈
👀 2
👏 2
cerbie 4
👏🏼 1
🐍 1
a
Anna Paykina
02/07/2025, 12:49 PM
Happy Friday, community 👋 😊
We just published a deep dive into externalized authorization management (EAM). In the blog, we cover: • what EAM is; • when you might need it; • the associated technical benefits; • along with how to implement it. 👉 [Feel free to check out the blog on EAM here](/content/blog/externalized-authorization-management-eam-and-benefits ""/index.html) 👈
Have a great weekend!
🙌 2
😊 1
cerbos 2
a
Anna Paykina
02/11/2025, 10:46 AM
hey everyone! :)
We just published a blog post, where we explore different approaches to enforcing RBAC and ABAC in an enterprise context. As well as what drives the business need to choose between RBAC and ABAC, the various architectural deployments of these access control methods, and the implications of their selection.
If you’re interested, [you can find the blog with all the details here](/content/blog/enterprise-access-control ""/index.html)
cerbie 3
🙌 2
👍 5
a
Anna Paykina
02/12/2025, 8:46 AM
Hey community!
We have some exciting news! Cerbos PDP - our open-source authorization solution, just hit 3.6k stars on GitHub! 🚀 🎉 https://github.com/cerbos/cerbos
Thank you all for your support ☺️💪
cerbie 4
💪 1
cerbos 1
🏅 2
💫 2
a
Anna Paykina
02/17/2025, 8:53 AM
Hey, <!channel>! 👋
We have a new blog out, where we discuss our journey from using OPA to building our own engine.
If you’re interested in the details (as well as understanding why we decided to make that transition, and what benefits we have seen since then) - [feel free to check out the piece here](/content/blog/from-opa-to-our-own-engine-cerbos ""/index.html)
👀 2
💪 2
cerbie 3
cerbos 2
👍 2
a
Anna Paykina
02/19/2025, 9:02 AM
Hey <!channel>!
We’ve gotten many questions from our community and customers about securing non-human identities. So we wanted to get into this topic in more detail 😊⬇️
Securing applications is not just about authorizing users based on their identity. Service-to-service calls, external API clients, AI agents, bots, and background jobs all act as independent workloads with their own identities, all requiring access to data and resources.
NHIs need to be authorized just like human users. Otherwise, these workloads can become security risks, leading to over-privileged services, unauthorized data exposure, and compliance violations.
Here you can learn how Cerbos can be used to secure NHIs 👉 [https://www.cerbos.dev/features-benefits-and-use-cases/authorization-non-human-identities](/content/features-benefits-and-use-cases/authorization-non-human-identities ""/index.html)
💪 3
🚀 5
🌟 4
cerbos 4
👍 2
🤖 2
💪🏻 1
💪🏼 1
👍🏼 1
a
Anna Paykina
02/21/2025, 7:12 AM
happy Friday, community! 🙂 We wanted to share our latest blog post with you.
We dove into the various certifications for enterprise architects, domain solutions architects, and software engineers, detailing their formats, prerequisites, and associated costs.
Although certification doesn’t replace experience - it can be a valuable addition to professional experience for architects. So if you’re interested - feel free to [check out the blog post here](/content/blog/certifications-for-enterprise-architects-domain-solutions-architects-software-engineers ""/index.html).
Some certifications we cover include: TOGAF 9, ITIL Master, Zachman Framework, AWS Certified Solutions Architect, Google Professional Cloud Architect, and others.
💡 3
🌟 1
😊 2
a
Anna Paykina
02/24/2025, 11:49 AM
Hey <!channel>!
In our latest blog, we dove into the topic of translating business requirements to authorization policy for HR 💡
Check it out if you’d like to understand the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible 👉 [https://www.cerbos.dev/blog/business-requirements-to-authorization-policy-in-hr-systems](/content/blog/business-requirements-to-authorization-policy-in-hr-systems ""/index.html)
🌟 2
cerbie 2
🙌 2
🙌🏼 1
a
Anna Paykina
02/26/2025, 8:18 AM
hey <!channel> 👋
We are happy to share that we’ve [introduced support](/content/blog/audit-logs-for-cerbos-hub-embedded-pdps ""/index.html) for capturing audit decision logs from the Cerbos Hub Embedded Policy Decision Points (ePDP) using the latest version of the Cerbos Javascript SDK 🌟 🎉
This feature enables organizations to track and analyze authorization decisions made locally in embedded environments, ensuring complete visibility and auditability, without relying on a centralized PDP or Cerbos Hub.
[Discover the details here](/content/blog/audit-logs-for-cerbos-hub-embedded-pdps ""/index.html)
🌟 3
🚀 3
👀 1
👍 2
a
Anna Paykina
03/04/2025, 12:56 PM
Hey community!
We’ve just published a blog post about authorization at the edge and it’s benefits • ✅ Faster response times • ✅ More reliable access control • ✅ Reduced load on central servers 👉 [Feel free to check it out here](/content/blog/edge-authorization ""/index.html) 👈
👍 1
💡 1
💫 1
GitHub
03/05/2025, 5:10 AM
Release - v0.41.0 New release published by github-actions[bot] Cerbos 0.41.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.41.0.html Changelog Features
• bfef008 feat(plan): Use scope value in the query plan ( #2485) • 9bec734 feat: Replace labels with deployments in bundle API v2 ( #2483)
Enhancements
• 71682d6 enhancement!: Switch to ContextEval to evaluate CEL expressions ( #2495) • 538ab24 enhancement: Correctly set GOMAXPROCS on ECS ( #2459) • 41787ba enhancement: Fail tests with unreachable output expectations ( #2418) • c2f16ff enhancement: Lazy rule table ( #2460) • 131bf5f enhancement: Rule table engine ( #2442) • ecf08cc enhancement: Support bundlev2 ( #2395)
Bug fixes
• 038719b fix: Add missing policy required for mutable e2e tests ( #2502) • bd3222d fix: Correctly handle defaultPolicyVersion engine config ( #2449) • 8983b99 fix: Correctly handle partial rule table and event subscription ( #2455) • a676fd1 fix: Fall back to default policy version sooner in query planner ( #2450) • 0b80bcb fix: Reload rule table when store contents change ( #2452) • f611ff2 fix: Return validation errors and effective policies in query planner responses ( #2447) • a12fd5c fix: Rule table reload should only purge ( #2467) • 3596a31 fix: Use correct filterDebug type in e2e query planner test ( #2448)
Documentation
• 73b40e4 docs: Correct examples for math functions ( #2445) • 9096ecb docs: Scope permissions ( #2487) • 1fd792d docs: Update 03_calling-cerbos.adoc of tutorial to use the updated
/api/check/resources
endpoint ( #2429) • 4eb7b26 docs: Update what-is-cerbos.adoc tenant ->tenet ( #2406)
Chores
• 282fe32 chore!: REQUIRE_PARENTAL_CONSENT refinements for resource and principal policies ( #2484) • 31e635e chore!: Role policy deny rows ( #2475) • 24551ba chore(deps): Bump filippo.io/age from 1.2.0 to 1.2.1 ( #2423) • 7a81126 chore(deps): Bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 in /tools ( #2491) • 39242a6 chore(deps): Bump github.com/quic-go/quic-go from 0.48.1 to 0.48.2 in /tools ( #2405) • 3792699 chore(deps): Bump golang.org/x/crypto from 0.29.0 to 0.31.0 in /tools ( #2414) • c03afd6 chore(deps): Remove SQL Server dependencies ( #2394) • 09806c6 chore(deps): Update alecthomas/kong to v1.5.1 ( #2404) • e11f815 chore(deps): Update dawidd6/action-download-artifact action to v7 ( #2417) • 5571a2c chore(deps): Update dependency node to v22.13.0 ( #2444) • 4eda1c7 chore(deps): Update github actions deps ( #2427) • 55dc0c8 chore(deps): Update github actions deps ( #2464) • d6818fa chore(deps): Update github.com/bufbuild/protovalidate-go to 0.8.0 ( #2428) • d0c26dd chore(deps): Update github.com/go-git/go-git/v5 ( #2437) • aa9a573 chore(deps): Update go deps ( #2397) • 915609b chore(deps): Update go deps ( #2407) • 8b6d25e chore(deps): Update go deps ( #2415) • 2660e5e chore(deps): Update go deps ( #2431) • <https://github.com/cerbos/cerbos/c… cerbos/cerbos
🎉 6
a
Anna Paykina
03/17/2025, 9:59 AM
Hey, <!channel>, happy Monday!
🚀 We wanted to share about our latest update - Cerbos Prisma Integration v2.0
With our latest update to the reference Prisma Query Plan Adapter, we’ve significantly expanded its capabilities, making it even easier to enforce fine-grained access control within applications using Prisma ORM. Updates include:
• Expanded operator support • Deep nested relations • Automatic field inference and type-safe mapping • Improved collection handling • Performance optimizations 👉 [Check out the full blog post for more details & info on how to get started](/content/blog/cerbos-prisma-integration-v2-0 ""/index.html) 👈
🙌 3
🙌🏼 1
a
Anna Paykina
03/21/2025, 11:36 AM
Hey <!channel> ! 👋
🎥 We will be hosting a webinar “Cloud, SaaS, or self-hosted? Which authentication & authorization deployment model is right for you?”
Join to learn about: • Security & compliance trade-offs across deployment models • Engineering implications from performance to integration complexity • Hidden costs & operational risks you might not expect • How to future-proof your auth stack for scalability & reliability
📅 April 17, 2025 | 5pm CET / 9am PST (recording will be available to all registrants)
🎙️ Speakers: Dan Moore, Principal Product Engineer at FusionAuth & Alex Olivier, CPO at Cerbos
👉 [register here](/content/ebooks-webinars/choosing-the-right-authentication-and-authorization-deployment ""/index.html) 👈 see you there! ☺️
cerbie 5
🚀 3
🎉 4
👍 3
👍🏼 1
a
Anna Paykina
03/24/2025, 9:07 AM
Hey everyone! 😊
Non-human identities now outnumber human users by 17:1, yet they are one of the most overlooked attack vectors in today’s systems.
Which is why we published a new blog post breaking down the OWASP Top 10 threats to non-human identities (NHIs). We explain what each threat is, real-world examples of breaches, and practical steps to mitigate them. Plus, we show how Cerbos helps enforce least privilege and context-aware access control for NHIs.
[Feel free to check it out here](/content/blog/securing-non-human-identities-understanding-and-addressing-owasp-top-10-threats ""/index.html)
🌟 1
💡 1
cerbie 1
👍 1
a
Anna Paykina
03/25/2025, 9:47 AM
Hey <!channel>!
We’ve published a blog post where we examine the key elements of compliance that should be prioritized, from data quality and change management to audit logs and access control. We also explore how picking the right authorization system can strengthen your compliance efforts. [Feel free to check it out here](/content/blog/staying-compliant ""/index.html)
💡 A study by the Ponemon Institute found that, on average, non-compliance costs companies about 2.7 times more than meeting compliance requirements in the first place.
👍 2
🙌 1
💡 2
👍🏼 1
🙌🏼 1
GitHub
03/26/2025, 4:12 AM
Release - v0.42.0 New release published by github-actions[bot] ## Cerbos 0.42.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.42.0.html
## Changelog
### Features
• e3aef93 feat: SPIFFE functions ( #2524)
### Enhancements
• 36c7625 enhancement: Stop logging attribute values as JSON-encoded strings in decision logs ( #2516)
### Bug fixes
• 8cbeca7 fix: Ensure derived role updates purge rule table caches ( #2523) • 4449609 fix: Evaluate condition blocks correctly in REPL ( #2513) • f1fc31d fix: Purge schema cache on store reload ( #2522) • e4da017 fix: Tidy up rule table trace outputs ( #2531)
### Documentation
• 970f7fd docs: Remove symlink to SQL Server schema ( #2505)
### Chores
• b7fa780 chore(deps): Bump github.com/containerd/containerd from 1.7.25 to 1.7.27 in /tools ( #2520) • 2658904 chore(deps): Bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 in /tools ( #2527) • ed471a3 chore(deps): Bump github.com/golang-jwt/jwt/v5 from 5.2.1 to 5.2.2 in /tools ( #2526) • 92b5da4 chore(deps): Bump github.com/redis/go-redis/v9 from 9.7.0 to 9.7.3 ( #2525) • b89d3c4 chore(deps): Bump golang.org/x/net from 0.35.0 to 0.36.0 in /api/genpb ( #2514) • 9bff439 chore(deps): Bump golang.org/x/net from 0.35.0 to 0.36.0 in /tools ( #2509) • fc62644 chore(deps): Update go deps ( #2507) • 5c2b5bd chore(deps): Update golangci/golangci-lint-action action to v6.5.1 ( #2517) • e682aeb chore(deps): Update golangci/golangci-lint-action action to v6.5.2 ( #2528) • 0276262 chore(deps): Update node.js deps ( #2508) • 25b8f18 chore(deps): Update pnpm to v10.6.3 ( #2518) • ed90ba0 chore(deps): Update pnpm to v10.6.5 ( #2529) • 5d3167a chore(planner): Switch from CEL protobuf to native types ( #2492) • 4e6d19b chore(release): Add 0.42.0 release notes ( #2532) • 1a5b7c2 chore(release): Prepare release 0.42.0 • bd70cea chore(version): Bump version to 0.42.0 • fa4ac36 chore: Add gopls's modernizer to linters ( #2515) • ba15837 chore: Handle empty policies in the parser ( #2530) • 8247248 chore: Handle kind ROLE in trace printer ( #2511) cerbos/cerbos
a
Anna Paykina
03/31/2025, 11:32 AM
Happy Monday, community! 😊 We’re heading KubeCon 2025 in London!
If you will be there - come meet the Cerbos team at 🔺Booth S632🔺 Daniel Maher, Emre Baran, Alex Olivier, and Andrew Haines are looking forward to chatting with you about all things authorization!
📢 Don’t miss Dan’s talk “ AuthZ as a Dev Workflow: Architecting Better Cloud Native Apps” Friday April 4, 2025 15:15 - 15:45 BST Level 1 | Hall Entrance S10 | Room C
🎁 And while you’re at it, feel free to participate in our collab raffle with FusionAuth for a chance to win a TIE Interceptor or X-Wing Starfighter.
See you there!
🌍 2
cerbie 2
🏆 1
a
Anna Paykina
04/03/2025, 10:23 AM
hey <!channel>!
🚀 We’re happy to share that [Cerbos PDP now supports native parsing of SPIFFE identities in authorization policies](/content/blog/spiffe-identity-parsing-cerbos-pdp ""/index.html)!
This unlocks precise access control for authorizing calls based on non-human identities using the framework be it services, workloads, or any other compute job.
This feature introduces a set of Cerbos-specific extensions to the Common Expression Language (CEL) used in policy conditions which understand the structure of a SPIFFE ID such as trust domains, path components, or target the full identity string.
🙌 1
cerbos 4
👏 2
🚀 1
🙌🏼 1
👏🏼 1
🤖 1
GitHub
04/07/2025, 8:01 AM
Release - v0.43.0 New release published by github-actions[bot] ## Cerbos 0.43.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.43.0.html
## Changelog
### Bug fixes
• ff7c199 fix: Maintain derived role mappings during policy updates ( #2536) • 03982ea fix: Purge rule table on index build failure ( #2538)
### Chores
• dba785d chore(ci): Make Coveralls upload optional ( #2541) • c1238e0 chore(deps): Update go deps ( #2534) • b0c542e chore(deps): Update go deps ( #2540) • b074c8f chore(deps): update node.js deps ( #2535) • 170a7e8 chore(release): Add 0.43.0 release notes ( #2542) • 69f4f15 chore(release): Prepare release 0.43.0 • c56621c chore(version): Bump version to 0.43.0 • 4ae6dac chore: Change logger keys based on bundle version ( #2533) cerbos/cerbos
a
Anna Paykina
04/10/2025, 7:04 AM
Hey community! 😊
As you might have already seen - we’ve introduced several updates that bring new capabilities and improvements to Cerbos 🙌
With v0.42 and v0.43, we’ve added support for SPIFFE identities in policies, improved the structure of audit logs, and tightened the reliability of policy updates in live environments.
[Details can be found here](/content/blog/cerbos-pdp-v0-42-and-v0-43-spiffe-identity-support-smarter-logging ""/index.html)
💪🏼 1
👍🏼 1
👍 3
cerbie 4
💪 1
a
Anna Paykina
04/22/2025, 5:31 AM
Thanks to everyone who joined our webinar on “Choosing the Right Authentication & Authorization Deployment Model” 🥳
📩 If you missed the live session, you can get the full recording by [submitting the form here](/content/ebooks-webinars/choosing-the-right-authentication-and-authorization-deployment ""/index.html). The recording will be sent directly to your email.
During the webinar: 👉 Dan Moore FusionAuth and Alex Olivier Cerbos compared self-hosted, cloud-hosted, and SaaS authentication solutions, examining their impact on security, compliance, and operational control 👉 Explored how to align deployment choices with your regulatory requirements and data governance needs 👉 Examined performance implications, integration challenges, and compatibility with teams’ technical roadmaps 👉 Covered operational risks including reliability, disaster recovery, and vendor lock-in—plus how to mitigate them 👉 Broke down the total cost of ownership, CapEx vs. OpEx considerations, and potential hidden costs
More webinars coming very soon!
cerbie 1
🙌 1
🎥 1
a
Anna Paykina
04/25/2025, 5:49 AM
Hey everyone! Happy Friday! 😊
🎉 We’re excited to share some big news: [Cerbos has been named Startup of the Year 2024 in Access Control by HackerNoon](/content/news/cerbos-startup-of-the-year-in-access-control-hackernoon ""/index.html). This recognition comes after a competitive vote involving 32 companies in our category and nearly 700 community votes.
This isn’t just a win for Cerbos—it’s a signal that the tech community is paying serious attention to the problem of authorization.
We wouldn’t be here without your support ☺️_. Whether you voted, contributed to the open-source project, deployed Cerbos in production, or just explored what we’re doing—thank you._ This win is a shared one. Onward 🚀
cerbie 5
🌟 2
🚀 3
🏆 4
🙌 2
a
Anna Paykina
04/28/2025, 12:06 PM
Hey <!channel>! 👋
We would like to invite you to join our upcoming webinar on “Mastering authorization in Fintech” 💻
Edgar Rivera and Daniel "phrawzty" Maher will walk through how to map business requirements of fintech products to authorization logic, accounting for dynamic trading rules, global market windows, and real-time risk assessment. Then they’ll show how to manage that complexity without cluttering your codebase or making things harder to maintain.
⏰ May 6, 2025 at 5pm CEST / 8am PDT 🔗 👉 [Register](/content/ebooks-webinars/mastering-authorization-in-fintech ""/index.html) [for the webinar](/content/ebooks-webinars/mastering-authorization-in-fintech ""/index.html) [here](/content/ebooks-webinars/mastering-authorization-in-fintech ""/index.html) 📩 Recording available for all registrants
cerbie 4
👍 1
🌟 2
👍🏼 1
a
d
- 3
- 7
a
Anna Paykina
05/28/2025, 12:09 PM
Hey, community! 😊
Multi-tenancy in SaaS applications presents a critical challenge: ensuring robust access control that isolates tenant data and operations while maintaining flexibility and scalability.
🚀 We’ve released some new features, which provide a powerful toolkit to define and enforce multi-tenant security effectively. Feel free to check out our [blog post on the topic for more details](/content/blog/multi-tenant-saas-authorization-role-policies-and-scoped-resource-policies ""/index.html). In it, we: • Go through key Cerbos concepts: Scopes, role policies, and scoped resource policies with scope permission modes. • Demonstrate how these features combine to address the multi-tenant access control problem. • Provide practical policy examples for a hypothetical SaaS HR platform.
🚀 2
💪 2
cerbie 2
a
Anna Paykina
05/30/2025, 5:42 AM
Hey everyone, happy Friday! ☺️
We’re excited to share our latest success story with you all: “ [How Cerbos gave Utility Warehouse control over 4,500 services and millions of NHIs](/content/customers/utility-warehouse/non-human-identities ""/index.html)”
Utility Warehouse, a FTSE 250 company, faced a growing challenge common in modern infrastructures: managing and securing Non-Human Identities across a vast network of over 4,500 services. As systems scale, NHIs like service accounts and workloads identities can proliferate, leading to overprivileged access and reduced visibility if not properly controlled.
By implementing Cerbos, Utility Warehouse transitioned to a true Zero Trust architecture, achieving: 🔹 𝐆𝐫𝐚𝐧𝐮𝐥𝐚𝐫 𝐍𝐇𝐈 𝐚𝐜𝐜𝐞𝐬𝐬 𝐜𝐨𝐧𝐭𝐫𝐨𝐥. Securing access at every hop within their service mesh, moving beyond perimeter-only trust. 🔹 𝐄𝐧𝐝-𝐭𝐨-𝐞𝐧𝐝 𝐢𝐝𝐞𝐧𝐭𝐢𝐭𝐲 𝐩𝐫𝐨𝐩𝐚𝐠𝐚𝐭𝐢𝐨𝐧. Ensuring user identity and intent are maintained throughout the service chain for full-context authorization. 🔹 𝐒𝐜𝐚𝐥𝐚𝐛𝐥𝐞 & 𝐬𝐭𝐚𝐭𝐞𝐥𝐞𝐬𝐬 𝐩𝐨𝐥𝐢𝐜𝐢𝐞𝐬. Efficiently managing millions of authorization decisions daily across their extensive service landscape. 🔹 𝐂𝐨𝐦𝐩𝐫𝐞𝐡𝐞𝐧𝐬𝐢𝐯𝐞 𝐚𝐮𝐝𝐢𝐭 & 𝐨𝐛𝐬𝐞𝐫𝐯𝐚𝐛𝐢𝐥𝐢𝐭𝐲. Leveraging integrated audit logging for enhanced threat detection and compliance.
This strategic implementation not only bolstered their security posture but also streamlined operations, reclaiming significant development time.
Kudos Rob Crowe and the Utility Warehouse team for their forward-thinking approach to securing NHIs at scale!
👍 2
🌟 2
🚀 3
🙌 2
GitHub
06/03/2025, 2:39 AM
Release - v0.44.0 New release published by github-actions[bot] ## Cerbos 0.44.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.44.0.html
## Changelog
### Features
• b383622 feat(audit): Add size-based batch limiting to audit log hub ( #2558) • 350d52c feat(plan): Add support for multiple actions ( #2543) • ff44bd4 feat: Add principal policy support to rule table ( #2544) • 44e21fb feat: Cerbosctl commands to interact with Hub store ( #2569)
### Enhancements
• 666976c enhancement!: Remove bundle version configuration parameter ( #2583) • 386230a enhancement(helm): Update helm charts to support bundle v2 ( #2580) • a2b376b enhancement: Simplify plan with exists operation ( #2570)
### Bug fixes
• 42fd48b fix(helm): Set correct environment variable to configure traces sampler ( #2551) • 86428c7 fix(plan): Preserve action field for auditing ( #2564) • 861bb1d fix: Return appropriate backoff in logcap ingest error path ( #2549)
### Documentation
• 314535a docs: Add talk to engineer link ( #2573)
### Chores
• 380d8f6 chore(ci): Don't bother caching dependencies for
upload-test-times
job ( #2557) • d4e6db6 chore(ci): Upgrade Helm and Helmfile ( #2586) • 73d0e25 chore(deps)!: Update module github.com/cenkalti/backoff/v4 to v5 ( #2555) • db07dcb chore(deps): Bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 ( #2563) • aedf313 chore(deps): Bump golang.org/x/net from 0.37.0 to 0.38.0 in /api/genpb ( #2559) • e5ad74e chore(deps): Bump helm.sh/helm/v3 from 3.16.4 to 3.17.3 in /tools ( #2545) • 1e6d83c chore(deps): Update dawidd6/action-download-artifact action to v10 ( #2585) • 61ba507 chore(deps): Update dawidd6/action-download-artifact action to v9 ( #2548) • 39c082b chore(deps): Update extractions/setup-just action to v3 ( #2552) • 44b2b26 chore(deps): Update go deps ( #2547) • 97f9326 chore(deps): Update go deps ( #2565) • b04997c chore(deps): Update go deps ( #2571) • e7cbf2d chore(deps): Update go deps ( #2576) • 1fa3df6 chore(deps): Update go deps ( #2581) • 672f97e chore(deps): Update go deps ( #2584) • 53314ec chore(deps): Update golangci/golangci-lint-action action to v7.0.1 ( #2566) • efca0ba chore(deps): Update module helm.sh/helm/v3 to v3.17.3 [security] ( #2546) • 537dc04 chore(deps): Update modules github.com/lestrrat-go/jwx and github.com/vektra/mockery to v3 (major) ( #2553) • 0e39c79 chore(deps): Update node.js deps ( #2562) • 5e2be4d chore(deps): Update node.js deps ( #2575) • d89540e chore(deps): Update node.js deps ( #2582) • 293307a chore(deps): Update pnpm to v10.10.0 ( #2572) • e657267 chore(deps): Update sigstore/cosign-installer action to v3.8.2 ( #2561) • 4b7b60c chore(deps): update go deps ( #2560) • ccf551a chore(deps): update module github.com/golangci/golangci-lint to v2 ( #2556) • c35ae86 chore(deps): update node.js deps ( #2539) • 9508a38 chore(docs): Fix how less than or equal operator is displayed (<https://github.com/cerbos… cerbos/cerbos
a
Anna Paykina
06/05/2025, 10:26 AM
Hey, <!channel>! 🎉 📖 We’re excited to share our new ebook “Securing Non-Human Identities in enterprise systems”
This ebook breaks down: • NHI taxonomy • 20 NHI and AI agent risk vectors you need to know • 12 security principles and 35 actionable steps for NHI governance • Insights from NHI breaches (Okta, GitHub, and Microsoft) • Expert opinions from CISOs, security architects, and EMs working on IAM programs that include NHI security • A vendor landscape and evaluation checklist to guide your implementation strategy
It’s actionable and built from real-world experience, designed to help IAM teams address the blind spots, over-permissioning, and security gaps that often come with AI agents, microservices, and automated workloads.
Feel free to read the ebook and let us know what you think!
🌟 1
📚 3
🙌 3
👍 2
a
Anna Paykina
06/06/2025, 7:32 AM
Happy Friday, community 😊
We wanted to share our case study with BarrierSystems with you! [“BarrierSystems integrates Cerbos into smart vehicle access gates, cutting internal costs by 15%”](/content/customers/barriersystems ""/index.html)
The company used Cerbos to externalize authorization for easier policy management. As a result, they were able to: • Improve user experience, with a 15% decrease in customer issues • Simplify their own policy management workflows to enable consistent and reliable access control for their customers • Decrease associated internal costs by 15% as a result • Ship new features faster
🌟 3
🚀 3
👏 2
cerbie 2
🙌 3
🧠 3
GitHub
06/16/2025, 10:09 AM
Release - v0.45.0 New release published by github-actions[bot] ## Cerbos 0.45.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.45.0.html
## Changelog
### Bug fixes
• 07adb2b fix: Handle multi-role planner precedence correctly ( #2592) • adf9207 fix: Honour compile cache duration in rule table ( #2602) • 1fd9668 fix: Protect against wildcards in policy names ( #2593)
### Chores
• 7fa8846 chore(ci): Remove deprecated
buf
actions ( #2604) • 201601e chore(deps): Bump brace-expansion from 2.0.1 to 2.0.2 in /npm/test/registry ( #2597) • abd1192 chore(deps): Update cerbos-sdk-go to 0.3.4 ( #2606) • cbd9efd chore(deps): Update cerbos-sdk-go to v0.3.2 ( #2589) • f5d113e chore(docs): Fix mistake related to compile.cacheSize configuration parameter ( #2598) • 2a65d5b chore(release): Add 0.45.0 release notes ( #2605) • eb97869 chore(release): Prepare release 0.45.0 • 6af3f42 chore(tracing): Fix names of tracing spans in engine ( #2603) • ee97a59 chore(version): Bump version to 0.45.0 • 9e24d95 chore: More ASCII character class replacements ( #2596) • 70c77ab chore: Replace ASCII character classes in validation regexes ( #2595) cerbos/cerbos
a
Anna Paykina
06/18/2025, 10:21 AM
Hey <!channel>!
We wanted to share our latest blog with you, in which we explore two approaches to implementing 💡 hierarchy-based permissions in Cerbos, inspired by a real-world use case for a data analytics platform. Both methods leverage ABAC, but differ in their implementation strategy:
1️⃣ Policy-defined roles with attribute-based conditions. Defining explicit role policies for each tenant where hierarchical logic is hardcoded inside the policy. 2️⃣ Dynamic, attribute-driven generic policies. Shifting the hierarchical conditions entirely to the principal’s attributes and using a single, generic policy for interpretation.
[Feel free to check out the details here](/content/blog/mastering-hierarchy-based-permissions-with-cerbos-policy-defined-roles-vs-dynamic-attributes ""/index.html)
👍 1
🧠 1
GitHub
06/30/2025, 7:22 AM
Release - v0.45.1 New release published by github-actions[bot] ## Cerbos 0.45.1
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.45.1.html
## Changelog
### Bug fixes
• 6808dae fix: Don't set bundleVersion when auto-configuring hub ( #2608)
### Documentation
• a4f2eea docs: Generate llm.txt and llm-full.txt ( #2609)
### Chores
• b0cc825 chore(ci): Fix
buf push
step ( #2610) • 70766ee chore(deps): Bump github.com/go-chi/chi/v5 from 5.2.1 to 5.2.2 in /tools ( #2611) • 549e877 chore(deps): Bump github.com/go-viper/mapstructure/v2 from 2.1.0 to 2.3.0 ( #2618) • 7893eaf chore(deps): Update go deps ( #2612) • 46458b5 chore(deps): Update go deps ( #2619) • 3de8602 chore(deps): Update node.js deps ( #2613) • 05e9783 chore(deps): Update node.js deps ( #2620) • 6194038 chore(release): Add 0.45.1 release notes ( #2621) • 47732be chore(release): Prepare release 0.45.1 • d9f01f8 chore(version): Bump version to 0.46.0 • 98d3145 chore: Pluggable schema resolver ( #2614) cerbos/cerbos
🔧 1
a
Anna Paykina
07/02/2025, 7:10 AM
hey <!channel>! 🙂
MCP servers are reshaping how AI agents interact with external tools and APIs.
They unlock speed and flexibility, but can also punch holes in your security model if every agent can call every tool by default.
Which why we are excited to share our [guide on implementing dynamic authorization for AI agents and fine-grained permissions in MCP servers](/content/blog/dynamic-authorization-for-ai-agents-guide-to-fine-grained-permissions-mcp-servers ""/index.html) (and it doesn’t require a backend rewrite 😊).
cerbie 4
👍 5
💡 4
a
Anna Paykina
07/08/2025, 9:07 AM
Hello, <!channel> !
We’re excited to share our latest ebook with you: 📘 The “How to adopt externalized authorization: Planning your path”!
Over the years, we’ve worked with hundreds of engineering, IAM, and security teams - helping everyone from early-stage startups to global enterprises navigate the process of adopting externalized authorization.
That experience became the foundation for our new ebook. It’s a hands-on, 10-chapter guide that walks through every stage of the journey, from foundational planning to externalized authorization rollout and long-term governance.
If you’re interested, feel free to download it here. Let us know what you think once you have a chance to read it! 🙌
🌟 5
🎉 4
cerbie 4
📚 4
a
Anna Paykina
07/15/2025, 2:03 PM
Hey, <!channel> 👋
Exciting news - Cerbos documentation is now LLM optimized!
Use your favorite AI assistant to help build Cerbos policies and integrations.
[Check out the details here.](/content/blog/llm-understanding-of-cerbos-documentation ""/index.html)
🙌 3
cerbie 5
🤖 8
cerbos 3
🙌🏼 1
a
Anna Paykina
07/17/2025, 11:10 AM
Hey <!channel>! We have a really big update today 😊
We’re very excited to share that we have 🚀🎉 just released the [updated Cerbos Hub](/content/blog/four-new-use-cases-in-updated-cerbos-hub ""/index.html)! Cerbos Hub is now the centralized control plane for every authorization decision across applications, AI agents, services, and workloads.
All identities. Any architecture at any scale. All in one place.
This update is the result of your feedback. Over the past year, hundreds of engineering and security teams shared their challenges, and this input shaped four powerful new use cases: 1. Fine-grained, tenant specific authorization 2. Dynamic policy management at scale 3. Scalable NHI permission management 4. Secure authorization for MCP servers This latest update brings new features across the entire authorization lifecycle. So now you can: • Create, update, and deploy policies programmatically • Scale your policies by tenant, team, environment, or use case with the new Policy Stores • Push and deploy policy updates from any Git provider, CI tool, or API, with real-time distribution and built-in testing • Get a complete audit trail of every access decision across all identities, tenants, and apps • [And much more](/content/blog/updated-cerbos-hub-complete-authorization-solution-for-your-identity-fabric ""/index.html)! If you haven’t tried Cerbos Hub yet, and you’re looking to manage authorization for every identity in your system with full visibility, consistent policy enforcement, and Zero Trust alignment - this is the time to check it out 🙂
We’re happy to walk you through the new features and explore how they can meet your requirements. Our engineer and Head of Product are happy [to talk with you](/content/workshop ""/index.html)!
🌟 6
cerbie 7
🙌 6
💫 5
🙌🏻 1
🚀 9
💥 3
a
Anna Paykina
07/18/2025, 10:51 AM
Happy Friday, community! We’re back with some more fun news! 😊
We are excited to share that Cerbos Hub has been named [Best in Microservices Infrastructure at the 2025 API Awards](/content/news/cerbos-2025-api-award-best-in-microservices-infrastructure ""/index.html)! 🥇
Thank you for your continued support, and for being on this journey with us!
🌟 2
🥇 1
🚀 3
👏 2
🏆 2
l
Lisa Dziuba
07/22/2025, 10:34 AM
Hello, our awesome community! Do you want to learn best practices for multi-tenant authorization? Join our spotlight webinar on Jul 29 to see how to model and manage per-tenant access policies.
Together with our CPO, @Alex Olivier (Cerbos), we’ll cover:
• Real-world implementation examples • How to build tenant-specific Policy Stores with isolation and traceability • The architecture needed to scale per-tenant authorization • Supporting enterprise customers with custom roles and dynamic logic • Live demo of policy creation, deployment, and updates via API and Git
Register here → https://zoom.us/webinar/register/WN_-U732lkoQLOdaCCyasJ_ag%20#/registration
cerbie 1
👀 1
🎉 1
a
Anna Paykina
07/31/2025, 9:48 AM
Hey everyone 👋 We wanted to let you know about our next upcoming webinar, where we will dive into programmatic policy management for complex systems.
We’ve heard from a number of you about issues with scaling manual permission updates. As your system grows with more tenants, services, and agents, keeping access control up to date gets messy.
If you’d like to learn how to manage permission updates with code, join us on August 6. We’ll go through: • When to use programmatic updates (and when not to) • Static vs. dynamic policy models • Managing policies via CLI, API, and SDKs • Deploying from Git, CI, or external systems • Architectures for scaling real-time policy updates • Live demo: building dynamic policies and integrating with your systems
You can register here ➡️ https://zoom.us/webinar/register/5317539696581/WN_SOGae5oqTSaJu28uiogCqA
💡 2
cerbie 2
👍 2
🚀 2
GitHub
08/01/2025, 2:13 AM
Release - v0.46.0 New release published by github-actions[bot] ## Cerbos 0.46.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.46.0.html
## Changelog
### Features
• 6cff78d feat: Include policy source in audit logs ( #2624)
### Enhancements
• e73ec4c enhancement: Add embedded PDP metadata to audit logs ( #2625) • 8b4cbe3 enhancement: Stickier PDP IDs ( #2641)
### Bug fixes
• 8184fdf fix: Handle const false DENY nodes in role-level query planning ( #2644) • 3b2f73c fix: Handle rule-less policies for multi-tenant fallthrough ( #2649)
### Documentation
• ede245a docs: Fix css for logo on hover ( #2628)
### Chores
• 3531121 chore(ci): Set MySQL tag ( #2647) • 084ad71 chore(ci): Temporarily disable MySQL E2E tests ( #2650) • 445ca4e chore(ci): Use official MySQL image in E2E tests ( #2646) • 616d48d chore(deps): Bump form-data from 4.0.2 to 4.0.4 in /npm/test/registry ( #2654) • e12847a chore(deps): Bump github.com/docker/docker from 28.2.2+incompatible to 28.3.3+incompatible in /tools ( #2655) • 15b5edf chore(deps): Bump helm.sh/helm/v3 from 3.17.3 to 3.18.4 in /tools ( #2632) • 664315c chore(deps): Update github actions deps ( #2642) • 149a57d chore(deps): Update go deps ( #2626) • 4abe304 chore(deps): Update go deps ( #2635) • 4803489 chore(deps): Update go deps ( #2643) • ded17ae chore(deps): Update go deps ( #2651) • 8629867 chore(deps): Update node.js deps ( #2652) • 3b6b8d3 chore(deps): Update pnpm to v10.13.1 ( #2636) • 1b3690b chore(deps): Update sigstore/cosign-installer action to v3.9.1 ( #2627) • 1a130aa chore(deps): update module helm.sh/helm/v3 to v3.18.4 [security] ( #2633) • 031a3c5 chore(release): Add 0.46.0 release notes ( #2657) • 2e55b6b chore(release): Prepare release 0.46.0 • 17d8000 chore(version): Bump version to 0.46.0 • 17e74dc chore: Enable gzip and increase response size limit for cerbosctl ( #2631) • 4b09afc chore: Rename cerbosctl hub
like
filter to
contains
( #2623) • e8e7a86 chore: Use new Bitnami repository ( #2640) cerbos/cerbos
🚀 4
a
Anna Paykina
08/04/2025, 12:07 PM
hey <!channel>! 👋 We have launched the new Usage Dashboard in Cerbos Hub! 🙌
This new feature provides a comprehensive, real-time view of your authorization service, allowing you to monitor key metrics, analyze trends, and gain valuable insights into your policies and their consumers.
The new usage insights, available on both the workspace homepage and its own dedicated “Usage” section, surface these key metrics into a quick reference dashboard. It provides a detailed breakdown of your Monthly Active Principals (MAPs), decisions, query plans, and more, allowing you to see exactly how your authorization policies are being used.
[Details can be found here](/content/blog/cerbos-hub-usage-dashboard ""/index.html).
🙌 4
👀 4
🙌🏻 1
💡 1
🎉 1
a
Anna Paykina
08/07/2025, 7:00 AM
Hey community! 🔥 During these hot summer days, we’re diving into an even hotter topic: securing MCP servers.
If your AI agents are getting smarter and gaining access to tools, APIs, and sensitive systems via the Model Context Protocol, you already know the risks aren’t just theoretical.
Join our free MCP security webinar on August 14: https://zoom.us/webinar/register/3017545640027/WN_lefbNhY7RmimAflP7xbTzg
Can’t make it live? No worries - we’ll share the recording afterward.
Check out the preview video below where Alex Olivier (our CPO & Co-Founder) gives you a taste of what we’ll cover! 👇
MCP server security webinar.mp4
cerbie 1
🙌 1
💡 1
👍 1
l
Lisa Dziuba
08/18/2025, 12:13 PM
🎉 We just passed 4,000 stars on GitHub. A huge thank you to our amazing community for the support! Who wants to give us star number 4001? 😉
🌟 9
✨ 3
a
Anna Paykina
08/20/2025, 8:09 AM
Hey <!channel>! 👋 Our next webinar is diving deep into non-human identity authorization on August 26th.
Most teams have Zero Trust figured out for humans. But their service accounts, API keys, workload identities and agents? Still getting broad permissions.
The reality is that Zero Trust architecture is only as strong as how teams handle these machine identities.
We’ll start the webinar with the fundamentals (NHI types, common risks) then get into the architecture patterns you need for proper Zero Trust, and fine-grained, method-level authorization
What we’re covering: • NHI fundamentals and risks • 5 common authentication methods for NHIs • Zero Trust principles applied to NHIs • Fine-grained, method-level authorization for workloads and agents • Delegated authorization and on-behalf-of identity handling • How to unify policies and audits across the stack • We’ll also touch briefly on broader NHI security strategies beyond authorization.
*Register:* https://zoom.us/webinar/register/4117556840966/WN_OHDM3rveSZ-pBD5ApU6gsw Can’t make it live? No worries - register anyway and you’ll get the recording.
Looking forward to seeing some familiar faces there! 🚀
🤖 4
👍 3
💡 2
👍🏼 1
a
Anna Paykina
09/05/2025, 11:18 AM
Happy Friday, community 😊 Excited to share that we have just shipped some new features!
Both came directly from customer feedback about debugging and monitoring: 1️⃣ Understanding why specific authorization decisions were made 2️⃣ Getting visibility into usage patterns across multiple teams.
[Details can be found here](/content/blog/trace-authorization-decisions-and-track-usage-patterns ""/index.html) If you’re already using Cerbos Hub, head to the playground to try execution traces or check your dashboard for the new organization view. If you’re not using Cerbos Hub yet, you can sign up for free and see both features in action with your own policies.
🧡 1
👍 1
cerbie 1
👀 1
a
Anna Paykina
09/15/2025, 6:56 AM
Hey everyone, hope your week is off to a good start!
We just published a technical guide on [making application authorization context-aware with Cerbos outputs](/content/blog/making-application-authorization-context-aware-cerbos-outputs ""/index.html) 📃
If you’ve ever had users confused by cryptic “access denied” messages, or struggled with audit trails that only tell you what happened but not why - this guide could be relevant for you.
Cerbos outputs solve the above by providing contextual metadata that transforms binary allow/deny decisions into intelligent, actionable authorization responses.
👍 2
cerbos 2
🙌 1
a
Anna Paykina
09/22/2025, 6:59 AM
Happy Monday, community 😊 We just published a guide on [how to write schemas](/content/blog/making-cerbos-policies-bulletproof-with-schemas ""/index.html).
Why care about schemas? Well, when you write Cerbos policies, you’re essentially making assumptions about the shape of data your application will send. Without schemas, those assumptions are just that: assumptions. Your policies become a house of cards waiting for the wrong payload to knock everything down.
With schemas in place: • You can catch integration errors during testing, not in production; • Get documentation that can’t lie; • And prevent attribute injection attacks. Feel free to check the blog out, if it’s relevant for you. Have a great week!
🙌 1
👀 1
a
Anna Paykina
09/25/2025, 1:41 PM
👋 Some of you have asked how to filter database results.
So we put together a detailed guide answering that question, the focus of which is the PlanResources API.
[You can check it out here](/content/blog/filtering-database-results-with-cerbos-query-plans ""/index.html).
👍 3
💡 1
a
Anna Paykina
09/26/2025, 3:52 AM
Hey, <!channel>!
After seeing so many of you registered for our MCP webinar (seriously, the response was amazing!), we knew there was a real appetite for diving deeper into MCP security.
So, our co-founder Emre wrote a comprehensive ebook “*Zero Trust for AI: Securing MCP Servers*” covering what we couldn’t fit into the webinar: • Why MCP servers are becoming high-privilege security risks • How traditional RBAC fails in AI environments • The PEP/PDP architecture for Zero Trust AI systems • Ready-to-implement authorization policies and deployment patterns The guide draws from our work with customers implementing AI systems and covers real incidents like the recent Supabase and Asana vulnerabilities.
Thanks for all the great questions during the webinar - they influenced what went into this guide. Hope you find it helpful for your MCP implementations!
:books:Get access to the ebook here
📖 4
👍 3
🎉 5
✨ 3
cerbie 1
a
Anna Paykina
10/13/2025, 8:37 AM
Hey everyone! Some more news on the topic of MCP to start off the week 😊 We are excited to share that 🤖 we have introduced cerbos-fastmcp middleware.
FastMCP is a popular Python framework for building production-ready Model Context Protocol servers. However, a default FastMCP implementation exposes all tools to all users, creating a significant security risk.
The introduced middleware brings policy-based, fine-grained access control to FastMCP deployments. This allows teams to define authorization rules in human-readable YAML policies, completely decoupled from application code.
Check out this blog for the details and a demo: [https://www.cerbos.dev/blog/how-to-secure-your-fast-mcp-server-with-permission-management](/content/blog/how-to-secure-your-fast-mcp-server-with-permission-management ""/index.html)
👍 2
👀 2
a
Anna Paykina
10/17/2025, 10:11 AM
Hey everyone 😊 We have a new guide out “ [Zero-Trust for microservices, a practical blueprint](/content/blog/zero-trust-for-microservices ""/index.html)”!
If you are moving from monoliths to distributed systems, you’ve likely hit the authorization wall.
In the guide, we tackle the critical question modern architectures struggle with: “Is Service A allowed to access Resource X on behalf of User Y?”
What we cover: → Why perimeter-based security fails in microservices, and creates lateral movement risks → Implementing workload identity for services, bots, and AI agents → The “on-behalf-of” authorization model for context-aware decisions → Real policy examples for service-to-service authorization and AI agent constraints → Observability through OpenTelemetry integration and centralized audit logs
🙌 3
cerbie 3
✨ 3
👀 1
a
Anna Paykina
10/21/2025, 9:19 AM
Hey community 👋
Earlier this year, Cerbos co-founder and CPO Alex Olivier took the stage at DevDays Europe alongside experts Kenneth Rohde Christiansen, Paul Dragoonis, Romano Roth, and Victor Lyuboslavsky to speak on the topic of “*Building the Future: Trends in Modern Application Architecture*”.
They tackled everything from AI’s impact on cloud infrastructure to the perennial microservices vs. monolith debate.
If you’re curious, you can check out the [recording and summary write-up here](/content/blog/modern-application-architecture-trends ""/index.html) 👈 😊
💡 2
👍 3
💻 2
a
Anna Paykina
10/23/2025, 10:47 AM
Hello, everyone ☺️ We just published a new guide “ [Mapping business requirements to authorization policy for insurance](/content/blog/mapping-business-requirements-to-authorization-policy-for-insurance ""/index.html)”
In it, we explore how authorization helps fight insurance fraud (which costs the industry $306B annually), and break down PBAC examples across auto, life, and property insurance. Complete with Cerbos policies you can use 💻
🙌 2
cerbos 1
GitHub
10/28/2025, 4:42 AM
Release - v0.47.0 New release published by github-actions[bot] ## Cerbos 0.47.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.47.0.html
## Changelog
### Features
• 1b8e12d feat(helm): allow specififying service.trafficDistribution ( #2693) • 3ea4971 feat: Add AWS Lambda support ( #2661) • ac53850 feat: Decouple rule table ( #2653)
### Enhancements
• d1e01d8 enhancement: Add upload-git cmd and change details from git to replace-files cmd ( #2695) • e82e409 enhancement: More detailed schema errors ( #2663) • 46bf586 enhancement: Use default config if one not provided for Lambda ( #2728)
### Bug fixes
• d0edd70 fix: Batch dependents and deflake CI suites ( #2677) • e89c9cc fix: Fix e2e blob test by guaranteeing policy existence ( #2672) • 0e863bb fix: Fix e2e overlay test ( #2671) • ce2c68d fix: Increase blob e2e sleep period ( #2684) • 054159c fix: Use CollectT in EventuallyWithT ( #2685)
### Documentation
• a9f9af4 docs(lambda): Add AWS Lambda docs ( #2740) • 2d8e7f6 docs: Add AI policy to contribution guidelines ( #2710) • 353d188 docs: Fix broken link in README.md ( #2658) • 7cfd150 docs: Fix broken links to Hub documentation ( #2741)
### Chores
• 2f6df1c chore(ci): Clean up .goreleaser.yml ( #2670) • fdc383f chore(ci): Clean up deployment to AWS SAR ( #2723) • 9f5baba chore(ci): Clear disk space quicker ( #2692) • 26f5ead chore(ci): Increase E2E blob store update interval ( #2720) • a72d22c chore(ci): Move all Minio images to bitnamilegacy ( #2722) • f8559c9 chore(ci): Publish AWS Lambda extension to SAR ( #2719) • 08ed41a chore(ci): Publish lambda handler to AWS SAR ( #2707) • ada628e chore(ci): Rename lambda release directories for consistency ( #2725) • 7cb7f74 chore(ci): Set minimum age for Renovate dependencies ( #2708) • 1dca73d chore(ci): Test publishing to SAR ( #2713) • 6ca5696 chore(ci): Use faster disk space reclaim action ( #2694) • 124d4f8 chore(ci): Use legacy Bitnami registry ( #2721) • f6bf465 chore(deps): Bump github.com/docker/docker from 27.2.0+incompatible to 28.0.0+incompatible ( #2666) • e621d1f chore(deps): Bump github.com/go-viper/mapstructure/v2 from 2.3.0 to 2.4.0 ( #2673) • 8705370 chore(deps): Bump github.com/quic-go/quic-go from 0.54.0 to 0.54.1 in /tools ( #2731) • 7848eb4 chore(deps): Bump github.com/ulikunitz/xz from 0.5.12 to 0.5.14 in /tools ( #2678) • 0c1cc42 chore(deps): Update Buf dependencies ( #2737) • 0bc938c chore(deps): Update GitHub Actions deps to v5 (major) ( #2712) • 86df549 chore(deps): Update Go deps ( #2711) • 27c8dbd chore(deps): Update Go deps ( #2717) • 8133849 chore(deps): Update Go deps ( #2727) • 617c1be chore(deps): Update Go deps ( #2732) • b3dfff0 chore(deps): Update Go deps ( #2739) • 4094281 chore(deps): Update Go deps ( #2744) • aa5c201 chore(deps): Update No… cerbos/cerbos
🚀 2
a
Anna Paykina
10/29/2025, 11:03 AM
Hey community 👋
We just published a [technical guide on how to leverage JWT claims in Cerbos](/content/blog/leveraging-jwt-claims-in-cerbos-access-control ""/index.html). Feel free to check it out if it’s relevant for you.
Main takeaways: • Cerbos verifies JWTs using your JWKS and exposes claims directly to policy conditions. • You can configure multiple keysets, cache verified tokens, and handle rotation without restarts. • Claims like iss, aud, and sub can be enforced centrally in CEL expressions. • Gateways can pass tokens through; one policy set covers edge and service. • Stolen credentials remain a top initial action in breaches at 24 percent in 2024. Strong token verification helps reduce risk. • Disable verification only for controlled testing, not for production.
👍 2
a
Anna Paykina
10/30/2025, 6:33 AM
Hey everyone 🙂 Coming to you with some great news. You can now run Cerbos natively inside AWS Lambda. [ [Guide for reference](/content/blog/run-cerbos-natively-inside-aws-lambda ""/index.html)]
Depending on your preference, you can deploy Cerbos directly in AWS Lambda-either as a standalone function or as a lightweight extension layer-while using Cerbos Hub for centralized policy management and audit-logging.
cerbie 1
🙌 1
a
Anna Paykina
11/03/2025, 11:00 AM
Hey everyone, we got some requests asking for a possibility to automate Cerbos policy uploads.
There is now a solution 🙌 The cerbos-store-action GitHub Action can be used for this purpose. [Check out our guide for details](/content/blog/automate-cerbos-policy-uploads-with-the-cerbos-store-action-git-hub-action ""/index.html).
Have a great week!👋
cerbie 2
💪 2
👍 2
a
Anna Paykina
11/20/2025, 9:25 AM
Hey <!channel>!
We have introduced security controls designed specifically for agentic AI 🤖🚀
Using Cerbos, you can enforce fine grained authorization at every step of your agent’s workflow: • You can filter RAG retrievals before they ever reach a prompt. • You can control which MCP tools an agent can use based on permissions and context. • You can authorize every downstream API call the agent makes. • And you can capture structured audit logs that explain every allow and deny decision. With Cerbos in place, your AI agents stay within the security and compliance boundaries you set.
[Check out the details here](/content/features-benefits-and-use-cases/ai-security ""/index.html)
🎉 5
🙌 1
🚀 2
a
Andre Du Plessis
11/20/2025, 11:05 AM
Okay
l
Lisa Dziuba
12/02/2025, 5:32 AM
Hello @channel!
I'd love to invite you all to a practical webinar on securing agnetic AI. I guess this is the topic many of you care about 🤖. It will be 45-minute sessions where our team will cover:
• Real attack surfaces and abuse cases from agentic workflows • Guardrail patterns for controlling agent-initiated actions • Authorization models that constrain what agents can do • How to map controls to SOC2 / privacy / enterprise audit needs • Practical architecture patterns you can reuse immediately • Zero trust principles for agents • A walkthrough of agentic access control policies + examples Speaker is @Alex Olivier (Cerbos), CPO at Cerbos. Much of his current work is centered around securing agentic workflows and the new controls required to keep AI systems safe. 🛠️ Alex will show agentic demos, access control policy templates, and workflow diagrams.
📆 Date: Dec 16, 2025, 05:30 PM (GMT+0)/ 9.30 AM PST cerbie Zoom link to register: https://zoom.us/webinar/register/3617646715082/WN_9mtiwDYGRZqw3hr6KsAbMQ
Looking to see you there!
cerbie 3
📹 3
🎉 3
cerbos 2
👌 1
GitHub
12/03/2025, 2:53 AM
Release - v0.48.0 New release published by github-actions[bot] ## Cerbos 0.48.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.48.0.html
## Changelog
• 8838f2a Add v0.48.0 release notes ( #2827) • c02028c Fix free-disk-space action ( #2816) • 1022dba Implement inspect.RuleTables ( #2818) • e050e29 Pin cerbos/buf-breaking-action version ( #2819) • d3133c2 Pin golangci-lint version in CI ( #2811) • 9de93b8 Remove jlumbroso/free-disk-space action ( #2815) • fe0a0dd Update verdaccio to 6.2.2 ( #2810) • dc198e5 Use
extractions/setup-crate
directly ( #2812) • 6a966b2 chore(api): Reimplement AuthZen APIs using direct calls to engine ( #2798) • 883e9ec chore(ci): Add "v" prefix to cosign version ( #2763) • ed6ac72 chore(ci): Fix cosign version to 2.6.1 ( #2760) • 72ff0e5 chore(ci): Fix no such host error in e2e tests ( #2775) • c747b01 chore(ci): Fix release workflow, rename cerbosfunc, update lambda docs ( #2748) • cc5819f chore(ci): Pin GitHub Action digests ( #2807) • a8bcd9e chore(ci): Remove -failfast flag when executing E2E tests ( #2776) • 052aec9 chore(ci): Remove conventional commits requirement ( #2806) • 6602c25 chore(deps): Bump github.com/opencontainers/runc from 1.2.3 to 1.2.8 ( #2767) • 0a4e029 chore(deps): Bump golang.org/x/crypto from 0.37.0 to 0.45.0 in /hack/tools/changelog ( #2805) • 4d99f7c chore(deps): Bump golang.org/x/crypto from 0.43.0 to 0.45.0 in /tools ( #2794) • 8dd72c7 chore(deps): Pin dependencies ( #2809) • cb47613 chore(deps): Update GitHub Actions deps ( #2750) • aa7968c chore(deps): Update GitHub Actions deps ( #2756) • 60703b8 chore(deps): Update GitHub Actions deps ( #2821) • 6136f27 chore(deps): Update GitHub Actions deps to v6 (major) ( #2755) • 3913ce1 chore(deps): Update Go deps ( #2751) • 81d1746 chore(deps): Update Go deps ( #2772) • 27656c0 chore(deps): Update Go deps ( #2788) • dbd2f64 chore(deps): Update Go deps ( #2799) • afd20ef chore(deps): Update Node.js deps ( #2753) • ebc6907 chore(deps): Update Node.js deps ( #2789) • f3872e9 chore(deps): Update Node.js deps ( #2800) • 9b7fae8 chore(deps): Update Node.js deps ( #2822) • e805581 chore(deps): Update actions/upload-artifact action to v5 ( #2754) • 0574697 chore(deps): Update dependency corepack to v0.34.2 ( #2771) • 019092f chore(deps): Update dependency node to v24 ( #2757) • 7215630 chore(deps): Update module golang.org/x/crypto to v0.45.0 [SECURITY] ( #2795) • b21e502 chore(deps): Update sigstore/cosign-installer action to v4 ( #2758) • 98da70f chore(release): Prepare release 0.48.0 • 15bf74d chore(version): Bump version to 0.48.0 • 71107bc chore: Add
just align
recipe to sort struct fields ( #2790) • a702850 chore: Add manifest field to rule table ( #2768) • <https://git… cerbos/cerbos
a
Anna Paykina
12/05/2025, 7:31 AM
Hey <!channel>, we have some big news: We just released our comprehensive guide to multitenant authorization! 🎉
📚 “One size does not fit all: A guide to multitenant authorization”
We keep seeing the same pattern across companies: fixed roles work at small scale, but collapse under enterprise complexity. This ebook captures how we help teams solve that problem.
The “Admin, Editor, Viewer” model becomes a cage when an enterprise signs up for a SaaS product. Teams scramble to create thousands of tenant-specific role variants. Role explosion follows. Support tickets pile up. Enterprise deals stall.
We’ve distilled everything we’ve learned, from real-world implementations, architecture patterns, and painful lessons, into a practical guide that shows teams how to implement dynamic, multitenant authorization that actually scales.
In the ebook we dive into: → Why fixed roles break at enterprise scale (and what role explosion really looks like) → How to implement authorization that mirrors each tenant’s organizational reality → Architecture patterns for separating platform-wide rules from tenant-specific policies → How to balance central control with tenant self-service and delegated administration → Real examples from leading SaaS companies scaling authorization across thousands of tenants → The PEP/PDP/PAP pattern and policy-as-code workflows
🔗* Download the ebook\* 🔗
👍 3
💪 4
🎉 2
cerbie 3
🙌 2
🏘️ 1
GitHub
12/10/2025, 4:15 AM
Release - v0.49.0 New release published by github-actions[bot] ## Cerbos 0.49.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.49.0.html
## Changelog
• a9d48db Ability to pipe Hub audit logs to a secondary backend ( #2832) • 6b9e9db Add policy source for EPDP v2 ( #2840) • 52c4f78 Add v0.49.0 release notes ( #2839) • 61ab8a6 Fix error message when upload-git fails ( #2828) • 347b733 Options to control instrumentation of in-process service ( #2838) • 4bdc775 changelog entry for role policy DENY intersect fix ( #2833) • 3885f81 chore(deps): Bump jws from 3.2.2 to 3.2.3 in /npm/test/registry ( #2830) • fcf3c3b chore(deps): Update GitHub Actions deps ( #2834) • e36e898 chore(deps): Update Go deps ( #2835) • 0e08f4c chore(release): Prepare release 0.49.0 • 82108bf chore(version): Bump version to 0.49.0 • c677615 fix: Correctly intersect role policy DENYs for multi-role principals ( #2831) • 60fac8a fix: Output serialization in the AuthZen response ( #2837) cerbos/cerbos
a
Anna Paykina
12/15/2025, 9:36 AM
Hey everyone! Our CPO and co-founder, Alex Olivier, put together a write-up of the [key insights from Gartner IAM Summit 2025](/content/blog/gartner-iam-summit-2025-authorization-authzen-identity-security-expanding-to-every-workload ""/index.html)
High level summary: Authorization has evolved from a backend control into strategic identity infrastructure.
What’s driving this shift: 1️⃣ Workload IAM is the new frontier. 2️⃣ Authorization modernization is no longer optional. 3️⃣ Standards are accelerating adoption.
As identity ecosystems expand beyond humans into autonomous agents and distributed infrastructure, organizations need to rethink how access decisions are designed, enforced, and standardized.
Feel free to read the full recapfor deeper insights on policy based authorization, the coexistence of authorization models, and why this matters for security architectures 👇 [https://www.cerbos.dev/blog/gartner-iam-summit-2025-authorization-authzen-identity-security-expanding-to-every-workload](/content/blog/gartner-iam-summit-2025-authorization-authzen-identity-security-expanding-to-every-workload ""/index.html)
👍 2
cerbie 2
👀 2
a
Anna Paykina
12/18/2025, 5:59 AM
Hey <!channel>! 👋
We just published a blog comparing Cerbos PDP vs. Cerbos Hub – ultimately, when you can use the open source engine alone vs. when you need the managed solution.
It breaks down the operational differences across policy writing, testing, distribution, updates, and audit logging – plus the engineering cost of building it yourself.
Worth a read if you’re scaling authorization or hitting operational pain points: [https://www.cerbos.dev/blog/cerbos-pdp-and-cerbos-hub-choosing-the-right-setup-for-your-team](/content/blog/cerbos-pdp-and-cerbos-hub-choosing-the-right-setup-for-your-team ""/index.html)
If you have any question - drop them in the thread. Happy to discuss! 💬
🙌 2
cerbos 2
👌 2
👍 2
GitHub
12/22/2025, 6:10 AM
Release - v0.50.0 New release published by github-actions[bot] ## Cerbos 0.50.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.50.0.html
## Changelog
• a4b548d Add default scope configuration to be used when scope is not specified in the request ( #2843) • 76861a6 Add dot as an alias to empty scope in requests ( #2846) • 6f76194 Add v0.50.0 release notes ( #2863) • 2422259 Introduce InspectPolicies API for rule tables ( #2836) • 777ad46 Prevent index lookup of constants, globals, and variables ( #2858) • 7db8ae1 Revert breaking change to EPDP interface ( #2853) • 0ccb88e Update GoReleaser config ( #2855) • 6929c0b Use namer.ScopeValue when fitting ( #2848) • 4e2292c chore(deps): Bump github.com/quic-go/quic-go from 0.56.0 to 0.57.0 in /tools ( #2841) • 7d58efd chore(deps): Update GitHub Actions deps ( #2844) • 1d3758c chore(deps): Update Go deps ( #2845) • 60f11a7 chore(deps): Update Go deps ( #2862) • 5bffe40 chore(deps): Update Node.js deps ( #2851) • 3afeeb8 chore(deps): Update actions/checkout action to v6 ( #2852) • 3d67f66 chore(release): Prepare release 0.50.0 • 2ff256b chore(version): Bump version to 0.50.0 • 3eef8f3 chore: Ruletable optimization clean-up ( #2860) • c20c6d7 enhancement: Ruletable optimizations and refactoring ( #2857) • db9fb5e fix(planner): Union nodes across scope boundaries ( #2849) • 1ab8a62 fix: Isolate role policy restrictions ( #2842) cerbos/cerbos
a
Anna Paykina
12/24/2025, 6:26 AM
Hey community! Happy Holidays from all of us at Cerbos! 🎄✨ Thank you for your support throughout the year, we’re excited for what’s ahead in 2026!
In the meantime, if you’re looking for a fun challenge over the holidays, check out our Policy Game.
See who among your friends and family can get the high score: https://game.cerbos.dev/?event=happyholidays2025 🕹️
It’s a brain-teasing policy puzzle that’ll test everyone’s accuracy and speed.
May the best decision-maker win!
cerbie 1
🎯 1
❄️ 1
🧡 1
l
Lisa Dziuba
02/13/2026, 6:48 AM
Roses are red. Violets are blue. Implicit trust is risky. Least privilege looks better on you.
❤️ Fall for runtime authorization this #ValentinesDay: [https://www.cerbos.dev/](/content/ ""/index.html)
P.S.: Have a happy Valentine's Day!
s
Slackbot
02/15/2026, 12:41 AM
@Nishant Vartak joined #announcements. They’re also new to Cerbos Community.
👋 2
l
Lisa Dziuba
02/17/2026, 9:16 AM
Hello everyone 👋
Today we’re announcing our integration with Tailscale to bring fine grained authorization to agentic AI. 🤖 AI agents are now calling internal tools and APIs in production. They often run with broad permissions. That creates real risk.
• Aperture by Tailscale sits in the request path and intercepts tool calls. It provides visibility into agent activity and usage across your connected systems. • Cerbos evaluates each tool call against policy and returns an explicit allow or deny decision. • Aperture enforces that decision before the action runs. Cerbos also produces decision-level audit logs tied to identity and policy version. 👉 Learn more: [https://www.cerbos.dev/tailscale-aperture](/content/tailscale-aperture ""/index.html)
👏 2
a
Anna Paykina
03/04/2026, 5:48 AM
Hey, <!channel> 👋 We’re excited to give a shoutout to Paulo - one of our community members - and his team at Flash!
Flash is a Brazilian fintech using Cerbos to power real-time expense controls for hundreds of corporate clients. Since making the switch to Cerbos they’ve seen corporate card usage double, they’re managing 6,000+ policy rules in real-time, and they’ve done it all without adding engineering headcount. 🙌📈
Huge thanks to Paulo and the Flash team - not only for building something impressive with Cerbos, but for being kind enough to share their journey with us.
Full story here if you want to explore the details: [https://www.cerbos.dev/customers/flash](/content/customers/flash ""/index.html)
cerbos 8
👏🏻 1
💫 6
🚀 7
🏦 4
🎉 10
👏 9
❤️ 1
a
Anna Paykina
03/09/2026, 7:20 AM
Hey <!channel>! We’re hosting a 💻 📹 free webinar next week on layered security and Zero Trust.
If one of your Zero Trust layers fails, what actually catches the threat next? Few teams can confidently answer what happens when a layer breaks - or whether the threat sails straight through to a breach.
Aviation solved this decades ago with the Swiss Cheese Model, and we’re applying the same framework to runtime security. You’ll walk away with a practical way to stress-test your security layers, identify where the dangerous gaps are, and build a true Zero Trust Architecture you can stand behind.
We’ll cover the six layers of runtime security (identity, authentication, PAM, entitlement management, coarse-grained and fine-grained authorization), where most orgs still have blind spots, and why end-to-end Zero Trust is finally implementable.
📅 Wednesday, March 18th · 6:30pm CET / 9:30am PST · 45 min + Q&A
🔗 Register here, if you’d like: https://zoom.us/webinar/register/9117730533248/WN_rBAJChIBR52EEd5XeNI9xw PS. No worries if you can’t make it live. Register anyway and we’ll send the recording post-webinar.
💫 5
👍 7
🙌 6
cerbie 3
👀 4
cerbos 1
l
Lisa Dziuba
03/10/2026, 6:25 AM
Cerbos turns 5 today. 🎉 For five years, Cerbos has been helping teams run secure, scalable authorization.
Cerbos is now used by companies around the world to manage complex permissions, enforce policies consistently, and control what AI agents are allowed to access and do.
Grateful to everyone building with Cerbos and helping us grow.
cerbie 7
💪🏻 1
🎉 10
👏 2
🎂 11
💪 4
👏🏻 1
💜 2
🥰 1
l
Lisa Dziuba
03/12/2026, 6:22 AM
Hey everyone 👋
We have some more cool news to share: we're introducing Cerbos for agentic commerce. AI agents are starting to place orders, trigger refunds, and modify subscriptions inside e-commerce systems. The question becomes: what are those agents actually allowed to do?
Cerbos helps e-commerce platforms evaluate every AI agent purchase, refund, and subscription action against centralized authorization policies before money moves:
• Evaluate agent actions against policies at runtime • Enforce authorization at the API boundary where agent transactions execute • Apply consistent policies across storefronts, APIs, and integrations • Maintain a clear decision trail showing which policy allowed or denied each action If you are building agent-driven commerce systems, see how authorization policies can control agent transactions. 👉 [https://www.cerbos.dev/agentic-commerce](/content/agentic-commerce ""/index.html)
🚀 5
cerbie 5
🌟 3
l
Lisa Dziuba
03/20/2026, 11:07 AM
Happy Friday everyone 🙂 Big one today, we’re introducing Cerbos Synapse 🎉
Every authorization decision is only as good as the data behind it. Who is this user? What groups are they in? What resource are they trying to access? Most teams end up building this data plumbing themselves, repeatedly, across apps, services, and increasingly AI agents in their stack.
Cerbos Synapse enriches authorization requests with identity, resource, and relationship data from your existing systems before the policy engine evaluates what to allow:
✔️ No custom enrichment middleware ✔️ Native integrations for Envoy, Kafka, Trino, and Kubernetes ✔️ Built for AI agents and non-human identities ✔️ Complete audit trail from data source to decision outcome
Extensions can be written in Go or any language that compiles to WebAssembly, so you're not locked into one ecosystem. Happy to answer any questions here, or feel free to explore Cerbos Synapse yourself: [https://www.cerbos.dev/product-synapse](/content/product-synapse ""/index.html)
🚀 6
🌟 4
💪 4
🙌 3
💪🏻 1
🙌🏻 1
l
Lisa Dziuba
03/26/2026, 12:08 PM
👋 Hey everyone, We’ve been seeing Claude Code spread well beyond engineering. Marketing teams exploring codebases, product managers reading configs, data analysts grepping logs.
But there is a gap. There is no central, enforceable way to control what those agents can actually do. Hooks exist, but they are local config, per developer, opt-in. That means no consistent enforcement across the org and no reliable way to see what agents actually did.
🎉 Today, we are introducing centralized authorization for Claude Code agents. Every tool call is intercepted and checked against policy before it runs. That gives you control over what agents are allowed to do, at the moment they act:
• Allow or deny decisions on every tool call, not just monitoring • Role-based controls so engineers can use Bash while other teams stay read-only • Full audit log tied to the user behind each agent action • Policies as code, versioned, reviewed, and updated without redeploying anything Policies and audit logs are managed in Cerbos Hub, so you have one place to control access and understand what agents are doing across your org. If you want to see how it works or try it out, we’re around and happy to help:
👉 [https://www.cerbos.dev/ecosystem/claude-code](/content/ecosystem/claude-code ""/index.html) 👉 [https://www.cerbos.dev/workshop](/content/workshop ""/index.html)
cerbie 4
💫 1
🚀 5
🎉 4
a
Anna Paykina
04/07/2026, 9:06 AM
Hey community! Hope your week is going well 😊
We wanted to share our new guide + demo with you. It’s all about using Cerbos Synapse with Apache Trino.
It covers how to add row-level security, column masking, and table-level access control to Trino through its existing OPA plugin. Synapse handles the protocol translation and enriches each query with user attributes from your IdP, so your Cerbos policies control what each user sees down to the row and column level.
The 3-min demo shows three users running the same SELECT query and getting completely different results based on who they are. [Blog](/content/blog/row-level-security-for-apache-trino ""/index.html) +
Demo video▾
If you’re running Trino and have questions about the setup, drop them here :)
💫 3
👍 3
🙌 3
🙌🏻 1
👍🏻 1
a
Anna Paykina
04/10/2026, 1:34 PM
Hey everyone, happy Friday ☺️
We just published a new blog on the 5 authorization blind spots auditors find most often in enterprise access control.
It walks through the things that come up again and again in real audits - scattered authorization logic across codebases, policies that exist on paper but no proof of enforcement, quarterly access reviews that check role labels instead of actual permissions, non-human identities running with standing privileges, and AI agents deployed without an authorization model.
Each section has a “what to do now” piece with practical steps to close the gap before the next audit cycle. Hoping it’s useful for anyone working through SOC 2, ISO 27001, HIPAA, or similar frameworks, or just generally rethinking how authorization fits into their Zero Trust setup 🙂
Full blog: [https://www.cerbos.dev/blog/5-authorization-blind-spots-auditors-find-and-how-to-fix-them](/content/blog/5-authorization-blind-spots-auditors-find-and-how-to-fix-them ""/index.html) Have a great weekend!
🔒 3
👍 3
cerbie 3
a
Anna Paykina
04/14/2026, 9:44 AM
Hey everyone! Excited to share a walkthrough on using Cerbos Synapse to add authorization to legacy applications without any code changes 🙂
Envoy sits in front of the app as a reverse proxy, handles authentication against your IdP, and calls Synapse for a policy decision on every request. The legacy app doesn’t need an SDK, doesn’t need modifications, doesn’t even know Cerbos is there.
📖 [Full guide](/content/blog/modernizing-authorization-for-legacy-applications ""/index.html) with policy examples and a phased rollout path 🎥
Video demo▾
showing it in action with a legacy payroll app
If you’re dealing with legacy systems that have been sitting outside your authorization framework, this one’s for you!
💥 5
🎉 5
cerbie 5
a
Anna Paykina
04/22/2026, 12:13 PM
Hey community 👋 We just published a new guide on writing Cerbos authorization policies with an agent skill we’ve released.
The hardest part of writing authorization policies isn’t the policy language. It’s the translation from business requirements into a precise spec of who can do what, under which conditions, on which resources.
So we built an agent skill that handles the translation for you. You describe the access rules in plain English (or any language!), it asks the clarifying questions to tighten up anything vague, then generates the full policy bundle for you, including schemas, derived roles, resource policies, and tests, and validates every output against the real Cerbos compiler. If validation fails, it reads the errors and keeps fixing until the policies compile cleanly.
It works in Claude Code, Cursor, Codex, OpenCode, and 10+ other agents. Install is one command:
Full write-up here: [https://www.cerbos.dev/blog/agent-skill-for-writing-authorization-policies](/content/blog/agent-skill-for-writing-authorization-policies ""/index.html)
cerbie 4
🤖 4
🙏 4
👍 3
🎉 2
GitHub
04/28/2026, 2:16 AM
Release - v0.52.0 New release published by github-actions[bot] Cerbos 0.52.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.52.0.html Changelog
• 2812325 Add 0.52.0 release notes ( #3127) • 3f8cfc3 Add TraceBatch format for compact trace representation ( #2945) • 9a8ceb5 Add ability to save Hub credentials ( #3067) • 78fec1d Add build constraints ( #2979) • 6e74c62 Add changelog entry for breaking OpenTelemetry changes ( #2954) • d7eefbe Add pages/recipes for common questions ( #3106) • 9fb62a2 Add path functions to Cerbos CEL library ( #3039) • f3f464b Add permissions advisor workflow ( #3007) • ad8d242 Add siteline to docs ( #3093) • b9dc7e1 Add tracer.TracesToBatch ( #2958) • de243ba Add verify.BundleStream ( #2944) • f8a1020 Additional repository statistics ( #3025) • 681bcf8 Avoid compiling constant expressions at runtime ( #3005) • cbfb1b3 Avoid round-tripping attributes to JSON for schema validation ( #3000) • f0e0df7 Bump brace-expansion from 2.0.2 to 2.0.3 in /npm/test/registry ( #3062) • 74fa896 Bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 ( #2975) • a3f8d30 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.96.4 to 1.97.3 in /tools ( #3083) • a02dfd0 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.97.1 to 1.97.3 ( #3082) • dce4632 Bump github.com/buger/jsonparser from 1.1.1 to 1.1.2 in /tools ( #3054) • 489656f Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 ( #2980) • bf6e74a Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 in /hack/tools/changelog ( #2981) • 96b53c0 Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 in /tools ( #2987) • 04960ce Bump github.com/docker/cli from 27.4.1+incompatible to 29.2.0+incompatible ( #3004) • a78b47a Bump github.com/go-git/go-git/v5 from 5.17.0 to 5.17.1 in /hack/tools/changelog ( #3070) • 8d29a2f Bump github.com/go-git/go-git/v5 from 5.17.1 to 5.18.0 in /tools ( #3109) • 10d8886 Bump github.com/go-git/go-git/v6 from 6.0.0-alpha.1 to 6.0.0-alpha.2 in /hack/tools/changelog ( #3113) • f1706dd Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 ( #3072) • 9d61b19 Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /hack/loadtest ( #3073) • e9bbc5e Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /tools ( #3074) • 35fd059 Bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 ( #3118) • d4cd21c Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 in /tools ( #3104) • 6febdf3 Bump go.opentelemetry.io/otel from 1.40.0 to 1.41.0 in /api/genpb ( #3121) • ebe00a5 Bump go.opentelemetry.io/otel from 1.40.0 to 1.41.0 in /hack/loadtest ( #3126) • 6071f59 Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in /tools ( #2986) • 73c754d Bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in /tools ( #3097) • <ht… cerbos/cerbos
🚀 3
GitHub
05/05/2026, 7:34 AM
Release - v0.53.0 New release published by github-actions[bot] Cerbos 0.53.0
View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.53.0.html Changelog
• 93a75a6 Add Helm release workflow and bump chart version to 0.52.1 ( #3133) • 218ea22 Add v0.53.0 release notes ( #3143) • 81ab26e Fix rendering of wildcard characters ( #3140) • 77974a7 Migrate to
cerbos/actions
( #3120) • 2e8e054 Move Helm release to its own workflow ( #3135) • 7cd3152 Move path functions documentation to correct place ( #3139) • d72ef61 Remove JWT verification cache ( #3138) • 5028a6f Remove
voxmedia/github-action-slack-notify-build
( #3129) • ccc98e9 Remove incorrect default tag value from Helm chart ( #3131) • ea252b9 Set
Content-Type
to
application/x-ndjson
on streaming responses ( #3130) • cc293e2 Update GitHub Actions deps ( #3124) • 2261983 Update cerbos/actions to bb55708 ( #3142) • 51ab843 Update to
<http://github.com/ory/dockertest/v4|github.com/ory/dockertest/v4>
( #3136) • 78d494c chore(release): Prepare release 0.53.0 • 47b23a4 chore(version): Bump version to 0.53.0 • c1d70c9 fix planner ignoring OVERRIDE_PARENT for parent DENYs ( #3137) cerbos/cerbos
a
Anna Paykina
05/26/2026, 11:13 AM
Hey everyone! 👋 hope your week is off to a good start!
We just published a page on [AI gateway authorization](/content/features-benefits-and-use-cases/ai-gateway-authorization ""/index.html), walking through how to layer fine-grained access control on top of your AI gateway. Feel free to check it out if it’s relevant for you ☺️
AI gateways are good at telling you who’s calling but not what that caller is actually allowed to do. Once an agent starts using tools, calling an LLM, or delegating to another agent, the human behind the request tends to disappear from the audit trail, sub-agents end up inheriting more privilege than they should, and revoking access usually means rotating credentials or redeploying.
The page covers what changes when every model call, tool invocation, and agent-to-agent handoff runs through the same policy layer your apps already use. You end up with one audit trail across humans, services, and agents, sub-agents that stay scoped to what the parent had, and policy changes that take effect at request time rather than at deploy time. Plus evidence trails that line up with SOC 2, ISO 27001, HIPAA, and DORA.
🤖 3
🚀 3
👍 3
cerbie 3
a
Anna Paykina
05/27/2026, 7:35 AM
Hey community 😊 Update for those working in automotive 🚗
UNECE R155 and R156 are now type approval requirements for new vehicle types in UN 1958 markets. They require auditable evidence of who can push what firmware, to which vehicles, under which conditions. Most platforms have that logic scattered across services in different languages, which is exactly what an auditor can’t follow.
We just published a guide on the authorization layer that actually produces that evidence. It walks through the
YAML
for a single OTA deploy action across five principals (vehicle engineer, production manager, owner, OEM partner, telematics agent), plus supplier data scoping and ECU diagnostics.
[Full write-up, with the allow/deny matrix and YAML per principal](/content/blog/mapping-business-requirements-to-authorization-policy-for-automotive ""/index.html)
🚗 3
👍 2
🔒 2
a
Anna Paykina
06/08/2026, 11:05 AM
Hey everyone 👋 Hope your week is off to a good start!
If you’re running our open-source Cerbos PDP, your authorization decisions are happening thousands / millions of times a day with no easy way to see the shape of that traffic. We just shipped 🚀 Insights to change that, a new page in every Cerbos Hub workspace that aggregates the decisions flowing through your PDPs into charts and rankings, so the patterns are obvious without you going looking for them.
You get allows and denies over time (hourly for the last 7 days, daily for the last 30), a count of active principals, and rankings of your busiest principals, resource kinds, and resource and action pairs. A spike in denials usually means a policy landed stricter than intended or a client is calling for something that no longer exists, and seeing it on a chart is the difference between catching it in minutes and hearing about it from a user days later.
Every chart links straight back into the audit log, pre-filtered to match what you’re looking at, so you can drop into the underlying decisions without rebuilding the filter by hand.
The best part is there’s nothing new to wire up. It’s built entirely on the decision data your PDPs already send to Hub, so once audit log collection is on, the page populates on its own. If your PDPs aren’t connected to Hub yet, this is the kind of thing you get when they are.
[Details can be found here](/content/blog/cerbos-hub-insights-live-view-of-what-your-authorization-layer-is-doing ""/index.html)
cerbie 2
✨ 1
🔢 1
a
Anna Paykina
06/17/2026, 7:19 AM
Hey <!channel>! We have a 📘 🔐 new ebook out: The Authorization Maturity Model, a CISO's Benchmark for 2026 If you’ve read our How to adopt externalized authorization ebook, this is the security team equivalent.
It gives CISOs: • A 4-stage model to benchmark where their authorization program actually stands • A regulator-by-regulator exposure rating across NIS2, DORA, SEC, the EU AI Act and more • And a 90-day plan to close the gaps. Written by Alex Olivier, our CPO and co-chair of OpenID AuthZEN. And if you’ve been trying to get security leadership behind a real authorization push, this is a good way in. It puts the work in the terms a CISO answers to, regulatory exposure and board-level risk, which is usually what unblocks the buy-in and budget to get started.
🚀 3
💫 4
🔐 3
👍 2
cerbie 4
👍🏻 1
🙌🏻 1
👏🏻 1
a
Anna Paykina
06/18/2026, 6:04 AM
Hey community, some more news for you all - we just shipped an 🤖🚀* [agent skill for building Cerbos Synapse extensions](/content/blog/agent-skill-for-building-cerbos-synapse-extensions ""/index.html)*
Cerbos Synapse lets you shape what flows through your Policy Decision Point. Enrich a principal with attributes from a database before the decision runs, map an incoming HTTP or Envoy request onto a check, or stand up a custom endpoint under /ext/ that does exactly what your app needs. The skill builds those extensions for you. You describe what you want in plain terms, something like “enrich the principal with the user’s department from Postgres before the check runs,” and it picks the extension kind and runtime, scaffolds the files, wires the config, writes a test suite, and runs it against a local PDP. You get a working extension to drop into your own project, not a blank file.
[Feel free to check it out here](/content/blog/agent-skill-for-building-cerbos-synapse-extensions ""/index.html).
👍 3
💡 1
a
Anna Paykina
06/30/2026, 7:16 AM
Hey everyone 👋 hope your week’s off to a good start
We just shipped the [Effect matrix in Cerbos Hub](/content/blog/cerbos-hub-effect-matrix-read-authorization-policy-at-a-glance ""/index.html). It takes the same compiled policy you already deploy and lays it out as a grid, roles down one side, actions across the top, every cell showing allowed, denied, or conditional.
If you’ve ever had a product owner, a reviewer, or support ask “can this role actually do that,” you know the answer normally means reading through resource policies, derived roles, and conditions to be sure 👀_. The matrix answers it at a glance, without anyone needing to read raw policy._
You’ll find it on the Policies tab of a deployment, as a toggle between Source and Effect matrix. Conditional cells aren’t flattened into a yes or no. They’re marked conditional, and you can click in to see the exact rule and the condition behind it. It also flags the cells a wildcard rule reaches into, so a broad
documents:*
grant shows up as broad instead of hiding in a pattern.
It’s live now for any deployment in Cerbos Hub cerbie🚀 [Full write-up here](/content/blog/cerbos-hub-effect-matrix-read-authorization-policy-at-a-glance ""/index.html)
cerbie 2
👍 1
🖥️ 1
👌 1
a
Anna Paykina
07/06/2026, 7:31 AM
Hey everyone 👋 hope your week is off to a good start
We just published a [guide on running an authorization POC that actually reaches production](/content/blog/authorization-poc-guide ""/index.html) ⚙️*.*
Most POCs don’t fail on the technology. They stall when success criteria only get defined at the end, so three weeks in the demo works but it’s hard to say whether that proves anything.
The guide covers how to scope the POC to one real service instead of a demo app, the six questions worth answering before day one (can it model your real rules, does latency hold under real load, does the audit output satisfy compliance, and so on), who needs to be in the room while it runs, and why two to four weeks with a hard deadline beats an open-ended pilot.
Full write-up here: [cerbos.dev/blog/authorization-poc-guide](/content/blog/authorization-poc-guide ""/index.html)
🖥️ 1
👀 1
👍 1
🙌 1
a
Anna Paykina
07/08/2026, 5:50 AM
Hey everyone! For anyone at 🌍 WeAreDevelopers World Congress in Berlin this week:
Alex Olivier, our co-founder and CPO, and co-chair of the OpenID AuthZEN working group, is speaking tomorrow on securing AI agents once they stop reading and start acting. Prompt instructions aren’t a security boundary, and the talk covers what to put there instead.
“The day the chatbot asked for sudo” Thursday, July 9, 11:30 to 12:00, Stage 6
If you’re around and want to chat in person, DM Alex on LinkedIn and he’ll make sure you find each other: linkedin.com/in/alexolivier
👍 1
🤖 1