Quickstart :: Cerbos Authorization Management Platform // Documentation
Quickstart
Create a directory to store the policies.
mkdir -p cerbos-quickstart/policies
Now start the Cerbos server. We are using the container image in this guide but you can follow along using the binary as well. See installation instructions for more information.
docker run --rm --name cerbos -d -v $(pwd)/cerbos-quickstart/policies:/policies -p 3592:3592 -p 3593:3593 ghcr.io/cerbos/cerbos:0.53.0
Time to try out a simple request.
| If you prefer to use Postman, Insomnia or any other software that supports OpenAPI, you can follow this guide along on those tools by downloading the OpenAPI definitions from http://localhost:3592/schema/swagger.json. You can also use the built-in API browser by pointing your browser to http://localhost:3592. |
- cURL
- .NET
- Go
- Java
- JS
- PHP
- Python
- Ruby
- Rust
cat <<EOF | curl --silent "http://localhost:3592/api/check/resources?pretty" -d @-
{
"requestId": "quickstart",
"principal": {
"id": "bugs_bunny",
"roles": [\
"user"\\
],
"attr": {
"beta_tester": true
}
},
"resources": [\
{\
"actions": [\
"view:public",\
"comment"\
],\
"resource": {\
"kind": "album:object",\
"id": "BUGS001",\
"attr": {\
"owner": "bugs_bunny",\
"public": false,\
"flagged": false\
}\
}\
},\
{\
"actions": [\
"view:public",\
"comment"\
],\
"resource": {\
"kind": "album:object",\
"id": "DAFFY002",\
"attr": {\
"owner": "daffy_duck",\
"public": true,\
"flagged": false\
}\
}\
}\
]
}
EOF
{
"requestId": "quickstart",
"results": [\
{\
"resource": {\
"id": "BUGS001",\
"kind": "album:object"\
},\
"actions": {\
"comment": "EFFECT_ALLOW",\
"view:public": "EFFECT_ALLOW"\
}\
},\
{\
"resource": {\
"id": "DAFFY002",\
"kind": "album:object"\
},\
"actions": {\
"comment": "EFFECT_DENY",\
"view:public": "EFFECT_ALLOW"\
}\
}\
]
}
Now create a derived roles definition that assigns the owner dynamic role to a user if the owner attribute of the resource they’re trying to access is equal to their ID.
cat > cerbos-quickstart/policies/derived_roles_common.yaml <<EOF
---
apiVersion: "api.cerbos.dev/v1"
derivedRoles:
name: common_roles
definitions:
- name: owner
parentRoles: ["user"]
condition:
match:
expr: request.resource.attr.owner == request.principal.id
EOF
Also create a resource policy that gives owners full access to their own albums.
cat > cerbos-quickstart/policies/resource_album.yaml <<EOF
---
apiVersion: api.cerbos.dev/v1
resourcePolicy:
version: "default"
importDerivedRoles:
- common_roles
resource: "album:object"
rules:
- actions: ['*']
effect: EFFECT_ALLOW
derivedRoles:
- owner
EOF
Try the request again. This time bugs_bunny should be allowed access to his own album but denied access to the album owned by daffy_duck.