Cerbos Newsletter [9 June 2022]

Hello from Cerbos!

Our June newsletter includes:

Cerbos v0.17 is available

This release introduces a new file-based audit logging backend for structured logs that can be ingested by log aggregators. Having the audit trails from all Cerbos instances aggregated in a log management system provides system and security operators fine-grained visibility into all the resources secured by Cerbos. The collected audit data can be used to monitor live trends, create alerts for exceptional or suspicious patterns, and investigate past incidents. Resource policies and derived role definitions now support the special * operator to be used with roles and parentRoles fields to match any role.
You can find the full release notes here. If you have any questions, please join our Slack community.

New Node and Ruby SDKs

SDKs for Cerbos now include a brand new Ruby SDK and an updated one for NodeJS.
These SDKs make interacting with Cerbos a much more streamlined experience and provide native methods for constructing calls out to check authorization from your codebase. As with everything else with Cerbos, they are open source and can be found on our GitHub account - Node SDK repository, Ruby SDK repository.

Blog highlights

In this article, you will learn about our AWS Cognito integration which works with the same principle that all of our other authentication integrations ( Okta, Auth0, WorkOS etc).

One of our engineers, Andrew Haines, explains how he was able to get the GitHub API to accept his request to create a secret, despite his lack of admin permissions. Andrew goes on to explain a better approach to enforcing access control in different application layers by passing permissions along from the backend.

Industry news

Zero Trust: designing an authorization model for enterprisesEmre Baran

Emre Baran writes how code-based solutions can be time-consuming. He also digs into the similarities and differences between role-based access control, core role-based access control, hierarchical role-based access control and attribute-based access control.

You should separate your billing from entitlements - Arnon Shimoni

Shimoni explains why entitlements, a customer’s access to a specific feature or product, within a given plan matter for SaaS companies. The author goes on to describe how things get complicated when changes happen, why entitlements should be separated, an entitlement architecture and the expected outcomes from separation.

Six cybersecurity startups to watch, according to VCs - Steph Bailey

Rob Kniaz, partner at Hoxton Ventures, named Cerbos as one of the top cybersecurity startups to watch.

Developer Relations role

We’ve growing very fast and need an experienced developer relations manager as the face of Cerbos in the developer community. We’d love this person to engage with developers to discover and remedy pain points, produce accessible technical content and help build an inclusive community of Cerbos users.

Do you want a Cerbos t-shirt?

Good! We want to give you a t-shirt! And we also want to talk to you about Cerbos and get your feedback, both what you like and dislike, what are your primary use cases, if you are missing any particular functionality or suggestions on how you would like us to improve the product.

Stay connected