Cerbos Newsletter [16 Feb 2023]
Hello from Cerbos!
Our February newsletter includes:
- Updates to Cerbos
- v0.25 of Cerbos
- Cerbos Playground - write, test, and debug Cerbos policies in your browser
- Help design the future of Cerbos to enable Product and Security teams to manage policy - book a workshop
- Upcoming launch of Cerbos Cloud - the solution that will help our users revolutionize the way they authorize. Sign up for updates
- Milestones:
- Cerbos events:
- New blog posts on Cerbos.dev:
- How Cerbos helped Nook build secure and extensible roles and permissions
- Supercharging your policy rules with self-service custom roles
- Modern Web podcast: Authorization on the web
- Stateful authorization is an anti-pattern
- Authorization trends 2023: Delegation to specialized solutions & advancements in technology
- React Round Up podcast: User authorization with Cerbos
- Cerbos best practices documentation - new section on attribute-led policy design
- and a chance to win a $100 Amazon gift card
Cerbos v0.25
The latest release of Cerbos, v0.25, contains improvements to the Admin API to make administrative tasks easier and error-free.
When using database-backed policy stores, it's now possible to disable policies by name cerbosctl or the Admin API.
The DeleteSchema Admin API endpoint now returns the number of schemas deleted and does not throw an error if none were deleted.
Now Cerbos detects when a policy file has changed its identifiers via the Admin API and evicts the old state from the cache.
You can find the full release notes here.
Over the past few weeks we have attended the following three events. For those of who were there and stopped by - it was great speaking with you!
- CloudNativeSecurityCon NA: Feb 1-2 (Seattle, WA)
- Civo Navigate: Feb 7-8 (Tampa Bay, FL)
Cerbos gave a talk on the topic of “Solving the never ending requirements of authorization” at the conference on February 8th. - The Notion Capital Cloud Challengers Report launch: Feb 9 (London, UK)
Cerbos shared their forecasts for the next year, and have been named one of Europe’s top 100 early stage B2B SaaS/Cloud companies in The Notion Capital Cloud Challengers Report!
Blog highlights
How Cerbos helped Nook build secure and extensible roles and permissions
Supercharging your policy rules with self-service custom roles
We previously released a blog post exploring the topic of mapping business requirements to authorization policies. It laid the foundations for how to approach writing your authorization policies from the ground up and discussed different patterns for implementing each.
In this post, we take it to the next level by diving into the implementation of self-service custom roles. Check it out to learn more!
Modern Web podcast: Authorization on the web
In this episode of the Modern Web podcast, listeners have the opportunity to hear from Cerbos' own Alex Olivier as he joins ThisDotLabs' Adam Barrett and Rob Ocel for a discussion about Cerbos. This must-listen episode is for developers and tech enthusiasts looking to centralize and improve their application's authorization layer and logic, and gain a deeper understanding of access controls and abstraction of permissions.
Don't miss this informative and insightful discussion among software engineers.
Stateful authorization is an anti-pattern
When it comes to designing core components of a software architecture one of the early decisions that need to be made is where to store the state of the application. The state is the persisted data about the resources inside a system and typically these would be kept in a database or some type of file system.
Read the blog post for a detailed comparison of stateless and stateful authorization.
Authorization trends 2023: Delegation to specialized solutions & advancements in technology
A common thread with RBAC, ABAC, and ReBAC solutions has been the decoupling of the logic from the application code base out into a standalone service that makes decisions for the entire application. This approach allows the logic to evolve independently of the code base and fits in perfectly with today’s heterogeneous service landscapes.
Have a look at the forecast for the authorization space from Cerbos’ co-founder, Emre Baran. Learn about the latest trends and advancements with relation to the authorization world, including cloud-native technology, machine learning-based security products, and chatbot-like assistants.
React Round Up podcast: User authorization with Cerbos
In this episode of the React Round Up podcast, listeners have the opportunity to hear from Cerbos' own Alex Olivier as he joins TJ VanToll to talk about Cerbos in more detail and what it can offer to its users. Additionally, Alex explains the process of testing and setting Cerbos up.
Listen to the episode to discover how authorization can help companies scale, win enterprise clients, and meet regulatory requirements & get a look into the process of testing and setting up Cerbos.
We want to give you a $100 Amazon gift card!
We also want to talk to you about Cerbos and get your feedback, both what you like and dislike, what are your primary use cases, if you are missing any particular functionality or have suggestions on how you would like us to improve the product. Please, contact us via our feedback page and we will reach out to you to book a session.