+1
HN user
gneray
This is cool! How, if at all, are you thinking about sequences of permissions in a given session? Like, ratcheting down the permissions, e.g., after reading a secret?
Everyone here firing shots at this guy should try holding their tongues.
You/we are all susceptible to this sort of thing, and I call BS on anyone who says they check every little thing their agent does with the same level of scrutiny as they would if they were doing it manually.
This ^^
There's a set of common needs across these gateways, and everyone is building their own proxies and reinventing the wheel, which just feels unnecessary.
~All of our customers at Oso (the launch partner in the article) have been asking us how to get a handle on this stuff...bc their CEO/board/whatever is asking them. So to us it was a no-brainer. (We're also Tailscale customers.)
Love to see it!
yield to a tech CEO from San Francisco
ahem, he's from Utah duh bro
I've been doing this for a year or two. Love it, but haven't made it a thing across my team...and I'm not sure they love it as much as I do :P
But first, before we get into Gas Town’s operation, I need to get rid of you real quick.
WARNING DANGER CAUTION GET THE F** OUT YOU WILL DIE
I have never met Steve, but this warning alone is :chefskiss:
Yes we've implemented this at Oso.
What a dempster fire
Say what you will -- East River Source Control is a great name
Props to this team for giving it their all
they don't actually "support" OPA. more like they run/depend on OPA
i know calvin, and he's one of the most authentic people i've worked with in tech. this could not be more off the mark
Love to see it
Curious to hear from the community about this, esp in light of article on supabase
This person is like the Gossip Guy of tech. Who cares?
Agreed! But you're glossing over the Zanzibar point of view on this topic, which falls back to dual-writes. That approach has a lot of downsides: "Unfortunately, when making writes to multiple systems, there are no easy answers."[0]
Having spoken with the actual creators of Zanzibar, they lament the massive challenge this design presents and the heroics they undertook over 7+ years at Google to overcome them.
By contrast, we're seeing lots of the best tech companies opt for approaches that let them leave the data in their source database wherever and as much as possible [1]
[0] https://authzed.com/blog/the-dual-write-problem
[1] https://www.osohq.com/post/local-authorization
I'm founder of Oso btw.
A classic
PIVOT
Inkeep has been great for us. Congrats on the launch!
I was wondering the same thing
This is the single-biggest drawback to purely Zanzibar-based architectures. The problem with requiring the authorization system to own all authorization data is that there’s really very little pure authorization data in any application. The majority of it is just application data that is sometimes used to make authorization decisions.
Here's a technical post that details these implications in practice: https://www.osohq.com/post/authorization-for-the-rest-of-us
And another post that describes an alternative approach, Oso: https://www.osohq.com/post/local-authorization
(Shocker: I'm cofounder/CEO of Oso)
This seems unrelated to Rails. Not sure why monolith can't continue handling authorization.
Agreed. You can totally keep some data in the monolith and some data in new services, and stitch them together if/as needed: https://www.osohq.com/post/distributed-authorization
+1 to this
Stripe has, frankly speaking, been somewhat slow on building out more sophisticated subscription and billing products, opening the door for companies like Paddle and more recent arrivals like Lago (which focuses on open sourced billing) to create significantly more nuanced offerings
Why do you think they’ve been slow?
We did more POCs and implementations than I care to admit. What Sam describes in this post is the result of many, many iterations that came before it. (Oso cofounder/CEO)
Well done
For all those in this thread who haven't tried Matzah, I strongly encourage you to do so. Think of it not as bread, but a cracker – a platform for spreads, if you will.
What kinds of spreads?
- Butter + salt
- Butter + jam
- I guess butter + anything
- Brie cheese
I could go on. Try it y'all!