Modernizing Authorization: From Basic Roles to Decoupled ABAC | Alex Olivier | Conf42 DevSecOps 2023
Read the abstract ➤ https://www.conf42.com/DevSecOps_2023_Alex_Olivier_modernizing_auth_decoupled_abac Other sessions at this event ➤ https://www.conf42.com/devsecops2023 Join Discord ➤ https://discord.gg/DnyHgrC7jC Cerbos Project ➤ https://cerbos.dev/ Chapters 0:00 intro 1:43 preamble 1:50 about alex 2:52 authn ≠ authz 4:05 let's scale a company 4:16 stage 1 - the blissful days of roles 4:58 stage 2 - let's change our product packaging 6:07 stage 3 - let's sell into another region 7:31 stage 4 - let's sell to 'enterprise' organisations 8:55 stage 5 - new ciso: let's get iso27001 / soc2 10:16 stage 6 - we need microservices! 11:57 a new approach 13:23 authorizaion-as-a-service? 14:09 code to policy 15:41 rise of sidecars 16:52 in practice 21:15 advantages, challenges 24:16 about cerbos 25:00 thanks