https://cerbos.dev logo
Join Slack
Powered by
# announcements
  • a

    Anna Paykina

    01/22/2025, 3:38 PM
    Hey again, <!channel> We recently released a blog post + video on the 11 trends that will define the future of authorization ๐Ÿ’ก If youโ€™re interested - feel free to check it out! The piece is based on our expertise as an enterprise authorization provider, and insights from hundreds of conversations with architects, IAM leads, and CISOs we got a chance to speak with over the past year.
    ๐Ÿ‘€ 3
    ๐Ÿš€ 3
    ๐Ÿ˜Š 2
    ๐Ÿ‘ 2
    ๐Ÿ‘๐Ÿผ 1
  • a

    Anna Paykina

    01/29/2025, 1:24 PM
    Hey, <!channel>! We have rolled out an update to the Cerbos Hub Playground thatโ€™s tailored for those of you who are building more complex policies and want a development experience that mirrors real-world deployments more closely. This update introduces Cerbos Hub Playground engine settings, letting you configure the Cerbos PDP engine used when evaluating policy during development, in a way that reflects your actual environment. ๐Ÿ‘‰Get the details here
    ๐Ÿ’ก 3
    cerbie 4
    ๐Ÿš€ 5
  • a

    Anna Paykina

    01/30/2025, 11:32 AM
    Hey, Cerbos community! ๐Ÿ‘‹๐Ÿ˜Š We just published a blog post discussing the core principles, advantages and disadvantages, and practical concerns of stateless architecture. Feel free to check it out here
    ๐Ÿ™Œ 3
    ๐Ÿ‘€ 3
    cerbie 3
    ๐Ÿ™Œ๐Ÿผ 1
    ๐Ÿ’ป 1
    d
    a
    • 3
    • 2
  • a

    Anna Paykina

    02/04/2025, 12:15 PM
    Hey <!channel>! Feel free to check out our latest blog post, itโ€™s about implementing authorization and access control in Flask ๐Ÿ‘‰https://www.cerbos.dev/blog/authorization-in-flask๐Ÿ‘ˆ
    ๐Ÿ‘€ 2
    ๐Ÿ‘ 2
    cerbie 4
    ๐Ÿ‘๐Ÿผ 1
    ๐Ÿ 1
  • a

    Anna Paykina

    02/07/2025, 5:49 PM
    Happy Friday, community ๐Ÿ‘‹ ๐Ÿ˜Š We just published a deep dive into externalized authorization management (EAM). In the blog, we cover: โ€ข what EAM is; โ€ข when you might need it; โ€ข the associated technical benefits; โ€ข along with how to implement it. ๐Ÿ‘‰ Feel free to check out the blog on EAM here ๐Ÿ‘ˆ Have a great weekend!
    ๐Ÿ™Œ 2
    ๐Ÿ˜Š 1
    cerbos 2
  • a

    Anna Paykina

    02/11/2025, 3:46 PM
    hey everyone! :) We just published a blog post, where we explore different approaches to enforcing RBAC and ABAC in an enterprise context. As well as what drives the business need to choose between RBAC and ABAC, the various architectural deployments of these access control methods, and the implications of their selection. If youโ€™re interested, you can find the blog with all the details here
    cerbie 3
    ๐Ÿ™Œ 2
    ๐Ÿ‘ 5
  • a

    Anna Paykina

    02/12/2025, 1:46 PM
    Hey community! We have some exciting news! Cerbos PDP - our open-source authorization solution, just hit 3.6k stars on GitHub! ๐Ÿš€ ๐ŸŽ‰ https://github.com/cerbos/cerbos Thank you all for your support โ˜บ๏ธ๐Ÿ’ช
    cerbie 4
    ๐Ÿ’ช 1
    cerbos 1
    ๐Ÿ… 2
    ๐Ÿ’ซ 2
  • a

    Anna Paykina

    02/17/2025, 1:53 PM
    Hey, <!channel>! ๐Ÿ‘‹ We have a new blog out, where we discuss our journey from using OPA to building our own engine. If youโ€™re interested in the details (as well as understanding why we decided to make that transition, and what benefits we have seen since then) - feel free to check out the piece here
    ๐Ÿ‘€ 2
    ๐Ÿ’ช 2
    cerbie 3
    cerbos 2
    ๐Ÿ‘ 2
  • a

    Anna Paykina

    02/19/2025, 2:02 PM
    Hey <!channel>! Weโ€™ve gotten many questions from our community and customers about securing non-human identities. So we wanted to get into this topic in more detail ๐Ÿ˜Šโฌ‡๏ธ Securing applications is not just about authorizing users based on their identity. Service-to-service calls, external API clients, AI agents, bots, and background jobs all act as independent workloads with their own identities, all requiring access to data and resources. NHIs need to be authorized just like human users. Otherwise, these workloads can become security risks, leading to over-privileged services, unauthorized data exposure, and compliance violations. Here you can learn how Cerbos can be used to secure NHIs ๐Ÿ‘‰ https://www.cerbos.dev/features-benefits-and-use-cases/authorization-non-human-identities
    ๐Ÿ’ช 3
    ๐Ÿš€ 5
    ๐ŸŒŸ 4
    cerbos 4
    ๐Ÿ‘ 2
    ๐Ÿค– 2
    ๐Ÿ’ช๐Ÿป 1
    ๐Ÿ’ช๐Ÿผ 1
    ๐Ÿ‘๐Ÿผ 1
  • a

    Anna Paykina

    02/21/2025, 12:12 PM
    happy Friday, community! ๐Ÿ™‚ We wanted to share our latest blog post with you. We dove into the various certifications for enterprise architects, domain solutions architects, and software engineers, detailing their formats, prerequisites, and associated costs. Although certification doesnโ€™t replace experience - it can be a valuable addition to professional experience for architects. So if youโ€™re interested - feel free to check out the blog post here. Some certifications we cover include: TOGAF 9, ITIL Master, Zachman Framework, AWS Certified Solutions Architect, Google Professional Cloud Architect, and others.
    ๐Ÿ’ก 3
    ๐ŸŒŸ 1
    ๐Ÿ˜Š 2
  • a

    Anna Paykina

    02/24/2025, 4:49 PM
    Hey <!channel>! In our latest blog, we dove into the topic of translating business requirements to authorization policy for HR ๐Ÿ’ก Check it out if youโ€™d like to understand the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible ๐Ÿ‘‰ https://www.cerbos.dev/blog/business-requirements-to-authorization-policy-in-hr-systems
    ๐ŸŒŸ 2
    cerbie 2
    ๐Ÿ™Œ 2
    ๐Ÿ™Œ๐Ÿผ 1
  • a

    Anna Paykina

    02/26/2025, 1:18 PM
    hey <!channel> ๐Ÿ‘‹ We are happy to share that weโ€™ve introduced support for capturing audit decision logs from the Cerbos Hub Embedded Policy Decision Points (ePDP) using the latest version of the Cerbos Javascript SDK ๐ŸŒŸ ๐ŸŽ‰ This feature enables organizations to track and analyze authorization decisions made locally in embedded environments, ensuring complete visibility and auditability, without relying on a centralized PDP or Cerbos Hub. Discover the details here
    ๐ŸŒŸ 3
    ๐Ÿš€ 3
    ๐Ÿ‘€ 1
    ๐Ÿ‘ 2
  • a

    Anna Paykina

    03/04/2025, 5:56 PM
    Hey community! Weโ€™ve just published a blog post about authorization at the edge and itโ€™s benefits โ€ข โœ… Faster response times โ€ข โœ… More reliable access control โ€ข โœ… Reduced load on central servers ๐Ÿ‘‰ Feel free to check it out here ๐Ÿ‘ˆ
    ๐Ÿ‘ 1
    ๐Ÿ’ก 1
    ๐Ÿ’ซ 1
  • g

    GitHub

    03/05/2025, 10:10 AM
    Release - v0.41.0 New release published by github-actions[bot] Cerbos 0.41.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.41.0.html Changelog Features โ€ข bfef008 feat(plan): Use scope value in the query plan (#2485) โ€ข 9bec734 feat: Replace labels with deployments in bundle API v2 (#2483) Enhancements โ€ข 71682d6 enhancement!: Switch to ContextEval to evaluate CEL expressions (#2495) โ€ข 538ab24 enhancement: Correctly set GOMAXPROCS on ECS (#2459) โ€ข 41787ba enhancement: Fail tests with unreachable output expectations (#2418) โ€ข c2f16ff enhancement: Lazy rule table (#2460) โ€ข 131bf5f enhancement: Rule table engine (#2442) โ€ข ecf08cc enhancement: Support bundlev2 (#2395) Bug fixes โ€ข 038719b fix: Add missing policy required for mutable e2e tests (#2502) โ€ข bd3222d fix: Correctly handle defaultPolicyVersion engine config (#2449) โ€ข 8983b99 fix: Correctly handle partial rule table and event subscription (#2455) โ€ข a676fd1 fix: Fall back to default policy version sooner in query planner (#2450) โ€ข 0b80bcb fix: Reload rule table when store contents change (#2452) โ€ข f611ff2 fix: Return validation errors and effective policies in query planner responses (#2447) โ€ข a12fd5c fix: Rule table reload should only purge (#2467) โ€ข 3596a31 fix: Use correct filterDebug type in e2e query planner test (#2448) Documentation โ€ข 73b40e4 docs: Correct examples for math functions (#2445) โ€ข 9096ecb docs: Scope permissions (#2487) โ€ข 1fd792d docs: Update 03_calling-cerbos.adoc of tutorial to use the updated
    /api/check/resources
    endpoint (#2429) โ€ข 4eb7b26 docs: Update what-is-cerbos.adoc tenant ->tenet (#2406) Chores โ€ข 282fe32 chore!: REQUIRE_PARENTAL_CONSENT refinements for resource and principal policies (#2484) โ€ข 31e635e chore!: Role policy deny rows (#2475) โ€ข 24551ba chore(deps): Bump filippo.io/age from 1.2.0 to 1.2.1 (#2423) โ€ข 7a81126 chore(deps): Bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 in /tools (#2491) โ€ข 39242a6 chore(deps): Bump github.com/quic-go/quic-go from 0.48.1 to 0.48.2 in /tools (#2405) โ€ข 3792699 chore(deps): Bump golang.org/x/crypto from 0.29.0 to 0.31.0 in /tools (#2414) โ€ข c03afd6 chore(deps): Remove SQL Server dependencies (#2394) โ€ข 09806c6 chore(deps): Update alecthomas/kong to v1.5.1 (#2404) โ€ข e11f815 chore(deps): Update dawidd6/action-download-artifact action to v7 (#2417) โ€ข 5571a2c chore(deps): Update dependency node to v22.13.0 (#2444) โ€ข 4eda1c7 chore(deps): Update github actions deps (#2427) โ€ข 55dc0c8 chore(deps): Update github actions deps (#2464) โ€ข d6818fa chore(deps): Update github.com/bufbuild/protovalidate-go to 0.8.0 (#2428) โ€ข d0c26dd chore(deps): Update github.com/go-git/go-git/v5 (#2437) โ€ข aa9a573 chore(deps): Update go deps (#2397) โ€ข 915609b chore(deps): Update go deps (#2407) โ€ข 8b6d25e chore(deps): Update go deps (#2415) โ€ข 2660e5e chore(deps): Update go deps (#2431) โ€ข <https://github.com/cerbos/cerbos/cโ€ฆ cerbos/cerbos
    ๐ŸŽ‰ 6
  • a

    Anna Paykina

    03/17/2025, 1:59 PM
    Hey, <!channel>, happy Monday! ๐Ÿš€ We wanted to share about our latest update - Cerbos Prisma Integration v2.0 With our latest update to the reference Prisma Query Plan Adapter, weโ€™ve significantly expanded its capabilities, making it even easier to enforce fine-grained access control within applications using Prisma ORM. Updates include: โ€ข Expanded operator support โ€ข Deep nested relations โ€ข Automatic field inference and type-safe mapping โ€ข Improved collection handling โ€ข Performance optimizations ๐Ÿ‘‰Check out the full blog post for more details &amp; info on how to get started ๐Ÿ‘ˆ
    ๐Ÿ™Œ 3
    ๐Ÿ™Œ๐Ÿผ 1
  • a

    Anna Paykina

    03/21/2025, 3:36 PM
    Hey <!channel> ! ๐Ÿ‘‹ ๐ŸŽฅ We will be hosting a webinar โ€œCloud, SaaS, or self-hosted? Which authentication & authorization deployment model is right for you?โ€ Join to learn about: โ€ข Security & compliance trade-offs across deployment models โ€ข Engineering implications from performance to integration complexity โ€ข Hidden costs & operational risks you might not expect โ€ข How to future-proof your auth stack for scalability & reliability ๐Ÿ“… April 17, 2025 | 5pm CET / 9am PST (recording will be available to all registrants) ๐ŸŽ™๏ธ Speakers: Dan Moore, Principal Product Engineer at FusionAuth & Alex Olivier, CPO at Cerbos ๐Ÿ‘‰ register here ๐Ÿ‘ˆ see you there! โ˜บ๏ธ
    cerbie 5
    ๐Ÿš€ 3
    ๐ŸŽ‰ 4
    ๐Ÿ‘ 3
    ๐Ÿ‘๐Ÿผ 1
  • a

    Anna Paykina

    03/24/2025, 1:07 PM
    Hey everyone! ๐Ÿ˜Š Non-human identities now outnumber human users by 17:1, yet they are one of the most overlooked attack vectors in todayโ€™s systems. Which is why we published a new blog post breaking down the OWASP Top 10 threats to non-human identities (NHIs). We explain what each threat is, real-world examples of breaches, and practical steps to mitigate them. Plus, we show how Cerbos helps enforce least privilege and context-aware access control for NHIs. Feel free to check it out here
    ๐ŸŒŸ 1
    ๐Ÿ’ก 1
    cerbie 1
    ๐Ÿ‘ 1
  • a

    Anna Paykina

    03/25/2025, 1:47 PM
    Hey <!channel>! Weโ€™ve published a blog post where we examine the key elements of compliance that should be prioritized, from data quality and change management to audit logs and access control. We also explore how picking the right authorization system can strengthen your compliance efforts. Feel free to check it out here ๐Ÿ’ก A study by the Ponemon Institute found that, on average, non-compliance costs companies about 2.7 times more than meeting compliance requirements in the first place.
    ๐Ÿ‘ 2
    ๐Ÿ™Œ 1
    ๐Ÿ’ก 2
    ๐Ÿ‘๐Ÿผ 1
    ๐Ÿ™Œ๐Ÿผ 1
  • g

    GitHub

    03/26/2025, 8:12 AM
    Release - v0.42.0 New release published by github-actions[bot] ## Cerbos 0.42.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.42.0.html ## Changelog ### Features โ€ข e3aef93 feat: SPIFFE functions (#2524) ### Enhancements โ€ข 36c7625 enhancement: Stop logging attribute values as JSON-encoded strings in decision logs (#2516) ### Bug fixes โ€ข 8cbeca7 fix: Ensure derived role updates purge rule table caches (#2523) โ€ข 4449609 fix: Evaluate condition blocks correctly in REPL (#2513) โ€ข f1fc31d fix: Purge schema cache on store reload (#2522) โ€ข e4da017 fix: Tidy up rule table trace outputs (#2531) ### Documentation โ€ข 970f7fd docs: Remove symlink to SQL Server schema (#2505) ### Chores โ€ข b7fa780 chore(deps): Bump github.com/containerd/containerd from 1.7.25 to 1.7.27 in /tools (#2520) โ€ข 2658904 chore(deps): Bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 in /tools (#2527) โ€ข ed471a3 chore(deps): Bump github.com/golang-jwt/jwt/v5 from 5.2.1 to 5.2.2 in /tools (#2526) โ€ข 92b5da4 chore(deps): Bump github.com/redis/go-redis/v9 from 9.7.0 to 9.7.3 (#2525) โ€ข b89d3c4 chore(deps): Bump golang.org/x/net from 0.35.0 to 0.36.0 in /api/genpb (#2514) โ€ข 9bff439 chore(deps): Bump golang.org/x/net from 0.35.0 to 0.36.0 in /tools (#2509) โ€ข fc62644 chore(deps): Update go deps (#2507) โ€ข 5c2b5bd chore(deps): Update golangci/golangci-lint-action action to v6.5.1 (#2517) โ€ข e682aeb chore(deps): Update golangci/golangci-lint-action action to v6.5.2 (#2528) โ€ข 0276262 chore(deps): Update node.js deps (#2508) โ€ข 25b8f18 chore(deps): Update pnpm to v10.6.3 (#2518) โ€ข ed90ba0 chore(deps): Update pnpm to v10.6.5 (#2529) โ€ข 5d3167a chore(planner): Switch from CEL protobuf to native types (#2492) โ€ข 4e6d19b chore(release): Add 0.42.0 release notes (#2532) โ€ข 1a5b7c2 chore(release): Prepare release 0.42.0 โ€ข bd70cea chore(version): Bump version to 0.42.0 โ€ข fa4ac36 chore: Add gopls's modernizer to linters (#2515) โ€ข ba15837 chore: Handle empty policies in the parser (#2530) โ€ข 8247248 chore: Handle kind ROLE in trace printer (#2511) cerbos/cerbos
  • a

    Anna Paykina

    03/31/2025, 3:32 PM
    Happy Monday, community! ๐Ÿ˜Š Weโ€™re heading KubeCon 2025 in London! If you will be there - come meet the Cerbos team at ๐Ÿ”บBooth S632๐Ÿ”บ Daniel Maher, Emre Baran, Alex Olivier, and Andrew Haines are looking forward to chatting with you about all things authorization! ๐Ÿ“ข Donโ€™t miss Danโ€™s talk โ€œAuthZ as a Dev Workflow: Architecting Better Cloud Native Appsโ€ Friday April 4, 2025 15:15 - 15:45 BST Level 1 | Hall Entrance S10 | Room C ๐ŸŽ And while youโ€™re at it, feel free to participate in our collab raffle with FusionAuth for a chance to win a TIE Interceptor or X-Wing Starfighter. See you there!
    ๐ŸŒ 2
    cerbie 2
    ๐Ÿ† 1
  • a

    Anna Paykina

    04/03/2025, 2:23 PM
    hey <!channel>! ๐Ÿš€ Weโ€™re happy to share that Cerbos PDP now supports native parsing of SPIFFE identities in authorization policies! This unlocks precise access control for authorizing calls based on non-human identities using the framework be it services, workloads, or any other compute job. This feature introduces a set of Cerbos-specific extensions to the Common Expression Language (CEL) used in policy conditions which understand the structure of a SPIFFE ID such as trust domains, path components, or target the full identity string.
    ๐Ÿ™Œ 1
    cerbos 4
    ๐Ÿ‘ 2
    ๐Ÿš€ 1
    ๐Ÿ™Œ๐Ÿผ 1
    ๐Ÿ‘๐Ÿผ 1
    ๐Ÿค– 1
  • g

    GitHub

    04/07/2025, 12:01 PM
    Release - v0.43.0 New release published by github-actions[bot] ## Cerbos 0.43.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.43.0.html ## Changelog ### Bug fixes โ€ข ff7c199 fix: Maintain derived role mappings during policy updates (#2536) โ€ข 03982ea fix: Purge rule table on index build failure (#2538) ### Chores โ€ข dba785d chore(ci): Make Coveralls upload optional (#2541) โ€ข c1238e0 chore(deps): Update go deps (#2534) โ€ข b0c542e chore(deps): Update go deps (#2540) โ€ข b074c8f chore(deps): update node.js deps (#2535) โ€ข 170a7e8 chore(release): Add 0.43.0 release notes (#2542) โ€ข 69f4f15 chore(release): Prepare release 0.43.0 โ€ข c56621c chore(version): Bump version to 0.43.0 โ€ข 4ae6dac chore: Change logger keys based on bundle version (#2533) cerbos/cerbos
  • a

    Anna Paykina

    04/10/2025, 11:04 AM
    Hey community! ๐Ÿ˜Š As you might have already seen - weโ€™ve introduced several updates that bring new capabilities and improvements to Cerbos ๐Ÿ™Œ With v0.42 and v0.43, weโ€™ve added support for SPIFFE identities in policies, improved the structure of audit logs, and tightened the reliability of policy updates in live environments. Details can be found here
    ๐Ÿ‘ 3
    cerbie 3
    ๐Ÿ’ช 1
  • a

    Anna Paykina

    04/22/2025, 9:31 AM
    Thanks to everyone who joined our webinar on โ€œChoosing the Right Authentication & Authorization Deployment Modelโ€ ๐Ÿฅณ ๐Ÿ“ฉ If you missed the live session, you can get the full recording by submitting the form here. The recording will be sent directly to your email. During the webinar: ๐Ÿ‘‰ Dan Moore FusionAuth and Alex Olivier Cerbos compared self-hosted, cloud-hosted, and SaaS authentication solutions, examining their impact on security, compliance, and operational control ๐Ÿ‘‰ Explored how to align deployment choices with your regulatory requirements and data governance needs ๐Ÿ‘‰ Examined performance implications, integration challenges, and compatibility with teamsโ€™ technical roadmaps ๐Ÿ‘‰ Covered operational risks including reliability, disaster recovery, and vendor lock-inโ€”plus how to mitigate them ๐Ÿ‘‰ Broke down the total cost of ownership, CapEx vs. OpEx considerations, and potential hidden costs More webinars coming very soon!
    cerbie 1
    ๐Ÿ™Œ 1
    ๐ŸŽฅ 1
  • a

    Anna Paykina

    04/25/2025, 9:49 AM
    Hey everyone! Happy Friday! ๐Ÿ˜Š ๐ŸŽ‰ Weโ€™re excited to share some big news: Cerbos has been named Startup of the Year 2024 in Access Control by HackerNoon. This recognition comes after a competitive vote involving 32 companies in our category and nearly 700 community votes. This isnโ€™t just a win for Cerbosโ€”itโ€™s a signal that the tech community is paying serious attention to the problem of authorization. We wouldnโ€™t be here without your support โ˜บ๏ธ_. Whether you voted, contributed to the open-source project, deployed Cerbos in production, or just explored what weโ€™re doingโ€”thank you._ This win is a shared one. Onward ๐Ÿš€
    cerbie 5
    ๐ŸŒŸ 2
    ๐Ÿš€ 3
    ๐Ÿ† 4
    ๐Ÿ™Œ 2
  • a

    Anna Paykina

    04/28/2025, 4:06 PM
    Hey <!channel>! ๐Ÿ‘‹ We would like to invite you to join our upcoming webinar on โ€œMastering authorization in Fintechโ€ ๐Ÿ’ป Edgar Rivera and Daniel "phrawzty" Maher will walk through how to map business requirements of fintech products to authorization logic, accounting for dynamic trading rules, global market windows, and real-time risk assessment. Then theyโ€™ll show how to manage that complexity without cluttering your codebase or making things harder to maintain. โฐ May 6, 2025 at 5pm CEST / 8am PDT ๐Ÿ”— ๐Ÿ‘‰ Register for the webinar here ๐Ÿ“ฉ Recording available for all registrants
    cerbie 4
    ๐Ÿ‘ 1
    ๐ŸŒŸ 2
    ๐Ÿ‘๐Ÿผ 1
    a
    d
    • 3
    • 7
  • a

    Anna Paykina

    05/28/2025, 4:09 PM
    Hey, community! ๐Ÿ˜Š Multi-tenancy in SaaS applications presents a critical challenge: ensuring robust access control that isolates tenant data and operations while maintaining flexibility and scalability. ๐Ÿš€ Weโ€™ve released some new features, which provide a powerful toolkit to define and enforce multi-tenant security effectively. Feel free to check out our blog post on the topic for more details. In it, we: โ€ข Go through key Cerbos concepts: Scopes, role policies, and scoped resource policies with scope permission modes. โ€ข Demonstrate how these features combine to address the multi-tenant access control problem. โ€ข Provide practical policy examples for a hypothetical SaaS HR platform.
    ๐Ÿš€ 2
    ๐Ÿ’ช 2
    cerbie 2
  • a

    Anna Paykina

    05/30/2025, 9:42 AM
    Hey everyone, happy Friday! โ˜บ๏ธ Weโ€™re excited to share our latest success story with you all: โ€œHow Cerbos gave Utility Warehouse control over 4,500 services and millions of NHIsโ€ Utility Warehouse, a FTSE 250 company, faced a growing challenge common in modern infrastructures: managing and securing Non-Human Identities across a vast network of over 4,500 services. As systems scale, NHIs like service accounts and workloads identities can proliferate, leading to overprivileged access and reduced visibility if not properly controlled. By implementing Cerbos, Utility Warehouse transitioned to a true Zero Trust architecture, achieving: ๐Ÿ”น ๐†๐ซ๐š๐ง๐ฎ๐ฅ๐š๐ซ ๐๐‡๐ˆ ๐š๐œ๐œ๐ž๐ฌ๐ฌ ๐œ๐จ๐ง๐ญ๐ซ๐จ๐ฅ. Securing access at every hop within their service mesh, moving beyond perimeter-only trust. ๐Ÿ”น ๐„๐ง๐-๐ญ๐จ-๐ž๐ง๐ ๐ข๐๐ž๐ง๐ญ๐ข๐ญ๐ฒ ๐ฉ๐ซ๐จ๐ฉ๐š๐ ๐š๐ญ๐ข๐จ๐ง. Ensuring user identity and intent are maintained throughout the service chain for full-context authorization. ๐Ÿ”น ๐’๐œ๐š๐ฅ๐š๐›๐ฅ๐ž & ๐ฌ๐ญ๐š๐ญ๐ž๐ฅ๐ž๐ฌ๐ฌ ๐ฉ๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ. Efficiently managing millions of authorization decisions daily across their extensive service landscape. ๐Ÿ”น ๐‚๐จ๐ฆ๐ฉ๐ซ๐ž๐ก๐ž๐ง๐ฌ๐ข๐ฏ๐ž ๐š๐ฎ๐๐ข๐ญ & ๐จ๐›๐ฌ๐ž๐ซ๐ฏ๐š๐›๐ข๐ฅ๐ข๐ญ๐ฒ. Leveraging integrated audit logging for enhanced threat detection and compliance. This strategic implementation not only bolstered their security posture but also streamlined operations, reclaiming significant development time. Kudos Rob Crowe and the Utility Warehouse team for their forward-thinking approach to securing NHIs at scale!
    ๐Ÿ‘ 2
    ๐ŸŒŸ 2
    ๐Ÿš€ 3
    ๐Ÿ™Œ 2
  • g

    GitHub

    06/03/2025, 6:39 AM
    Release - v0.44.0 New release published by github-actions[bot] ## Cerbos 0.44.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.44.0.html ## Changelog ### Features โ€ข b383622 feat(audit): Add size-based batch limiting to audit log hub (#2558) โ€ข 350d52c feat(plan): Add support for multiple actions (#2543) โ€ข ff44bd4 feat: Add principal policy support to rule table (#2544) โ€ข 44e21fb feat: Cerbosctl commands to interact with Hub store (#2569) ### Enhancements โ€ข 666976c enhancement!: Remove bundle version configuration parameter (#2583) โ€ข 386230a enhancement(helm): Update helm charts to support bundle v2 (#2580) โ€ข a2b376b enhancement: Simplify plan with exists operation (#2570) ### Bug fixes โ€ข 42fd48b fix(helm): Set correct environment variable to configure traces sampler (#2551) โ€ข 86428c7 fix(plan): Preserve action field for auditing (#2564) โ€ข 861bb1d fix: Return appropriate backoff in logcap ingest error path (#2549) ### Documentation โ€ข 314535a docs: Add talk to engineer link (#2573) ### Chores โ€ข 380d8f6 chore(ci): Don't bother caching dependencies for
    upload-test-times
    job (#2557) โ€ข d4e6db6 chore(ci): Upgrade Helm and Helmfile (#2586) โ€ข 73d0e25 chore(deps)!: Update module github.com/cenkalti/backoff/v4 to v5 (#2555) โ€ข db07dcb chore(deps): Bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 (#2563) โ€ข aedf313 chore(deps): Bump golang.org/x/net from 0.37.0 to 0.38.0 in /api/genpb (#2559) โ€ข e5ad74e chore(deps): Bump helm.sh/helm/v3 from 3.16.4 to 3.17.3 in /tools (#2545) โ€ข 1e6d83c chore(deps): Update dawidd6/action-download-artifact action to v10 (#2585) โ€ข 61ba507 chore(deps): Update dawidd6/action-download-artifact action to v9 (#2548) โ€ข 39c082b chore(deps): Update extractions/setup-just action to v3 (#2552) โ€ข 44b2b26 chore(deps): Update go deps (#2547) โ€ข 97f9326 chore(deps): Update go deps (#2565) โ€ข b04997c chore(deps): Update go deps (#2571) โ€ข e7cbf2d chore(deps): Update go deps (#2576) โ€ข 1fa3df6 chore(deps): Update go deps (#2581) โ€ข 672f97e chore(deps): Update go deps (#2584) โ€ข 53314ec chore(deps): Update golangci/golangci-lint-action action to v7.0.1 (#2566) โ€ข efca0ba chore(deps): Update module helm.sh/helm/v3 to v3.17.3 [security] (#2546) โ€ข 537dc04 chore(deps): Update modules github.com/lestrrat-go/jwx and github.com/vektra/mockery to v3 (major) (#2553) โ€ข 0e39c79 chore(deps): Update node.js deps (#2562) โ€ข 5e2be4d chore(deps): Update node.js deps (#2575) โ€ข d89540e chore(deps): Update node.js deps (#2582) โ€ข 293307a chore(deps): Update pnpm to v10.10.0 (#2572) โ€ข e657267 chore(deps): Update sigstore/cosign-installer action to v3.8.2 (#2561) โ€ข 4b7b60c chore(deps): update go deps (#2560) โ€ข ccf551a chore(deps): update module github.com/golangci/golangci-lint to v2 (#2556) โ€ข c35ae86 chore(deps): update node.js deps (#2539) โ€ข 9508a38 chore(docs): Fix how less than or equal operator is displayed (<https://github.com/cerbosโ€ฆ cerbos/cerbos
  • a

    Anna Paykina

    06/05/2025, 2:26 PM
    Hey, <!channel>! ๐ŸŽ‰ ๐Ÿ“– Weโ€™re excited to share our new ebook โ€œSecuring Non-Human Identities in enterprise systemsโ€ This ebook breaks down: โ€ข NHI taxonomy โ€ข 20 NHI and AI agent risk vectors you need to know โ€ข 12 security principles and 35 actionable steps for NHI governance โ€ข Insights from NHI breaches (Okta, GitHub, and Microsoft) โ€ข Expert opinions from CISOs, security architects, and EMs working on IAM programs that include NHI security โ€ข A vendor landscape and evaluation checklist to guide your implementation strategy Itโ€™s actionable and built from real-world experience, designed to help IAM teams address the blind spots, over-permissioning, and security gaps that often come with AI agents, microservices, and automated workloads. Feel free to read the ebook and let us know what you think!
    ๐ŸŒŸ 1
    ๐Ÿ“š 1
    ๐Ÿ™Œ 1
    ๐Ÿ‘ 1