hey <!channel>!
π Weβre happy to share that
Cerbos PDP now supports native parsing of SPIFFE identities in authorization policies!
This unlocks precise access control for authorizing calls based on non-human identities using the framework be it services, workloads, or any other compute job.
This feature introduces a set of Cerbos-specific extensions to the Common Expression Language (CEL) used in policy conditions which understand the structure of a SPIFFE ID such as trust domains, path components, or target the full identity string.