TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Cedar policy language is now open source

99 点作者 hakejam大约 2 年前

8 条评论

mjb大约 2 年前
One angle on this I&#x27;m particularly excited about is the formal methods&#x2F;automated reasoning work the team did on Cedar: <a href="https:&#x2F;&#x2F;www.amazon.science&#x2F;blog&#x2F;how-we-built-cedar-with-automated-reasoning-and-differential-testing" rel="nofollow">https:&#x2F;&#x2F;www.amazon.science&#x2F;blog&#x2F;how-we-built-cedar-with-auto...</a><p>&quot;We want to assure developers that Cedar’s authorization decisions will be correct. To provide that assurance, we follow a two-part process we call verification-guided development when we’re working on Cedar. First, we use automated reasoning to prove important correctness properties about formal models of Cedar’s components. Second, we use differential random testing to show that the models match the production code.&quot;
评论 #35891347 未加载
jzelinskie大约 2 年前
Congratulations on the OSS launch! Was it always in the cards to open source Cedar?<p>I&#x27;m excited to see you&#x27;ve found a way to bring verification that exists in non-policy-based authorization solutions to Cedar. Was that functionality the driving factor that made the team create something new instead of leveraging the widely adopted Rego&#x2F;OPA[0] stack for policy?<p>It looks like this talk[1] briefly covers why you made Cedar, but I&#x27;d be eager to hear more about the trade-offs in design, because other policy languages are leveraging decades of formal research on Datalog.<p>Disclosure: I work on SpiceDB[2], an authorization database inspired by Google&#x27;s Zanzibar system[3], but I wouldn&#x27;t say Cedar is directly competitive as SpiceDB is not a policy-based system.<p>[0]: <a href="https:&#x2F;&#x2F;www.openpolicyagent.org&#x2F;docs&#x2F;latest&#x2F;policy-language&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.openpolicyagent.org&#x2F;docs&#x2F;latest&#x2F;policy-language&#x2F;</a><p>[1]: <a href="https:&#x2F;&#x2F;youtu.be&#x2F;k6pPcnLuOXY?t=2037" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;k6pPcnLuOXY?t=2037</a><p>[2]: <a href="https:&#x2F;&#x2F;github.com&#x2F;authzed&#x2F;spicedb">https:&#x2F;&#x2F;github.com&#x2F;authzed&#x2F;spicedb</a><p>[3]: <a href="https:&#x2F;&#x2F;zanzibar.tech" rel="nofollow">https:&#x2F;&#x2F;zanzibar.tech</a>
评论 #35892325 未加载
dang大约 2 年前
Related:<p><i>AWS Creates New Policy-Based Access Control Language Cedar</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34865768" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34865768</a> - Feb 2023 (83 comments)<p><i>Cedar: A New Policy Language</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34449828" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34449828</a> - Jan 2023 (3 comments)
flurie大约 2 年前
I tried Cedar out for a small research project when it was first announced, and it felt incredibly clumsy compared to what I could have done in OPA. That was probably 8-9 months ago, so things may have changed.
评论 #35895001 未加载
aseipp大约 2 年前
Really exciting to see this and the recent renewed interest in more expressive ACL systems re: policy and (alternatively) relational access control.<p>The pedigree of Cedar is also really interesting to me, coming from the angle that Torlak was previously part of the UNSAT group @ Washington, and was the developer of Rosette. I was hoping there might be a semantic description of Cedar using Rosette as well! Maybe writing one would be a good challenge...
efitz大约 2 年前
Why do all the web pages have Amazon copyright footers?
评论 #35893992 未加载
sakesun大约 2 年前
The website is neat.
stev678923大约 2 年前
Great website— its my favorite part!