Loading…
June 26-27, 2024 | Seattle, WA
View More Details | Registration Information

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for CloudNativeSecurityCon North America 2024 to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Daylight Time (PDT), UTC -7. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

The schedule is subject to change.
Thursday June 27, 2024 1:55pm - 2:30pm PDT
435
When we built the open source supply chain security platform, Minder, we initially wrote our own database-backed authorization implementation, with the concepts of users, roles, organizations, and groups. This was a lot of code that distracted from our core mission of securing software repositories, but it was critical to get right in a multi-tenant service. In this talk, we’ll explain how we replaced that code with OpenFGA, an open source authorization solution, to implement hierarchical permissions and project relationships. We’ll show how we used OpenFGA’s modeling language to write and test our permissions model, using middleware to perform the authorization check, and additional work you may need to do outside of OpenFGA to better connect with your own identity providers. At the end of this talk, you’ll know enough to decide if OpenFGA is right for you.
Speakers
avatar for Evan Anderson

Evan Anderson

Software Engineer, Stacklok
Co-founder and maintainer on Knative project. Member of sigstore-oncall. Previously worked on Google Compute Engine and Serverless (App Engine, Functions) and in SRE. Principal engineer at Stacklok. Ex-Google, ex-VMware. Author of Building Serverless Applications on Knative by O'Reilly... Read More →
avatar for María Inés Parnisari

María Inés Parnisari

Senior Software Engineer, Okta
Maria is a software engineer specializing in backends running in the cloud. She is based in Canada.
Thursday June 27, 2024 1:55pm - 2:30pm PDT
435
Feedback form is now closed.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link