Innovations in Cloud Native Authorization | KubeCon SLC 2024
Transcript
This is Textron tv. Hey, everyone. Good.
Well, good morning, good afternoon. Depends when you're watching this, I guess. Good evening.
Uh, we're, we're here at Q Con wrapping up our final day of coverage. Really happy to have my friend Ri gaze. Gazi.
Yeah, Gazi. How do you pronounce Gazi? Yeah, Gazi.
So I know Armory. I don't know, three, four companies already. Right, right.
But he's been with, he's co-founded CEO of his last company. Now, what, three years? Four years?
Uh, It's four years now. Yeah. Four Years.
Yeah. Four, four years This month. And, uh, that's, I think I interviewed you at a, a cube con right when you were launching.
Indeed. Exactly. Yeah.
Funny stuff. Anyway, AMRI, thanks for coming here. Welcome.
Thank you. Alan. Why don't we start with, I said, I've known you through several companies.
You've had quite the career. Get without, I don't wanna embarrass you, but give him an idea of your career path. Well, let's see.
Uh, I started my career as an engineer, uh, and I was fortunate enough to be the founding engineer of a startup that went public early nineties to late nineties. I call that my rose color tour through stardom. Right.
It's like winning at the casino the first. Exactly. That's right.
I thought it was good, but And you're gonna win the time. Right, exactly. It's all good.
net and later on, uh, be the general manager for the app server business and, uh, anticipated the Azure, uh, wave. So I helped start that and, uh, was the general manager for App Server, app Fabric. And then, uh, you know, also what became Azure Active Directory, including the access control server.
So that's kind of where I got my, uh, taste for identity and access. Yep. Then when I left, uh, evil Empire spent 12 years working on open source.
So, uh, OpenStack, uh, I was, uh, uh, board of directors of the Cloud Foundry Foundation later on, worked on Kubernetes, uh, and most recently as Puppet as well, yeah. CPO of Puppet. So I remember, and that was when Puppet was Puppet.
It Was Puppet. Yeah. It was Puppet.
Exactly. It was DevOps. So, excellent.
I mean, look, it's quite a new list of accomplishments, but you Aperto, how do you pronounce the company? Uh, AER Aer Yeah. Excuse me.
A assert, as we said, we started four years ago. Mm-Hmm. Let's assume these people have never heard of it.
They don't know what's a Certo. A CERTO is an authorization platform. So if you think about, you know, what Auth Zero did for authentication, make it so that developers don't ever have to think about writing login again.
Erdos mission is to make that for authorization. And the difference is authentication is proving that user is who they say they are. You know, used to be passwords, now it's biometrics and pasties and match links.
We, and all sorts of things like that. Yep. Authorization hasn't really moved forward, you know, like authentication solved, problem authorization, not so authorization is what can you do once you log in?
Right. Right. Like, what permissions do you have?
What roles do you have? Uh, and that problem hasn't been solved for developers, and that's what we're trying to do. Yeah.
I, I think for too much we've said, oh, well, let's go zero trust. And that's great. It's probably safer to be zero trust than not, but as they say in Las Vegas, that's a fine beginning.
Where do you go? Okay, so now you've got zero trust. I don't give you access to anything now based upon you did authorize as you Mm-Hmm.
But where do we let you go? You know, so we gotta unlock some gates. Yeah.
So, and that's really a way of looking at it, right? Right. I mean, zero trust is all about defense in depth.
Right. So, so far people, you know, authenticate, then they put some scopes and access tokens and think of that as permissions. Right.
That, that's called hope. And hope is not a strategy. No.
Right? No. So what You really want, what we call modern or cloud native authorization is what we call fine-grained policy based in real time fine-grained, meaning you're not just like a viewer on a tenant or an admin on a tenant.
You are a viewer of this particular resource of this document inside of this particular system. It's gotta be fine-grained. That's the principle of lease privilege.
That's a cornerstone. Exactly. Zero choice.
Then policy based is the idea of, you know, rather than putting all of these authorization calls and as if, or switch statements inside of the application, we call this authorization spaghetti logic. Right. Extract that and express it as a policy.
And you are able to treat that as code policy, as code, just like puppet pioneer configuration as code infras, and then Terra Terraform infrastructures code. We now have policy as code. And then the last point, the real time point is super important too.
Like I said, permissions in an access token, that's not authorization. Instead, you need to make a real time call to find out whether this user has this permission on this resource. And that's what's called real time authorization.
So taken together cloud native authorization, fine grade, policy based real time. I love it. That's excellent.
You've probably said this once or twice before, but that was an excellent explanation. That Was that me my second time? No.
Yeah. But I, I think, I think that it'll resonate with people. So you guys are here.
What, what was news for you at, at CubeCon this year? Yeah, so I would say in the last few cube coupons, it was, you know, I either got zero or one talks, right? Like, it was hard to get people to really, you know, think about authorization as a hot topic.
I got three really this coupon. Good for you. What does that tell you?
It tells you that people are finally interested in cloud native authorization. It's about to hit, you know, kind of like the, the hockey stick of awareness that we will, you know, then lead to adoption. I Hope So.
I think part of that army, quite frankly is, you know, you made it like it's a fat of complete Mm-Hmm. Around just pure identity. It's not, yeah.
You know, I know a lot of people who they absolutely hate two factor authentication. Mm-Hmm. They, you know, they, they, they're just coming along to biometrics.
Mm-Hmm. Passkey. Look, I got Google, the Google Passkey, uh, token things, not token.
The, uh, you know, the, like the fobs Yeah. Yep. Sitting in my drawer.
I don't use them. I got news. I do use pads, keys, authenticator on my phones and stuff, but, but I'm, I'm geeky.
I think that that's, I'm not the mainstream in this market. I don't, I think we're just at the cusp of saying, all right, we've got, we've got something in place here. Now let's look at authorization.
I agree. And I think, you know, people that focus only on authentication, they're still focused on the perimeter. Yeah.
You know, in the sense that, okay, you know, like, I'm gonna try my best for this identity not to be compromised. Turns out identities will absolutely be compromised. It's just a fact of life.
And now you have to think about limiting the blast radius of what a compromised identity can actually do within your system. And that's all about authorization, modernize your authorization. That's the key to actually controlling all this craziness that's going on in terms of breaches and the blast radius of breaches.
I agree. I agree. A hundred percent ex excellent stuff.
And again, it is tied up in the zero trust, the defense and depth. Mm-Hmm. You know, and, and just limiting that.
Um, how has the show been at, like, when people coming by? The conversations you're having with people? Yeah.
Yeah. I mean, it's been great. We have an open source project called Topaz that we launched Oh, okay.
Years ago. I Remember. And it's been blown up.
I mean, we've doubled the number of stars of the last year. We've had a lot of new adopters, people like Roblox, people like open systems, you know, people like Right. Data, um, you know, a bunch of folks that, you know, onic, like big companies, small companies are all adopting it.
And it's winning because I like to say it's fast, it's flexible, and it's easy to integrate by fast. I mean, it's literally the fastest authorization system on the market authorized in one millisecond or less, or your money's back. Okay.
It's like Billy, what's his name? That's right. Flexible.
You know, it does rback, but is more, There's more, right. It does Rback, abac, Reback, all the backs as we like to say. Yeah.
And you know, like, without getting too technical, I would say that abac and Reback are the two contending fine-grained authorization models. What we've done is an elegant merger. So you don't have to pick between something like opa, which is an ABAC system or something like Zanzibar, which is a reback system.
We've put them together in a single package. That's what people love. And then easy to integrate, you know, it's, it's, it's five minutes, right?
We have SDKs in every language. We have GRPC, APIs, rest APIs, GraphQL APIs. It's by far the easiest system to integrate on the market.
And so that's why we see it getting adopted. And of course, that's leading to some financial success for a company too. I would say Q4, this, uh, this quarter will be the best quarter the company's ever seen.
I Hope so. That's great, man. I'm, I, you should be for people out here who say, oh, you know, this sounds interesting, something I want to give a try.
Kinda what's the on-ramp look like? So it's as easy as, you know, doing a brew install on Topaz, which is our CLI. And then, you know, the CLI makes it real easy to spin up a Topaz container on your system.
Let's A real remedial, where should they go first? Oh, course to download, of course. I get all this course.
Www dot topaz sh that's the site, that's the micro site. com to find out more about the commercial offerings around Topaz and how to basically take Topaz and systematize it, scale it across your environment. If you have many users, like you're a multi-tenant SaaS company that you know, has many tenants, or if you have, uh, you're in an enterprise and you have many applications that you're trying to standardize the authorization for, uh, you know, our commercial solutions basically have a multi-tenant authorized or multi-tenant directory, you know, decision logs and, uh, collection and compliance and uh, and, you know, uh, for, for forensics and compliance and so on.
Sure. So all of the things that you need to, you know, really kind of roll out, uh, a topaz based infrastructure for your entire environment. I love it.
Mention the site again. It's Topaz sh you said correct. Topaz.
Sh That's T-O-P-A-Z. That is exactly right. That's All right.
I just wanted to make sure. Um, I do have, uh, you know, one other thing that I'm super excited about this show, look In here. It's awesome.
That's right. So as of yesterday, we now have the first implementers draft of the Open ID off Zen specification. So let me, let me unpack what all that is.
So, um, everyone knows what Open ID connect is right at this point, right? So that is the thing that allows everybody to log in, in the same way. It's the thing that allows single sign on for large companies.
When you log into like, let's say Salesforce or ServiceNow through your Okta, that is all enabled by Open Id Connect, which is the standard, the Lingua Franco for how you log into websites. And what we are now doing with Open ID Auth Zen, which is the newest working group from Open id. So trying to do for authorization what Connect did for authentication, right?
So Auth Zen is through authorization. What OIDC is for login, and we're a year in, we find we have our first implementers draft. We have 14 interoperable implementations about to become, uh, around 20.
And we'll basically get the entire authorization industry to adopt a single specification, a single API, and that will unlock all of, you know, kind of like this idea of externalized authorization or cloud native authorization. It'll finally be easier for a developer to target an externalized author authorization system than to build it all. Kinda Like federated identity Was Exactly.
Years ago. Exactly. So, super excited about that.
I'm one of the co-chairs of the Open id Zen working group. So that's, you know, putting my other hat on. And you know, this, uh, I gave a talk, uh, uh, a couple days ago, actually on Wednesday packed packed house.
And everybody's super excited about it. They were fi they were like, this is finally the thing that we need to get all our enterprises Exactly. To authorize consistently.
So we're very excited about that. We're, you know, obviously a Certo and Topaz are one of the first, uh, companies to build Zen into our products, but we expect everybody else will. It'll be a standard.
I'd expect nothing less from you, my friend. Good for you. Thank For you.
Thank you so much. Always good. We had To do that.
A Gaza, I mean, this guy, you heard his background. He's been involved in some incredible, incredible things in, in the tech world, in open source and what he's doing here with a certo and, and, and the open source piece of it as well. Topaz.
And, and this overnight d it's about to pop. You heard it here on Tech Drunk tv. Keep your eye on this.
We're gonna take a break. We're wrapping up here in, uh, salt Lake City. We'll be back in a bit.