authz
topaz
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
authz
- Authorization back end that comes with a front end
- Authorization back end that comes with a UI for RBAC and ABAC
- Authz: A centralized authorization back end with its front end
-
AWS Cognito - Am I doing this right?
There are auth systems like ory.sh and https://github.com/eko/authz and many other open source that are a lot better.
- authz: Authorization backend that comes with a UI for RBAC and ABAC permissions
- Authorization back end that comes with a UI for RBAC and ABAC permissions
- Authz: Authorization back end that comes with a UI for RBAC and ABAC permissions
topaz
-
Open Policy Agent
OPA is a great tool for implementing a policy-as-code system. But if you're trying to use it for application authorization (e.g. fine-grained authz for B2B SaaS or a set of internal applications), you may find that its policy story is strong, but it doesn't really have a "data plane": you either store data in a data.json file and rebuild the policy any time that data changes, or make an http.send call out of the policy to fetch dynamic data.
Check out Topaz [0], which uses OPA as its decision engine, but adds a data plane that is based on the ReBAC ideas explored in the Google Zanzibar [1] paper.
Disclaimer: I work on the team [2] that builds and maintains the Topaz project.
[0] https://www.topaz.sh
[1] https://research.google/pubs/zanzibar-googles-consistent-glo...
[2] https://www.aserto.com
-
Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar
You can, simply use the topazd.exe binary from the topaz_windows_x86_64.zip from the GH releases page (https://github.com/aserto-dev/topaz/releases). Note this is currently not a Windows Service, so not net start topaz. Let me know if that would be interesting.
-
OPA (Open Policy Agent) VS topaz - a user suggested alternative
2 projects | 25 Jul 2023
Topaz is an open-source authorization project for cloud-native applications. It uses OPA as the decision engine and supports Rego policy as first-class citizens. It also has an embedded relationship database to support data-centric authorization models like Google Zanzibar's relationship-based access controls (ReBAC).
- Topaz
- Show HN: Topaz: open-source authorization combining the best of OPA and Zanzibar
What are some alternatives?
qbee-agent - Device agent component of the qbee.io IoT device management platform.
openfga - A high performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar
policy-enforcer - Represent your rego rules programmatically.
permify - Open source authorization service inspired by Google Zanzibar to build fine-grained and scalable authorization systems.
casbin - An authorization library that supports access control models like ACL, RBAC, ABAC in Golang: https://discord.gg/S5UjpzGZjN
DSP-Shared_Collection
warrant - Warrant is a highly scalable, centralized authorization service based on Google Zanzibar, used for defining, querying, and auditing application authorization models and access control rules.
spicedb - Open Source, Google Zanzibar-inspired permissions database to enable fine-grained access control for customer applications
awesome-auth - 📊 Software and Libraries for Authentication & Authorization & SSO & IAM
ASP.NET Identity
casbin-server - Casbin as a Service (CaaS)
IAmRoot NuGet Package - 📦🏴☠️ NuGet package that shows we can run arbitrary code from any NuGet package