1 of 14

www.gluu.org

#GluuFederation

Intro to the Cedarling

www.gluu.org

#GluuFederation

2 of 14

Also see Cedar team blogs Why Cedar and How we built Cedar

From Emina Torlak AWS re:Invent 2022 presentation

  • Ergonomic syntax
  • Fast and Safe
  • Powerful static analysis tools

RBAC

Rego

www.gluu.org

#GluuFederation

3 of 14

RBAC (fast) + ABAC (slow)

From Emina Torlak AWS re:Invent 2022 presentation

www.gluu.org

#GluuFederation

4 of 14

Safe

Graph

Rego

Cedar

RBAC

Edge

Ergonomic�Syntax

Expressive

Cedar versus…

www.gluu.org

#GluuFederation

5 of 14

Cedarling Anatomy

www.gluu.org

#GluuFederation

6 of 14

Browser / Mobile / Cloud

www.gluu.org

#GluuFederation

7 of 14

Why use Cedarling to validate JWTs?

www.gluu.org

#GluuFederation

8 of 14

Enterprise

Application

Security

Developers

DevOps

End

User

Architect

Auditor

www.gluu.org

#GluuFederation

9 of 14

Developers want

  1. Build better security UX

  • Basic understanding of JWTs is enough�
  • Free software for their chosen language / platform

Developers

www.gluu.org

#GluuFederation

10 of 14

Auditors needs

  • Catalog / govern all policies

  • Gather evidence of policy decisions�
  • Tools for forensic analysis

Auditor

www.gluu.org

#GluuFederation

11 of 14

Cloud Engineers want…

  • Cloud native deployment�
  • Centralized logging�
  • Automated key management�
  • Bandwidth efficiency

DevOps

www.gluu.org

#GluuFederation

12 of 14

Architects want…

  • Externalized policies�
  • Open standards�
  • Flexibility to write policies for any applications�
  • Real time response capability

Architect

www.gluu.org

#GluuFederation

13 of 14

End Users want

  • Great UX�
  • Confidence they’re not getting scammed (safety)

End

User

www.gluu.org

#GluuFederation

14 of 14

Digital Chain of Custody

  • Person with unique passkey
  • Cryptographically unique workload identities
  • Trusted delivery of Policy Store to a specific Cedarling instance
  • Audit log of all policies Allowed or Denied by all Cedarlings

www.gluu.org

#GluuFederation