Or Weis, Permit.io | KubeCon + CloudNativeCon Europe 2023
Alan and Or discuss how Permit.io builds permissions with accessible interfaces. Or also emphasizes the danger of building authorization into software from scratch.
Transcript
This is texturing TV. Hey everyone, it's me. Alan Schimmel from text drunk back here live in kubecon.
Kind of at the beach. It's really sunny here. So I'm going with my sunglasses.
So I don't squint. Um, I took the sun seat my friend or Weiss here. I gave him a seat in the shade.
He's kind of made in the shade. You took one for the team. I took one for the team like I'm supposed to or welcome.
How are you? I'm great. It's good to be here cubecon is Lively and with some awesome people buzzing with 10,000 people here.
Yeah, so or you know what we should start off with this is our Weiss from a company called permit permanent, Iowa. Why don't you give him a little bit of the ore and permit story? Yeah.
So permanent is really about building permissions into your product. If you ever use software, you probably notice that in every software you need to decide who can do what and you need these interfaces that control how people and system connect what you've built so not along if you ever seen or use any of these user management with the Digital sign roles API Key Management Secrets management audit logs approval flows emergency access invites and this let's just goes on and on it's something that you have to have in every piece of software, but you really shouldn't be building it yourself just like you don't build authentication just you've done you don't build encryption on your own. It's dangerous to build authorization on your own.
So we provided ready off the shelf you embedded into your software and it's it comes with easy to use interfaces that even a monkey can use or is even say a product manager if they're smart enough it generates policy for you. Okay, but anyway product managers are the ones that love their joke the most ironically so permit generates policies for you is policy is code pushes into a good repository but makes it all is right and easy to use interface as part of your system so you can focus on your core features. io.
Okay, or we got that out of the way. What's new? What's new with permit?
What's new with some Market that you see so actually I want to talk about the market. What we're seeing is just like as authentication got standardized and had other players coming into the space and having the space mature. We're seeing this happening now very quickly with authorization.
So we already have companies like us like permit kind of leading the charge but we're seeing other companies the cloud vendors Microsoft and AWS coming in with their own policy languages and their own ways to try and standardize the space and that's something that I'm very excited about because it's not just about having a specific solution or specific implementation. It's how we as a whole Community how we decide how we manage access and how we build secure applications together and the other players kind of recognizing this recognizing what we're building in chiming in is something that I think is very exciting. It's going to dramatically accelerate the space one maybe Going to mention is what AWS is doing so they're launching a new service called AVP Amazon verified permissions that comes with its own policy language called Cedar.
Which is kind of like Opa like all Rego and open policy agent. So they're coming off their own language and here at Fairmount. We're already looking at that and now we as just like we support open support our policy languages where language agnostic and we want to work with those new languages and this new polyglot but standardized ecosystem that it is emerging.
I find it very very exciting. very cool Um, you know, the thing sometimes with AWS is they'll introduce something like this and some people will say well I don't need a standalone solution. You know, and I'm not banging AWS at all here, but generally their Solutions.
They're not as full featured as a standalone. Let's say there are very hard to consume off more often. They're not they are so that's why I'm more excited not about a specific solution here, but the maturity of the ecosystem they recognize their recognition that everyone needs a solution like this and we should have different building blocks that we can consume together and agree on in a standardized fashion.
So one of the key things that we bring with permit as I mentioned these these interfaces these policy as code interfaces that generate code for you. So those will allow you to consume services like AWS or any other solution the space without having to go deep into the Reed. So this is the standard standards being formed being adopted and solutions like hours to help everyone to consume them and build them build them into their software and the end result is very software more secure software more easily consumable software.
For everyone absolutely, you know. you mentioned this whole standard thing and I think that that is kind of tied into like the core of yes the ncf and Linux foundation and the whole open source movement is it's when you when you can build a a common framework a common standard right a common way of Communicating of interacting it allows companies like a permit to come in on top of that. Excuse me, and maybe not worry about the foundational Plumbing if you will, but build on higher.
Yeah functionality. So you're spot on so we ferment we we had to build some of the infrastructure components on our own because they didn't exist, but we would have much more better preferred if the ecosystem was more maturing can just latch on into existing blood goals within systems, but thing is those are still maturing we decided to expedite that both my creating open source ourselves. So we created an open source project called opal open policy and administration later, which is at this point.
It's kind of the defective way to use Opa to use open policy agent in scale. So opal loads the policy directly from kids and the day that you need from wherever you have it Direct. Into your policy agents in real time.
And that's also the connecting block that we have with the other services with what AWS is building before other players are in our Cloud vendors are building as well. And it's how we can seamlessly connect with other players. And also how we create part of the standards that help the space accelerate.
So I'm really excited about what the cncf is leading and how we participate in that by the adoption of all opal and other policy engines and other Solutions the existence of space. I love it. Yeah.
What else you think is we sit here with 10,000 people around us. I think it's first of all, it's great to see kubecon coming back to its Glory Days. I can think of prepandemic times where we had conferences like this and the previous ones were a bit of a letdown I have to say, but seeing how people here running around interacting with all of these companies and having this amount of people again, it's kind of gives me hope that we can regain those Glory Days that we had in the past and I'm also very excited about interacting with all these people I'm excited about the questions being asked I'm excited to see that little Sparkle and developers eyes as they're talking about embedding the what real building and whatever vendors are bringing here into their software and and it's just it's hardwarming to see cool.
Or thank you for coming in coming. It's stopping and always my friend or wife's permit dot IO check it out. We're live here.
We'll take a break. We'll be back. Hopefully this Sun Passes over.
Bye. Bye everyone.





