Omri Gazitt, Aserto | KubeCon + CloudNativeCon NA 2022
Omri Gazitt, co-founder and CEO of Aserto, joins Alan Shimel at KubeCon to discuss Aserto’s authorization-as-a-service solution.
Transcript
This is texturing TV. Hey everyone. We're back here live on the show floor at kubecon cloud nativecon in Detroit.
It's actually pretty busy out here right now. I guess maybe it's a break in the sessions. Um, I am joined by a long time friend of mine.
I haven't had him on video in certainly before covid but a while let me introduce you to Armory Gizzy Armory. Welcome great to be here. Thank you, and it's been a minute and it has been a little more than a New York minute as we say Armory.
I'm not gonna embarrass you, but I got you. Before we start talking about armories with a company now called the cerdo and we're going to jump into it. But I want you to understand a little bit about who this fellow is and what he's done and why I have a ton of respect for him.
And I you know, I enjoy having him as a friend. Army give them. Tell them you the Armory because it's good started on a cold winter night.
That's right exactly over 30 years ago, you know building software for Developers for about 30 years, you know did a startup and that went public that was my rose color two or three star of them back in the 90s and then join Microsoft and helped, you know was one of the first dozen people on net so was a co-founder of that project and we're co-founder of the Azure project. We worked on access control and Azure active directory. So those are my roots and identity and access and you know ran Cloud engineering at HP and most recently the chief product officer puppet.
Yep, so it's pretty impressive. Story, you know, that's just what he's done in work and the rest of his life. But anyway Armory you're now with assertive.
I I'm gonna assume a lot of folks out here are it's a new name for them a new company. Yep. Why don't we, you know, give them a little background?
Yeah. So, you know, we really kind of the story starts 15 years ago back when I was at Microsoft and we were thinking about what was gonna happen to Identity and access in the age of SAS and Cloud, right? Well, you know fast forward 15 years identity moved to the cloud so you have oauth two and open Eddie connect and Samuel and John and you have companies like I'll see hero and OCTA and a bunch of others that have made it so that no one has to go build authentication anymore.
If you don't want to right it's all standards based. It's all cloud-based access the access part of identity and access didn't move forward at all has a move forward at all in the last 15 years and so my co-founder and I who work together on what became Azure active directory decided to go focus on that problem and really solve that problem and that problem is an even bigger than the problem of identity. Absolutely you mentioned active directory look You know, there was a time in the world where Microsoft used to get banged on for being a monopoly maybe with Windows, but the fact of the matter was the real Monopoly was active directory active directory had become the defacto standard for directory Services which identity and access that's right.
Right and we because you didn't have a cloud. Yep, right. We had 95% market share of you and my boss Bob Marley who used to run the server and tools division president of service division.
He used to call it the lynchpin workload for the Windows Server franchise. It was how important it was. It was it was that important.
I mean, again Those not my age or even armory's age. Right, there was it there was a time where a company called novel started something called ldap. That's right.
And I'll dap was very much the that was like the first director. Yeah. What service?
Yeah, and it was great when we all ran, you know Novell netware and so forth Windows came along 95% market share of laptops. That's hot and that makes me laptops desktops, but also Windows Server. Yep, and it became you that's how you was signed access control.
So you did identity now, like you said the cloud comes along And frankly, it's not just the cut Microsoft. Isn't that 95? They're probably an eighty percent.
Yeah, but You know, but you have more. more places more ad sitting in your data center or aren't in your server closet isn't going to do it now Microsoft moved a d to as a service, right? It is sure.
Yeah. But even that wasn't enough, yeah, so I would say, you know, if you think about the challenges today that admins face they used to live in ldap or active directory and what they did was they assigned users to groups and groups represented roles and business applications and it was clunky but it was one place to administer all that now in the age of SAS and Cloud they have dozens or hundreds of different admin consoles. And so the admins life is just hell right now right and not to mention the developers.
They have to reinvent that wheel every time they build a new microservice or application and my other services just make it worse because every microservice builds its own access control and so it's impossible the reason about like the surface area of a microservices based application. So that's why we built asserto and we just this week. We open source our client side authorizer called topaz.
Oh, okay as a new open source project that combines Opa the open policy agent. So it uses Opa as a decision engine, but then it brings a embedded directory with it that represents the Google Zanzibar model. If you if you know how you know Google Docs and Google Drive Works.
They basically have this idea where you can assign a viewer or a commenter or an owner type of permission to users a groups and that Cascades all the way down through the object directory until you know, you can basically evaluate queries like those Allen have viewer access on this document if Alan is in this group and if this document is in this folder sound familiar, that's really all right. It is a directory. That's right.
And so that's what we've brought together. We've brought together a directory and opa together. So now you have policy as code, but you know how I understand.
So we're marrying Oprah to a directory, but it's not your grandpa's director. That's right. It's a directory that contains not just users and Mobile direct a portable director.
That's right, and it has objects and the relationship between the objects and the original groups. Very straight so it's not just that's clunky uses. Yes.
It's it takes sort of that zero trust model where I could I'm not gonna just because you're in a group doesn't mean you get everything exactly and I'm not gonna have three million groups, but three million permutations of what I'm gonna do. I'm gonna marry you to certain objects and that's who you that's right. And that's really kind of a here's the principle of least privilege which is all all of us are trying to get to right right.
I mean today if you look at breaches, it's not a matter of if it's a matter of when yeah and you want to make sure that you lock down each user to the minimum set of operations. Yep that they need but no more than that. So they can limit the blast radius of these types of breaches and so assert.
Oh and everybody's like us, you know, help us do that. So topaz is open source. That's the client side.
Yes, but can you use it without the other absolutely. So topaz is completely Standalone. It has everything you need to build fine-grained policy based real-time authorization into your SAS app into your microservice into your API.
And then we have a control plane that you know a sort of hosts. It's a SAS control plane that helps you do all the management. So management of policies management of users and groups and connections to Identity providers like OCTA and odd zero, you know, gather all the decision logs and centralize them and pour them into your Splunk or your elk.
So all of the stuff that you need to make it Enterprise grade is what we have in our control plane go right I got to do a Shameless plug Armory was nice enough to Submitter byline that contain a journal is published last week. It's called The Five Laws of cloud native authorization. And yeah had give us the Five Laws of cloud.
It's here for right because you need any cheat notes, but go ahead sounds good. So, you know, one of the things that we noticed is that you know, we haven't moved forward in 15 years, but all the sudden in the last year or two all these large companies like Google and Intuit Airbnb and Carta and Netflix, they're all right writing about how they do Cloud native authorization. It's a hard problem.
So what we've done is we've abstracted a set of principles. We call the Five Laws of cloud native authorization and you know, they they basically their best practices that all these people write about. The first one is you want to extract authorization out of each one of the your microservices in centralized into you know, what we call a purpose-built authorization service.
And so all of these five companies they did that and Build it as a distributed system so that it's not just you know, kind of like one of those things where you know, you're processing over stale data, you're making decisions over, you know, live data the way they do that, you know, the the second principle is fine grains. So instead of relying on coarse-grained roles and permissions you want to be basically allocate the smallest, you know set of permissions that you can to users sure. The third one is policy based.
So you want to make sure that authorization policies expressed as code, you know, you you and I worked on things like configuration is code and infrastructure's code. Everything is code now policy is code. So you want to express it in a domain specific language in our case.
It's Rego the open policy agent, right DSL, right and you want to be able to you know store and evolve it separately and maybe even put it under the control of your security engineering team. So now the application Engineers can work on applogic and then security Engineers can own and maintain that Policy right the fourth one is real time. So you want to make decisions based on real-time data and you want to you know, so rather than relying on stale permissions that are stored in Access tokens.
You want to basically make a call to the authorizer right before you want to make a decision about you know, whether you can show a protected resource to a user. The last one is you want fine grain decision logs. So like we talked about, you know, it's not a matter of if it's a matter of when you get breached.
And so rather than just having a login Trail, you know Allen logged in at 235 pm today. You want to know what Alan did you know every single decision that the application made, you know, whether you were allowed to view this resource or access this resource or not. And so that's a best practice as well.
And so those are the five laws of authorization. If you want to, you know, go build a modern authorization system. We advise you to follow those laws and if you need help with that within an open source solution we have topaz for you.
And if you just want a really good commercial. Solution that incorporates all of that. That's exactly if you don't want to kind of build everything on your own, you know, it's if it's not core and critical to your business exactly don't do it.
And that's most people tell us it doesn't make their beer taste any better. No critical. It's the cost of doing business, but it's not different words.
It's not the core thing. They do either. com.
com. com check them out. And now you have an idea not only is he really armories really one of the nicest guys in the business.
Thank you so much. Enjoy talking with him Armory of pleasure. I'm glad you all the luck with you sir know.
Come back. You don't have to wait till kubecon. We could always do this.
We're gonna take a break. We're in Detroit. We'll be right back.
