Or Weis, Permit.io | Yalla DevOps 2022
At Yalla DevOps 2022, Alan spoke with Or Weis, co-founder and CEO of Permit.io, about its full-stack permission solution that can be baked directly into products. Alan and Or also discuss how the transition from monolithic applications to microservices has forced companies to evolve more than ever before.
Transcript
This is texturung TV. Hey everyone. We're back here at yala devops.
It's actually a lunch break here. It's a little chaotic. I very Lively very lively.
That's a good way of putting. Yeah, let me introduce you to or why so it's been with us before but not in person first time in person. Yep, and Oh that lights in my eyes orange with permanent IO and it's it's not IO and you know, what or before we jump into yalla and what's going on here.
Let's yeah quick company background sure. So maybe I'll start with my own background. So my name is overweiss background starts in the intelligence score like a lot of Israeli entrepreneurs.
Then I worked in a startup that it containers. We're for containers were a thing with the VP of our Indian a cyber security company and then I created another company that actually presents here and maybe you talked with workout. You know, I'm well sure and when I was at work out, I ended up rebuilding X control for our product five times when the company wasn't even three years old and I said, I don't want to build this one.
So let alone five times so that drove me crazy and getting together with my now co-founder of stuff who worked at Facebook. We saw that for example at Facebook, they invested a team of 30 people for half a decade to build their level of access control and they're still building. Yeah.
So it's annoying for developers building it on their own and it's constantly giving and increasing so we thought we should put an end to that and that's what terminal does it's a full stack permission solution you bake into your product and you're done. So look harder in my mind. Anyway, yeah part of the issue is that with moving to the cloud and now we're talking about moving to the edge and right all of these things in many ways Access Control has become the killer app for cloud security for you know, right security right?
We're when I was doing security 20 years ago. We had the Moten perimeter with a drawer free, right? And that was where the action was the most gone.
Everything's melt away is God. Yeah, so well, so there used to be the Jericho form that you talk about the end of the perimeter and micro per years and all of these things so there is there is a perimeter but it's almost like an individual perimeter around the individual or the machine or whatever that I said it is now yes and And so access has become I mean the killer app, but it's a result of that. It's also become very much more complex.
It's not as easy. Yeah as it used to be which is why with all due respect you had to rewrite it five times in three years exactly also because it's evolving. So even if you don't go two way back like you go five years ten years back you'd have like mostly monolithic applications and then within those like in Ruby you'd have rails with Administration in Python.
You have Django if it's Administration panel Java with spring framework, you'd have like a unified basic layer that you can do access control for your product with but as you move to microservices that becomes irrelevant because you have different microservices with different languages and you need to control all of them. So instead of having one spot, you need a little bit of Access Control a little bit permissions in every little bit of code. You're right.
That creates a distributed area that is very hard to maintain manage keep track of and so new technologies need to come in. And so we started with adopting open source and promoting open source software, like open policy agent sure, but also creating opens projects like our own opal open policy Administration layer, which allows you to work with a lot of open instances in scale and update them in real time. And only then could we actually build a service that we're providing now, which gives you the interfaces and management on top well.
But to me this whole thing is very kind of cloud-native right open source in that, you know, it's it's also the way I mean, I'm looking at you people at home can't see but there's just there's a big billboard up there big screen and it just said 92% Of applications contain open source today, which is a number. I've heard 90% So 92 is not far up. Yeah, that's not surprising at all.
Right. It said like 99% I wouldn't be surprised absolutely. But here's the thing because the way we build application applications have really become sort of that factory model where we have third-party components.
Right? Right, and we we get our suppliers and some components we make ourselves but a lot of it is third party components we put together it becomes more and more so Like five ten years ago, you'd be like I'm not gonna use an authentication vendor. I'm not gonna trust I don't trust.
Yeah nowadays. It's the complete opposite. Like what am I ignition?
Someone else's do billing same thing analytics same thing and a lot and there's a lot more coming in especially in the form of AI agents. Yeah. Those are gonna proliferate the space completely it just think about how you manage permissions for your AI agent working with my AI agent in the third party application.
So we're just seeing the beginning of the pain here. Yeah. Well, you've got I think microservice, please into that right for me.
I first became really acutely aware of this. So I have a strong connection of bold or Boulder, Colorado great town. Yeah.
Well, I had a place there for many years. I started a company based on all the co-founder the company Boulder. But you know my friends at sendgrid and if you remembered yeah, of course, they're still they're part of the video now, right?
It's really up. Yeah, but you know sangrid to me opened my eyes to the idea of look they took the issue of how to kick an email off. Yeah email off the developers play you were developing an application and when someone signed up you had to get that verification email right or you know, something in the application you didn't have to rewrite that you have to invent that wheel.
Yeah, you just by the way everything we're seeing here is just regular evolution of Technology like you start with everyone's doing a bit of everything and then you start to specialize you can even go back to Hunter gever times when people with that like shape their own Spears and then they would be the one guy that creates a better spirit and then you did. Yeah and oh that's out the way. The fact is there's very little revolutionary in technology.
It's evolutionary, right? So you build it and then you apply learning from one area to another area and gradually what we'll be seeing is the applications. We're building will become more and more proprietary so developers which by the way, I think everyone's becoming a developer.
Yeah local NOCO developers regular developers. So everyone will be riding software, but the things that they'll be riding will be more and more proprietary more and more unique to them and everything else would become specialized layers that you can consume as either open source Services products, etc, etc. But it gets build to the end you sir, you don't necessarily see those layers or those parts.
It's it's just an application, right exactly they do and then we just need good layers good good connectors between those days so everything. Playing securely safely in the way that we can manage and that's where we are that well that that's part of access right? Also API security you're starting to talk about now.
That's a whole nother Hot Topic. But anyway, let me let me turn quickly though to yalla. Yalla.
What do you think of the show? I think it's amazing it as we already said it's very Lively people are are asking questions. They're engaged.
Yeah, I've been in a lot of conferences. A lot of times you have just people asking give me Swag goodreaders like yeah. Yeah, that's a good definition.
Right? I'll use it. But here you like people are really interested in building things.
They're really interesting and and thinking about their how they're taking the technology and solutions forward and what was particularly interesting for me was to see the difference between how developers and devops react to things here in the conference. So for example with with us with permit, so developers are really like Do I get rid of this problem of permissions devops people would say how do I make sure that when the developers do this? They don't mess up, right?
That's in it. You know, you're the first person to bring that up. It's an interesting thing.
I have to maybe kernel down from you. Yeah, it's an even trade now absolutely pay for people we got permit that IO right? Yeah or thanks for coming on I'm gonna like let's go eat lunch always a pleasure here.
It's great to see you in person until next time. We'll see you soon. Hopefully everyone.
All right. We're here at yalla. We'll be back.





