The efficiency of OPA #129
-
Consider this application scenario. If the granularity of access control is fine enough, a large number of access control policies are required. I would like to ask the following questions:
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Hi @xwzbupt 👋 I don't think you'll necessarily need a large number of policies for fine grained access control. OPA uses both policy and data to make policy decisions, and the common pattern is to try and push as much of the dynamic data (i.e. things that are likely to change over time) into data and not policy rules. Granted, there are situations where you'd actually want to have a large number of rules, but those are rare.
|
Beta Was this translation helpful? Give feedback.
-
Thanks for your answer! |
Beta Was this translation helpful? Give feedback.
Hi @xwzbupt 👋
I don't think you'll necessarily need a large number of policies for fine grained access control.
OPA uses both policy and data to make policy decisions, and the common pattern is to try and push as much of the dynamic data (i.e. things that are likely to change over time) into data and not policy rules. Granted, there are situations where you'd actually want to have a large number of rules, but those are rare.