Project Lightning Talk: OpenFGA: The Cloud Native Way to Implement Fine Grained Aut... Andres Aguiar
Andres Aguiar
KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk
Overview
In the realm of modern cloud-native applications, managing access control with precision and scalability is a formidable challenge. Andres Aguiar's KubeCon EU talk introduces OpenFGA, an open-source, cloud-native authorization system designed to simplify the implementation of fine-grained authorization for developers. Positioned as an evolution beyond traditional role-based access control (RBAC) and attribute-based access control (ABAC), OpenFGA leverages a concept known as relationship-based access control (ReBAC) to offer unparalleled flexibility and scalability.

Key moments
- 0:00 Introduction to OpenFGA and its inspiration
- 1:20 Core concepts: Authorization Model and Relationship Tuples
- 2:30 Extending RBAC with flexible relationship-based access control
- 3:40 OpenFGA's community and notable adopters
- 4:00 Real-world examples: Grafana, Docker, Canonical, and more
- 5:00 How to get started with OpenFGA
Project Lightning Talk: OpenFGA: The Cloud Native Way to Implement Fine Grained Aut... Andres Aguiar
Speakers: Andres Aguiar, Product Manager, Octa
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=ohS-ibtuQWw
Overview
In the realm of modern cloud-native applications, managing access control with precision and scalability is a formidable challenge. Andres Aguiar's KubeCon EU talk introduces OpenFGA, an open-source, cloud-native authorization system designed to simplify the implementation of fine-grained authorization for developers. Positioned as an evolution beyond traditional role-based access control (RBAC) and attribute-based access control (ABAC), OpenFGA leverages a concept known as relationship-based access control (ReBAC) to offer unparalleled flexibility and scalability.
OpenFGA draws its core inspiration from a seminal research paper published by Google, detailing their internal authorization system, Google Zanzibar. This system was engineered to provide generic, scalable authorization across Google's vast array of products and services. OpenFGA takes these foundational principles, open-sources them, and delivers a complete ecosystem including a server, APIs, SDKs, CLIs, and IDE integrations, making advanced authorization accessible to the broader developer community. The project is currently a CNCF Sandbox project and is actively pursuing incubation, demonstrating its growing maturity and community engagement.
The significance of OpenFGA lies in its ability to empower developers to define complex authorization logic that mirrors real-world organizational structures and data hierarchies, without sacrificing performance or maintainability. By externalizing authorization decisions into a dedicated, scalable service, OpenFGA helps prevent common security pitfalls associated with custom, in-application authorization logic and ensures consistent enforcement of policies across distributed systems. Its adoption by major players like Grafana Labs, Canonical, and Docker underscores its practical utility and robust design for diverse cloud-native environments.
Background
▶ Watch: Introduction to OpenFGA and its inspiration (0:00)
The evolution of access control mechanisms has seen significant shifts from basic discretionary access control (DAC) to more structured approaches like Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC). RBAC simplifies permission management by assigning users to roles, which in turn have specific permissions. While effective for many scenarios, RBAC can become cumbersome when dealing with complex hierarchies, dynamic relationships, or very specific object-level permissions. ABAC attempts to address this by making access decisions based on attributes of the user, resource, and environment, offering greater flexibility. However, ABAC can lead to complex policy engines that are difficult to write, audit, and optimize.
The limitations of RBAC and ABAC in highly distributed, large-scale systems led Google to develop Zanzibar, a globally distributed authorization system capable of evaluating billions of access checks per second across trillions of access control lists. The core innovation of Zanzibar, and by extension OpenFGA, is Relationship-Based Access Control (ReBAC). Instead of focusing solely on roles or attributes, ReBAC models authorization as relationships between users and resources. For example, "Maria is a member of ACME organization," or "John is an editor of document X." These relationships can then be composed and evaluated to determine permissions, offering a highly expressive and scalable way to define complex access rules.
Before OpenFGA, implementing such a sophisticated authorization system often meant building it from scratch, a task requiring significant engineering effort and deep security expertise. This challenge is particularly acute in the cloud-native landscape, where applications are composed of numerous microservices, each potentially requiring its own authorization logic. The lack of a standardized, scalable, and developer-friendly solution for fine-grained authorization often leads to inconsistent security policies, increased development time, and a higher risk of vulnerabilities. OpenFGA directly addresses this gap by providing an open-source, production-ready implementation of the Zanzibar model, making this advanced authorization paradigm accessible to any application developer.
Key Findings
▶ Watch: Extending RBAC with flexible relationship-based access control (2:30)
OpenFGA's primary contribution is democratizing the sophisticated authorization capabilities inspired by Google Zanzibar, making them available as a production-ready, open-source solution for the cloud-native ecosystem. The talk highlights several key findings and contributions:
- Evolutionary Authorization Paradigm: OpenFGA firmly establishes Relationship-Based Access Control (ReBAC) as a powerful evolution over traditional RBAC and ABAC. It demonstrates how ReBAC can handle complex, hierarchical, and dynamic authorization requirements that are challenging for older models.
- Comprehensive Developer Ecosystem: Beyond just the core authorization engine, OpenFGA provides a complete suite of tools for developers. This includes the OpenFGA server, a range of SDKs for various programming languages (e.g., Go SDK mentioned), CLIs, APIs, and even IDE integrations. This comprehensive toolkit significantly lowers the barrier to entry for implementing fine-grained authorization.
- Flexible and Extensible Authorization Model: A core finding is the power of OpenFGA's authorization model. Developers can define arbitrary entity types (e.g.,
organization,folder,document), relationships (e.g.,member,admin,owner,editor), and permissions (e.g.,view,edit). Crucially, these definitions can refer to other roles or relationships in a hierarchical manner, allowing for highly nuanced and inherited permissions, as demonstrated by the document management example. - Scalability and Performance: While not explicitly detailing performance benchmarks, the talk underscores OpenFGA's foundation in Google Zanzibar, a system built for massive scale. The architecture is designed to handle high-throughput authorization checks, making it suitable for even the largest cloud-native applications.
- Robust Community Adoption and Ecosystem: The talk proudly points to 197 GitHub repositories that mention OpenFGA, indicating a vibrant and active community. Furthermore, a diverse set of significant adopters, including Grafana Labs, Canonical, Docker, GoDaddy, Zuplo, Stacklok, and ReadAI, are leveraging OpenFGA for critical authorization needs across various domains, from operating systems to API gateways and SaaS applications. This widespread adoption validates OpenFGA's utility and reliability in real-world scenarios.
Technical Deep Dive
▶ Watch: OpenFGA's community and notable adopters (3:40)
At the heart of OpenFGA's technical architecture are two fundamental components: the authorization model and relationship tuples. Together, these define and instantiate the authorization logic for any application.
The Authorization Model
The authorization model is essentially the schema for your authorization system. It describes the types of entities in your application and the possible relationships and permissions that can exist between them. Aguiar illustrates this with two primary examples:
- Simple Multi-Tenant RBAC:
- Entity Types:
organization(representing a tenant),user. - Relationships/Roles:
admin,memberwithin anorganization. - Permissions:
editanorganizationif you are anadminof thatorganization.viewanorganizationif you are amemberor anadminof thatorganization.
This demonstrates how OpenFGA can easily define traditional RBAC concepts but within its more flexible ReBAC framework.
- Complex Document Management Application: This example showcases OpenFGA's power to go "well beyond role-based access control" by defining hierarchical and inherited permissions:
- Entity Types:
organization,folder,document. - Relationships:
foldercanbelongto anorganization.foldercan have aparentfolder.documentcan have aparentfolder.- Permissions:
- A user is an
editorin afolderif they are anownerof thatfolderOR anadminof theparent organization. - A user can
editadocumentif they are anownerof thedocumentOR aneditorfrom theparent folder. This implies thateditorpermissions can cascade down from an organization to a folder, and then from a folder to a document, providing a powerful mechanism for inherited access.
This model is defined using a declarative language, allowing developers to precisely specify the relationships and permissions relevant to their application's domain.
Relationship Tuples
While the authorization model defines what relationships and permissions are possible, relationship tuples define who has what relationship with which resource at a given moment. These are the instance data that instantiate the model.
For example, based on the multi-tenant RBAC model:
Maria is a member of the ACME organizationAna is an admin of the ACME organization
These tuples are stored in a database. OpenFGA currently supports popular choices such as SQLite, PostgreSQL, and MySQL, offering flexibility for different deployment scenarios.
APIs and SDKs
OpenFGA provides a set of APIs and SDKs to interact with the authorization system:
writeAPI: Used to add or remove relationship tuples. For instance, to grant Maria membership to the ACME organization, an application would call thewriteAPI with the appropriate tuple. The talk shows an example using the Go SDK for this operation.checkAPI: This is the core API for making authorization decisions. When an application needs to know if ausercan perform anactionon aresource, it calls thecheckAPI. For example,Can Mary edit a specific organization?The OpenFGA server then evaluates this query against the defined authorization model and the current set of relationship tuples to return atrueorfalsedecision.
The combination of a flexible, declarative authorization model, dynamic relationship tuples, and a clear API surface allows OpenFGA to provide a robust and scalable solution for fine-grained authorization in complex, distributed systems.
Demo / Proof of Concept
▶ Watch: Real-world examples: Grafana, Docker, Canonical, and more (4:00)
While the talk did not feature a live, interactive demo, Andres Aguiar effectively walked through several illustrative examples that serve as conceptual demonstrations of OpenFGA's capabilities and its practical application. These examples highlight the system's flexibility and power.
The first illustrative example involved a simple multi-tenant RBAC scenario. Aguiar demonstrated how to define an authorization model where organizations can have admins and members. He then showed how to define permissions like "an admin can edit an organization" and "a member or admin can view an organization." This was followed by instantiating the model with relationship tuples, such as "Maria is a member of the ACME organization" and "Ana is an admin of the ACME organization." Finally, he demonstrated how the check API would be used to query permissions, for example, "Can Mary edit a specific organization?" This walkthrough clearly articulated the core workflow of defining, populating, and querying authorization logic in OpenFGA.
The second, more complex example showcased a document management application with hierarchical permissions. This involved defining folders that belong to organizations and can have parent folders, and documents that belong to parent folders. The critical demonstration here was how permissions could be inherited and composed: a user could be an editor of a folder if they were an owner of that specific folder OR an admin of the parent organization. Similarly, editing a document could be permitted if the user was an owner of the document OR an editor of the parent folder, effectively demonstrating how permissions cascade through a nested hierarchy. This conceptual demonstration highlighted OpenFGA's ability to handle intricate, real-world authorization requirements.
Beyond these direct examples, the talk presented several real-world adopters as concrete proof of concept for OpenFGA's utility and robustness:
- Grafana: Uses OpenFGA to manage permissions for dashboards, allowing users to add permissions to specific users, roles, groups, or service accounts.
- Canonical: Integrates OpenFGA into different stacks of its Ubuntu Pro offering, showcasing its use in critical operating system components.
- Docker Hub: Leverages OpenFGA to power its team and role management functionality, demonstrating its applicability in large-scale SaaS platforms.
- Zuplo: An API gateway that uses OpenFGA to manage permissions for each API key, securing API access.
- Stacklok: A software supply chain security tool that uses OpenFGA for managing roles within its CLI application.
- ReadAI: A meeting copilot tool that uses OpenFGA to manage sharing permissions for meeting documents.
These diverse use cases, ranging from operating systems to API gateways and SaaS applications, collectively serve as a powerful proof of concept, illustrating OpenFGA's versatility and reliability in production environments.
Defensive Implications
▶ Watch: How to get started with OpenFGA (5:00)
OpenFGA offers significant defensive implications for organizations grappling with complex authorization challenges, helping to enhance security posture, reduce attack surface, and streamline compliance.
- Centralized and Standardized Authorization: By externalizing authorization logic from application code into a dedicated, scalable service, OpenFGA promotes a centralized approach. This means security teams can define, manage, and audit authorization policies from a single source of truth, rather than sifting through disparate codebases across numerous microservices. This standardization drastically reduces the likelihood of inconsistent policy enforcement and accidental permission misconfigurations, which are common sources of vulnerabilities.
- Reduced Custom Code Security Risks: Building custom authorization logic within each application or microservice is notoriously difficult and error-prone. Developers, even with good intentions, can inadvertently introduce bugs, bypasses, or insecure defaults. OpenFGA abstracts this complexity, providing a battle-tested, open-source engine inspired by Google's robust design. This significantly reduces the amount of custom security-sensitive code developers need to write, thereby lowering the risk of authorization-related vulnerabilities.
- Fine-Grained Control and Least Privilege: OpenFGA's Relationship-Based Access Control (ReBAC) model enables highly granular permissions, allowing organizations to implement the principle of least privilege effectively. Instead of broad role assignments, access can be precisely defined based on specific relationships between users and resources, down to individual documents or folders. This minimizes the potential impact of a compromised account, as its access will be limited to only what is strictly necessary.
- Enhanced Auditability and Compliance: All authorization decisions made by OpenFGA are based on the defined model and relationship tuples. This structured approach facilitates robust logging and auditing of access attempts and decisions. Security teams can easily query who has access to what, why, and when, which is crucial for incident response, forensic analysis, and demonstrating compliance with regulatory requirements like GDPR, HIPAA, or SOC 2.
- Faster Development of Secure Applications: By providing pre-built APIs, SDKs, and a clear model for defining authorization, OpenFGA empowers developers to integrate strong security into their applications more rapidly. This means security is considered earlier in the development lifecycle (shifting left), rather than being an afterthought, leading to more inherently secure applications and reducing technical debt associated with retrofitting security controls.
- Scalability for Evolving Security Needs: As applications grow and evolve, so do their authorization requirements. OpenFGA, being inspired by Zanzibar, is designed for massive scale and high performance. This ensures that the authorization system can keep pace with increasing user bases and complex data structures without becoming a bottleneck or compromising security due to performance trade-offs.
In essence, OpenFGA offers a strategic defensive advantage by transforming authorization from a fragmented, custom-coded burden into a centralized, scalable, and auditable service that directly contributes to a stronger, more resilient security posture.
Key Takeaways
- OpenFGA is a CNCF Sandbox project providing an open-source, cloud-native authorization system. It's inspired by Google's globally distributed authorization system, Zanzibar, and aims to make fine-grained authorization accessible to developers.
- It utilizes Relationship-Based Access Control (ReBAC) as an evolution of RBAC and ABAC. ReBAC allows for highly flexible and scalable authorization decisions based on relationships between users and resources, enabling complex hierarchical permissions.
- The core components are the Authorization Model and Relationship Tuples. The model defines the schema of entity types, relationships, and permissions, while tuples instantiate these relationships with actual data (e.g., "Maria is a member of ACME organization").
- OpenFGA supports complex, inherited permissions. Its model allows relationships and permissions to refer to others in a hierarchy, enabling sophisticated access control like cascading "editor" permissions from an organization down to individual documents.
- A comprehensive developer ecosystem exists, including a server, APIs, SDKs, and CLIs. It supports popular databases like SQLite, PostgreSQL, and MySQL for storing relationship tuples and offers SDKs for various platforms (e.g., Go SDK).
- OpenFGA has significant community adoption and is used by major companies. Adopters include Grafana Labs, Canonical, Docker, GoDaddy, Zuplo, Stacklok, and ReadAI, showcasing its versatility across different application types and its proven reliability in production.
About the Speaker(s)
Andres Aguiar is a Product Manager at Octa and a maintainer in the OpenFGA project. His involvement as a maintainer underscores his deep technical understanding and commitment to the development and growth of OpenFGA as a leading authorization system for developers. His role at Octa, a prominent identity and access management company, further highlights his expertise in the broader security and authorization landscape.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
OpenFGA, an open-source ReBAC system inspired by Google Zanzibar, offers a robust and scalable solution for fine-grained authorization in cloud-native environments. This talk clearly articulates its technical foundations, comprehensive ecosystem, and significant practical impact, making advanced authorization accessible to developers and directly addressing common security pitfalls associated with custom, in-application authorization logic.
Heather Calloway (CISO) — STRONG ACCEPT
This talk on OpenFGA introduces a critical capability for modern cloud-native security: scalable, fine-grained authorization via Relationship-Based Access Control (ReBAC). Inspired by Google Zanzibar, OpenFGA offers a robust, open-source solution that directly addresses the challenges of fragmented, custom-coded authorization logic in distributed systems. For a CISO, the value lies in its potential to significantly reduce application security risk, enhance auditability and compliance, and enable more effective enforcement of least privilege across complex environments. While the KubeCon context suggests a developer-centric delivery, the strategic implications for enterprise governance and…