Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 13 additions & 3 deletions docs/authz-oss-cedar.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ class). Attribute-rich (ABAC/ReBAC) policy is an Enterprise / bring-your-own-PDP

| Driver | What it is |
| --------- | ---------------------------------------------------------------------- |
| `builtin` | **Default.** Pre-authz rules: authenticated = allowed, admin via SSO groups. Zero behavior change. |
| `builtin` | **Default.** Pre-authz rules: authenticated = allowed, admin via SSO groups. The `agent` resource (agent reads and remote configuration) also requires the admin check for users; agent service accounts may only register, ingest and sync. |
| `cedar` | Embedded Cedar RBAC against the bundled role policies (this document). |
| `authzen` | Delegate every decision to a remote AuthZen-compliant PDP (bring your own). |

Expand All @@ -28,7 +28,7 @@ CCF_AUTHZ_CEDAR_POLICY_DIR=/etc/ccf/policies # optional operator .cedar files

## Bundled roles

Four fixed global roles plus the agent service role, defined in the manifest's `roles:` block
Four fixed global roles plus the agent service role (the manifest lists every role, e.g. `ssp-subscriber`), defined in the manifest's `roles:` block
(`internal/authz/manifest.yaml`) and compiled to Cedar policies at startup:

| Role | Grants |
Expand All @@ -37,7 +37,17 @@ Four fixed global roles plus the agent service role, defined in the manifest's `
| `contributor` | Author content (OSCAL docs, risk/poam register, workflows, dashboards, evidence); read everything; no admin. |
| `auditor` | Read everything; record evidence; maintain the risk/poam register. |
| `viewer` | Read everything; no writes. |
| `agent` | Service accounts: ingest evidence/heartbeats, register. |
| `agent` | Service accounts: ingest evidence/heartbeats, register, sync their remote configuration. |

viewer, auditor and contributor read agent configurations through `"*": [read]`. This is
intended; narrow it with an operator `forbid` policy if needed. The instance reports
(`base`/`effective`) are redacted. `GET …/config` and `GET …/config/revisions/{rev}` return
the **overlay** verbatim only to callers that also hold `agent:configure` (editors), so it
can be edited; every other `agent:read` holder gets it redacted with the report rules
(secret-like keys and values become `••••`). If the configure check cannot be evaluated,
the overlay is redacted. Still, prefer `${env:NAME}` placeholders over literal secrets in
an overlay: editors and every stored revision keep the literal. Deleting an agent deletes
its revisions. Previewing an overlay (`POST …/config/preview`) needs `agent:configure`.

Cedar is **deny-by-default**: a subject with no assigned role is denied every request.

Expand Down
Loading
Loading