
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Mon, 25 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/zanzibar/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-25-authorization-fga-zanzibar-spicedb-permify-openfga-cerbos-cedar-oso-2026-deep-dive.en</guid>
    <title>Fine-grained Authorization (FGA) Systems in 2026 — Zanzibar, SpiceDB, Permify, OpenFGA, Cerbos, Cedar, Oso Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-25-authorization-fga-zanzibar-spicedb-permify-openfga-cerbos-cedar-oso-2026-deep-dive.en</link>
    <description>Authorization no longer ends with one line of &quot;if user.role == admin&quot;. Since Google&#39;s Zanzibar paper rewrote the industry&#39;s mental model, 2026 has more than a dozen FGA engines fighting it out — SpiceDB, OpenFGA (Auth0/Okta), Permify, Cerbos, Cedar (AWS), Casbin, Oso, Ory Keto, Warrant, Aserto, Topaz. This piece covers the difference between ReBAC, RBAC, and ABAC, the internals of the Zanzibar paper (snapshot reads, Leopard index, watch API), namespace/relation/condition schemas, Check API patterns, ListObjects vs ListRelations, multi-tenant isolation, Postgres RLS as a fallback, edge authorization (Cloudflare + OPA), and real-world deployments at Naver, Kakao, AWS Tokyo, and Cybozu.</description>
    <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>authorization</category><category>fga</category><category>zanzibar</category><category>spicedb</category><category>permify</category><category>openfga</category><category>cerbos</category><category>aserto</category><category>casbin</category><category>oso</category><category>cedar</category><category>rebac</category><category>rbac</category><category>abac</category><category>opa</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-25-authorization-fga-zanzibar-spicedb-permify-openfga-cerbos-cedar-oso-2026-deep-dive.ja</guid>
    <title>きめ細かな認可(FGA)システム 2026 徹底解説 — Zanzibar、SpiceDB、Permify、OpenFGA、Cerbos、Cedar、Oso 完全ガイド</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-25-authorization-fga-zanzibar-spicedb-permify-openfga-cerbos-cedar-oso-2026-deep-dive.ja</link>
    <description>認可(Authorization)は、もう if user.role == admin の一行で終わる時代ではない。Google の Zanzibar 論文が業界全体の発想を変えて以来、2026 年現在では SpiceDB、OpenFGA(Auth0/Okta)、Permify、Cerbos、AWS Cedar、Casbin、Oso、Ory Keto、Warrant、Aserto、Topaz まで十数の FGA エンジンが激突している。ReBAC と RBAC と ABAC の違い、Zanzibar 論文の内部(snapshot read、Leopard インデックス、watch API)、ネームスペース・リレーション・コンディションのスキーマ、Check API パターン、ListObjects と ListRelations、マルチテナント隔離、Postgres RLS のフォールバック、エッジ認可(Cloudflare + OPA)、そして Naver / Kakao / Cybozu の実際の導入事例まで一気通貫で整理する。</description>
    <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>authorization</category><category>fga</category><category>zanzibar</category><category>spicedb</category><category>permify</category><category>openfga</category><category>cerbos</category><category>aserto</category><category>casbin</category><category>oso</category><category>cedar</category><category>rebac</category><category>rbac</category><category>abac</category><category>opa</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-25-authorization-fga-zanzibar-spicedb-permify-openfga-cerbos-cedar-oso-2026-deep-dive</guid>
    <title>세분화 인가(FGA) 시스템 2026 심층 분석 — Zanzibar, SpiceDB, Permify, OpenFGA, Cerbos, Cedar, Oso 완전 정복</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-25-authorization-fga-zanzibar-spicedb-permify-openfga-cerbos-cedar-oso-2026-deep-dive</link>
    <description>인가(Authorization)는 더 이상 if user.role == admin 한 줄로 끝나지 않는다. 구글의 Zanzibar 논문이 산업 전체의 사고방식을 바꾼 이후 2026년 현재 SpiceDB, OpenFGA(Auth0/Okta), Permify, Cerbos, Cedar(AWS), Casbin, Oso, Ory Keto, Warrant, Aserto, Topaz까지 십수 개의 FGA 엔진이 격돌하고 있다. ReBAC vs RBAC vs ABAC의 차이, Zanzibar 논문 내부(snapshot read, Leopard index, watch API), 네임스페이스/릴레이션/컨디션 스키마, Check API 패턴, ListObjects vs ListRelations, 멀티테넌트 격리, Postgres RLS 폴백, 엣지 인가(Cloudflare + OPA), 그리고 네이버/카카오/Cybozu의 실제 도입 사례까지 한 번에 정리한다.</description>
    <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>authorization</category><category>fga</category><category>zanzibar</category><category>spicedb</category><category>permify</category><category>openfga</category><category>cerbos</category><category>aserto</category><category>casbin</category><category>oso</category><category>cedar</category><category>rebac</category><category>rbac</category><category>abac</category><category>opa</category>
  </item>

    </channel>
  </rss>
