Styra Declarative Authorization Service Expands Offering to Microservices and Service Mesh
May 20, 2020

Styra announced that Styra Declarative Authorization Service (DAS) now supports microservices and extends context-based authorization to the service mesh.

This new use case is the second addition to the company’s turnkey enterprise security solution, which is built on OPA. Now, Styra DAS provides security, compliance and operational guardrails for both Kubernetes and microservices to help customers mitigate risk, reduce errors and accelerate software development. With OPA at its core, Styra DAS provides a single control plane for authorization both within applications and for the infrastructure they run upon.

Styra DAS was introduced in 2019 to help enterprises set up policy-as-code guardrails for Kubernetes, ensuring that workloads are compliant with both internal and external regulations. Now, with support for microservices, Styra DAS provides unified policy across two crucial layers of the new software stack: Kubernetes and microservices.

With authorization for microservices, Styra DAS helps operationalize the service mesh by controlling what APIs can be executed on what services, both on ingress and egress. As companies increase deployments and software scales to customer demands, these controls are critical in ensuring cloud-native applications adhere to data privacy and compliance regulations, as well as risk mitigation. Styra DAS goes beyond what service mesh provides natively, by allowing any business context to be evaluated, compared and included in policy decisions. Developers have far richer control over service proxy authorization and can tightly define communication throughout the mesh.

With Styra DAS, each team no longer needs to implement a dedicated, custom-built authorization system for their particular part of the application (infrastructure, containers, etc.). Instead, they can use a common policy language everywhere, freeing them to spend more development cycles on crucial, more differentiated problems and accelerate their time-to-market.

“With support for microservices, we’ve reached another milestone on our journey to provide authorization across the cloud-native stack,” said Tim Hinrichs, co-creator of OPA and co-founder and CTO of Styra. “When we founded OPA, we designed it for portability -- and indeed OPA is now used across the most critical cloud-native components. With Styra DAS, we started at the platform level with Kubernetes guardrails, and are now extending into the app with support for microservices authorization. It’s thrilling to see our vision borne out in real-world customer deployments.”

Open Policy Agent (OPA) and Styra DAS work together to solve typical entitlements/authorization problems for enterprises. For example, enterprise development teams typically build siloed policy in multiple places, use different languages to codify authorization, and have infrastructure policy that is typically unrelated to app policy.

OPA and Styra DAS overcome these issues by providing developers with a common policy language, toolset and framework for policy across the cloud-native stack. OPA adds context-aware policy evaluation to tightly control exactly what the proxies allow or deny, and does so with the same policy language and tooling used for all authorization decisions. Styra DAS provides the authoring, distribution, impact analysis, monitoring and audit controls for that policy.

Styra DAS support for microservices is available now to all customers.

Share this

Industry News

April 14, 2021

SmartBear has integrated TestComplete, its UI test automation tool, with BitBar, its native mobile device cloud.

April 14, 2021

Elastic announced an expanded strategic partnership with Confluent to deliver the best integrated product experience to the Apache Kafka and Elasticsearch community.

April 14, 2021

Threat Stack announced its ability to support AWS Graviton2-based instances through the Threat Stack Cloud Security Platform.

April 13, 2021

Broadcom and Google Cloud announced a strategic collaboration to accelerate innovation and strengthen cloud services integration within the core software franchises of Broadcom.

April 13, 2021

Nylas announced the launch of Components, JavaScript UI/UX solutions that allow developers to bring productivity features to market faster without needing to design front-end elements from scratch.

April 13, 2021

Perforce Software announces its new version control desktop client — Helix Sync — enabling non-coders such as artists and designers to version digital assets, with a simple drag-and-drop UI.

April 12, 2021

ShiftLeft introduced ShiftLeft CORE, a unified code security platform.

April 12, 2021

GrammaTech announced a new version of its CodeSonar SAST (static application security testing) product that helps developers build safer and more secure code without disrupting workflows.

April 12, 2021

Panaya announced a strategic partnership with Being Guided, a Salesforce Consulting Partner, specializing in the CRM and Salesforce ecosystem, to bring Panaya's ForeSight solution to a wider audience.

April 08, 2021

Palo Alto Networks announced the second generation of Checkov, the static analysis tool for infrastructure as code (IaC).

April 08, 2021

Postman now allows any team with up to three members to collaborate in Postman with unlimited shared workspaces and unlimited shared requests at no cost.

April 08, 2021

Taos, an IBM company, has announced 24x5 managed service availability.

April 07, 2021

VMware unveiled expanded cloud workload protection capabilities to deliver security for containers and Kubernetes.

April 07, 2021

Catapult CX is launching the DevOps Institute’s (DOI) Assessment of DevOps Capabilities (ADOC).

April 07, 2021

Equinix announced that Tinkerbell, an all-in-one open source bare metal provisioning platform, has added significant new features since joining the Cloud Native Computing Foundation (CNCF) Sandbox program.