1"use strict";(globalThis.webpackChunkdocumentation=globalThis.webpackChunkdocumentation||[]).push([[6326],{4196(e,n,o){o.r(n),o.d(n,{assets:()=>s,contentTitle:()=>a,default:()=>h,frontMatter:()=>i,metadata:()=>t,toc:()=>d});const t=JSON.parse('{"id":"tutorials/cedar","title":"Cedar-Agent and Cedar","description":"Cedar is an open-source engine and language created by AWS.","source":"@site/docs/tutorials/cedar.mdx","sourceDirName":"tutorials","slug":"/tutorials/cedar","permalink":"/tutorials/cedar","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{},"sidebar":"opalSidebar","previous":{"title":"OPAL Server Connectivity Control","permalink":"/tutorials/opal_server_connectivity"},"next":{"title":"OPAL Helm Chart for Kubernetes","permalink":"/tutorials/helm-chart-for-kubernetes"}}');var r=o(1684),c=o(506);const i={},a="Cedar-Agent and Cedar",s={},d=[];function l(e){const n={a:"a",admonition:"admonition",code:"code",h1:"h1",header:"header",p:"p",pre:"pre",strong:"strong",...(0,c.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.header,{children:(0,r.jsx)(n.h1,{id:"cedar-agent-and-cedar",children:"Cedar-Agent and Cedar"})}),"\n",(0,r.jsxs)(n.p,{children:["Cedar is an open-source engine and language created by AWS.\n",(0,r.jsx)(n.a,{href:"https://github.com/permitio/cedar-agent",children:"Cedar agent"})," is an OSS project from Permit.io - which provides the ability to run Cedar as a standalone agent (Similar to how one would use OPA) which can then be powered by ",(0,r.jsx)(n.a,{href:"https://github.com/permitio/opal",children:"OPAL"}),".\nCedar agent is the easiest way to deploy and run Cedar."]}),"\n",(0,r.jsx)(n.admonition,{title:"Demo",type:"info",children:(0,r.jsxs)(n.p,{children:["Check out our ",(0,r.jsx)(n.a,{href:"https://github.com/permitio/tinytodo",children:"demo app that uses Cedar-Agent and OPAL here"}),"."]})}),"\n",(0,r.jsx)(n.p,{children:"OPAL can run Cedar instead of OPA. To launch an example configuration with Docker Compose, do:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{children:"git clone https://github.com/permitio/opal.git\ncd opal\ndocker compose -f docker/docker-compose-example-cedar.yml up -d\n"})}),"\n",(0,r.jsxs)(n.p,{children:["You'll then have Cedar's dev web interface at ",(0,r.jsx)(n.a,{href:"http://localhost:8180/rapidoc/",children:"http://localhost:8180/rapidoc/"}),", where you can call Cedar-Agent's API routes."]}),"\n",(0,r.jsxs)(n.p,{children:["You can show data with GET on ",(0,r.jsx)(n.strong,{children:"/data"}),", policy with GET on ",(0,r.jsx)(n.strong,{children:"/policies"}),", and you can POST the following authorization to ",(0,r.jsx)(n.strong,{children:"/is_authorized"})," request to perform an authorization check:"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{children:'{\n "principal": "User::\\"[email protected]\\"",\n "action": "Action::\\"document:write\\"",\n "resource": "ResourceType::\\"document\\""\n}\n'})}),"\n",(0,r.jsxs)(n.p,{children:["To show how the policy affects the request, set a policy with fewer permissions with a PUT on ",(0,r.jsx)(n.strong,{children:"/policies"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{children:'[\n {\n "id": "policy.cedar",\n "content": "permit(\\n principal in Role::\\"Editor\\",\\n action in [Action::\\"document:read\\",Action::\\"document:delete\\"],\\n resource in ResourceType::\\"document\\"\\n) when {\\n true\\n};"\n }\n]\n'})}),"\n",(0,r.jsx)(n.p,{children:"Then restore the correct policy:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{children:'[\n {\n "id": "policy.cedar",\n "content": "permit(\\n principal in Role::\\"Editor\\",\\n action in [Action::\\"document:read\\",Action::\\"document:write\\",Action::\\"document:delete\\"],\\n resource in ResourceType::\\"document\\"\\n) when {\\n true\\n};"\n }\n]\n'})}),"\n",(0,r.jsxs)(n.p,{children:["Alternatively, you can also change the Docker compose config and set your own policy git repo (the ",(0,r.jsx)(n.strong,{children:"OPAL_POLICY_REPO_URL"})," variable), and change it on the fly."]}),"\n",(0,r.jsx)(n.p,{children:"If you want to see OPAL's logs, you can do:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{children:"docker
1compose -f docker/docker-compose-example-cedar.yml logs opal_server\n"})}),"\n",(0,r.jsx)(n.p,{children:"and"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{children:"docker compose -f docker/docker-compose-example-cedar.yml logs opal_client\n"})}),"\n",(0,r.jsx)(n.p,{children:"For the server and client, respectively."})]})}function h(e={}){const{wrapper:n}={...(0,c.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(l,{...e})}):l(e)}},506(e,n,o){o.d(n,{R:()=>i,x:()=>a});var t=o(2888);const r={},c=t.createContext(r);function i(e){const n=t.useContext(c);return t.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:i(e.components),t.createElement(c.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.