Episode 213 - GluuFederation/identerati-office-hours GitHub Wiki

Title: CNCF Cedar Update

Channels

Description

Since joining the CNCF, Cedar is evolving from an AWS-originated policy language into a vendor-neutral community project with broader governance and a growing ecosystem. We’ll explore how Cedar’s verification-guided foundations—expressive policies, predictable performance, and automated analysis—are finding adoption across application authorization, Kubernetes, databases, and AI-agent security. Where is the community taking Cedar next, and can CNCF stewardship establish it as a common authorization layer for cloud-native systems?

Homework

Takeaways

  • ⚡ CNCF membership will help Cedar move beyond its AWS origins, but Amazon still provides the key resources that make it possible--i.e. without the dream team of formal reasoning innovating and maintaining it, Cedar wouldn't be possible. Almost every successful open source project needs some organization to drive it forward, and Cedar is no exception.

  • ⚡ Analyzability is Cedar's most important differentiator, but are the Cedar Rust analysis tools up to the job? How can organizations turn formal reasoning into simple, “push-button” answers that ordinary developers and auditors can use without writing formal specifications.

  • ⚡ AI agents and MCP may become Cedar’s strongest adoption path. Cedar can derive schemas from MCP tool definitions, govern which tools agents may invoke, and formally identify whether an AI-generated policy change makes particular actions more or less permissive. See also the recent announcement about Project Dogwood which is Cedar-adjacent.

  • ⚡ Open source and community governance is a requirement for adoption, but it doesn't necessarily lead to adoption. Adoption requires community outreach, tools, packaging, tutorials, case studies, and strategic planning. The CNCF provides some of the metaphorical lanes, but the project must still drive everything.

Livestream Archive