Security
Part 4 of 6 · AuthorizationReBAC & Zanzibar — Relationship Tuples & Consistency
Relationship-based auth with Zanzibar-style tuples and consistency tradeoffs for sharing graphs.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
A share graph vs a role per document
Prefer
Tuples plus rewrites
Users, groups, folders, and documents are edges. Editor implies viewer. A parent folder can grant viewer on the child.
- One check walks the configured graph.
- Inheritance lives in the namespace, not in a copied role.
- A zookie lets a reader demand a snapshot at least as new as the share they just wrote.
Alternative
ACL list or a role named after the file
Easy to draw for ten documents. Inheritance is a batch job. Listing who has access means scanning forward edges you never stored.
- Per-object roles are the explosion from the RBAC lesson.
- owner_id attributes cover a single owner and stop at multi-hop shares.
- Eventual reads after a share produce support tickets.
Check, then freshness
The boolean answer and the snapshot it was computed on are different questions.
- 1
Write tuples
object#relation@subject. A group subject points at another userset, not at a copied member list. - 2
Namespace rewrites
Which relations exist, which imply others, and which walk a parent edge. - 3
Check
May this subject hold this relation on this object? Walk until you reach the user or you exhaust the graph. - 4
Pass the zookie
After a share, the client sends the token from the write. The check must not answer from an older snapshot.
Overview
Drive, Dropbox, and GitHub-style sharing is a graph: users, groups, folders, documents, and inherited roles. Flat RBAC invents a role per object. ABAC can encode owner_id and then gets awkward for "editor of the parent folder." Relationship-based access control stores the edge and answers check by walking a configured rewrite.
Google's Zanzibar paper is the reference design for doing that at global scale, including consistency tokens so a new collaborator is not denied by a stale replica, and a revoked user is not allowed by one. AuthN still only has to produce a stable subject id.
Tuple anatomy
Common shape: object#relation@subject.
doc:readme#owner@user:alicedoc:readme#editor@user:bobdoc:readme#viewer@group:eng#member- A parent edge, often modeled as the folder relating to the document (the exact direction is a schema choice)
The namespace config declares relations and rewrites. Editor implies viewer. Viewer includes parent->viewer. Check does not enumerate every grant by hand. It expands those rules.
Flow
- 1
1. Write relationship tuples
- next2. Namespace defines rewrites
- 2
2. Namespace defines rewrites
- next3. Check subject on object
- 3
3. Check subject on object
- next4. Walk the userset graph
- 4
4. Walk the userset graph
- next5. Allow if user reached
- next6. Deny if not reached
- 5
5. Allow if user reached
- 6
6. Deny if not reached
Lesson map
ReBAC & Zanzibar — Relationship Tuples & Consistency
Relationship-based auth with Zanzibar-style tuples and consistency tradeoffs for sharing graphs.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB a["1. Write relationship tuples"] b["2. Namespace defines rewrites"] c["3. Check subject on object"] d["4. Walk the userset graph"] a -->|1. Write relationship tuples| b b -->|2. Namespace defines rewrites| c c -->|3. Check subject on object| d
Check vs list
| API | Question | Hard part |
|---|---|---|
| Check | May S hold relation R on object O? | Latency, cache, consistency |
| List or expand | Which objects can S access, or who has R on O? | Fan-out, indexes, pagination |
| Write | Add or remove a tuple | Ordering against readers |
List is not N checks. You need reverse edges or an expand API. Interviews listen for that sentence.
Consistency tokens and the new-enemy problem
Alice shares a document with Bob. Bob opens immediately. A stale replica still denies. That is the new-enemy problem: the new collaborator is treated as an outsider. The dangerous twin is a stale allow after revoke.
Zanzibar returns a zookie with the write. A later check can require "at least as fresh as this token." Stricter consistency costs coordination and latency. Many reads can stay on a fast snapshot when staleness is safe. ACL writes should not. Pass the token on the read that must observe the share.
Flow
- 1
1. Alice writes a share
- next2. Write returns zookie Z
- 2
2. Write returns zookie Z
- next3. Bob checks with Z
- 3
3. Bob checks with Z
- next4. Serve snapshot at least Z
- 4
4. Serve snapshot at least Z
- next5. Allow is not a stale deny
- 5
5. Allow is not a stale deny
Against nearby models
| Model | Pros | Cons | Use when |
|---|---|---|---|
| Per-object ACL | Easy to picture | Weak inheritance; large lists | Tiny apps |
| RBAC | Persona bundles | Explosion on shares | Coarse admin |
| ReBAC / Zanzibar | Inheritance, groups, scale patterns | Modeling and consistency | Collaboration products |
| ABAC on owner id | Simple single-owner checks | Poor multi-hop shares | Resources with one owner |
Compose them when you need both: check the relation first, then apply an attribute constraint (region, time) from the ABAC lesson. Engines can call a tuple store; they do not replace the graph by themselves. That comparison is next.
Sandbox: one-level check, then a zookie stub
Owner implies editor and viewer. Editor implies viewer. Cara is a member of eng, and eng#member is a viewer of the document. She can view. She cannot edit.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Press Run. Snippets must be self-contained — no network, files, or native modules.
The second check asks for snapshot 99 while the store is still at 2. The stub returns false instead of answering from a stale map. A real system waits or reads a fresher replica. It does not pretend the old deny is current.
Interview Q&A
What is a relationship tuple?
Answer
A durable edge: a subject has a relation to an object. It is the unit ReBAC stores, and the input to check and list.
What does a namespace or userset rewrite do?
Answer
It declares relations and how they expand: implication, union, intersection, and tuple-to-userset such as parent to viewer. Checks walk that graph instead of listing every direct grant.
Check vs list objects?
Answer
Check is a boolean for one object. Listing authorized objects needs different indexes. Looping check over every id does not scale.
What is the new-enemy problem?
Answer
A freshly granted or revoked ACL is invisible to a stale read. The new collaborator is denied, or a revoked subject keeps access. Consistency tokens tell the check how fresh it must be.
Why not put relations in the credential?
Answer
Graphs are large and they change often. A credential would bloat and go stale. Store tuples server-side. The credential carries the subject id. How that credential was issued is the OAuth and OIDC cluster.
How does ReBAC compose with ABAC?
Answer
Check the relation, or expose it as an attribute, then apply constraints such as region or time. SpiceDB-style stores next to a policy engine show up for that reason.
Name systems that follow this model.
Answer
Google Zanzibar is the paper. Open implementations include SpiceDB (Authzed) and OpenFGA. Know the tuple, the rewrite, and the zookie. Product trivia is optional.
What is a userset subject?
Answer
group:eng#member means "the members of eng," not the string "eng" as a user. Check has to expand it. If you compare it as a raw user id, every group grant denies.
Why store reverse edges?
Answer
Forward edges answer "what can Alice do?" slowly if you start from objects. Audits and "who can view this doc?" start from the object. Without a reverse index, expand becomes a scan.
Pitfalls
Write three tuples: Alice owns the folder, the document parents to the folder, and viewer on the folder should reach the document. Say which rewrite makes the third fact true without copying Alice onto the document. Then say which token Bob's client must send if Alice shared the folder a moment ago.