Skip to main content

Fine-grained access control in LXD with OpenFGA

UA2.118 (Henriot) | Day 2 | 13:05 - 13:35 | Speakers: Mark Laing

Fine-grained access control in LXD with OpenFGA
A picture of a devroom at FOSDEM 2024
Open in browser

Notes

Abstract

LXD is increasingly deployed on premises as a private cloud solution. To manage access over the HTTPS API, LXD has developed a novel approach using relationship-based access control (ReBAC) and OpenFGA. This approach facilitates fine-grained permission management and enforcement in air-gapped deployments where it is not feasible to deploy a separate OpenFGA server.

This talk will outline LXD's implementation and discuss its benefits and drawbacks.

Implementation details can be found in the specification and in the LXD Github repository

Speakers

Mark Laing

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.