Langkau ke kandungan utama

Casbin vs. Cedar

Cedar is an open-source policy language and evaluation engine created at AWS; it is the language behind Amazon Verified Permissions. Casbin is an authorization library under the Apache Software Foundation with a configurable model and implementations in many languages. Both evaluate requests inside your application; they differ in how rules are expressed and in what surrounds the engine.

Summary​

CasbinCedar
How rules are writtenA model file plus policy rules as rowspermit and forbid statements in the Cedar language
Access control stylesACL, RBAC, RBAC with domains, ABAC, ReBAC, and more, chosen in the modelRBAC through entity groups, ABAC through conditions
SemanticsDefined by the model's policy effect; allow-override, deny-override, and priority are availableFixed: deny by default, forbid overrides permit
ValidationModel syntax is checked on load; test with the online editorPolicies are validated against a schema; automated analysis tools exist
Native implementationsGo, Java, Node.js, Python, .NET, PHP, Rust, C++, and moreRust, with Java, Go, and WebAssembly options
Storage and distributionDatabase adapters and watchersYou provide storage, or use the managed AWS service
Managed serviceNone required; runs in your processAmazon Verified Permissions
GovernanceApache Software Foundation (Incubating)Open source from AWS, Apache-2.0

Policy language versus configurable model​

A Cedar policy reads like a sentence:

permit (
principal in Role::"editor",
action == Action::"update",
resource in Folder::"articles"
)
when { resource.owner == principal };

The language has a fixed meaning: everything is denied unless a permit matches, and any matching forbid wins. Policies can be checked against a schema before they are deployed, and the design allows automated reasoning about what a policy set permits.

Casbin splits the same rule into a model and data. Here the request object is an article with Folder and Owner fields (ABAC):

[matchers]
m = g(r.sub, p.sub) && r.obj.Folder == p.obj && r.act == p.act && r.obj.Owner == r.sub
p, editor, articles, update
g, alice, editor

The model decides how requests and policy rules are compared and how results combine. That flexibility is the point of Casbin's PERM design: the same engine can behave as a simple ACL, as RBAC with tenants, as deny-override, or as an ordered firewall-style list. See How it works and Supported models.

What surrounds the engine​

Cedar gives you an evaluator. Loading entities, storing policies, and distributing changes are left to your application, or to Amazon Verified Permissions if you use AWS.

Casbin includes those pieces:

  • Adapters persist policy in SQL and NoSQL databases, files, and cloud stores.
  • Watchers keep multiple instances synchronized.
  • Role managers resolve role hierarchies, including from external sources such as LDAP or an identity provider.
  • The Management API and RBAC API let administrators change permissions at runtime.
  • Middleware exists for most web frameworks.

Languages​

Cedar's reference implementation is in Rust, with bindings and ports for a few other languages.

Casbin has maintained native implementations for Go, Java, Node.js, Python, .NET, PHP, Rust, C++, and more, and a model and policy written once work in all of them.

When to choose which​

Choose Cedar if you want a readable policy language with schema validation and formal analysis, or you plan to use Amazon Verified Permissions.

Choose Casbin if you need to choose or customize the access control model, want storage, synchronization, and management APIs included, need a native library in your language, or prefer a project under Apache Software Foundation governance that does not depend on one cloud provider.

Try Casbin​

Test a model and policy in the online editor, or follow the tutorial for Go, Node.js, Python, or Java.

See also the comparison overview.