Cloud Native
Security Talks
RSS

KubeCon Europe 2025

From Chaos To Control: Migrating Access Control To OpenFGA in a Multi-Tenant World

Jo Guerreiro, Grafana Labs & Poovamraj Thanganadar Thiagarajan, Okta

Abstract

Designing access control that works seamlessly for individuals and scales to millions of resources is a complex challenge. From lackluster search performance to feature inconsistency and multi-tenant schema discrepancies, there’s no shortage of issues to face. Join the Grafana Access squad’s journey through the ups and downs of how we’re tackling these issues using OpenFGA, a CNCF sandbox project, by porting our existing access control schema and rethinking our resource search strategy. If you’ve ever wondered what it takes as a platform engineer to support access control on a multi-tenant system with millions of resources, this is your opportunity to learn how to orchestrate a migration from your current access control system and hear about the peculiar challenges of developing security critical systems.

More from KubeCon Europe 2025

Open in the index →
  1. Trust No One: Secure Storage With Confidential ContainersAurélien Bombo, Microsoft 2025-04-02
  2. Signed, Sealed, Delivered - Sign and Verify All the ThingsJeremy Rickard, Microsoft 2025-04-02
  3. Securing AI Workloads: Building Zero-Trust Architecture for LLM ApplicationsRohit Ghumare, Taikun & Joinal Ahmed, NTG 2025-04-02
  4. Weaving a VEX Feed Through the Kubernetes ProjectAdolfo García Veytia, Stacklok 2025-04-03
  5. Redefining Access Control: Scaling Policy as Code for Humans and AI AgentsRaz Cohen, Permit.io 2025-04-03
  6. Open Source Malware or a Vulnerability? The Philosophical Debate and How To MitigateBrian Fox, Sonatype; Madelein van der Hout, Forrester Research Inc.; Santiago Torres-Arias, Purdue University 2025-04-03
  7. Mind the Gap: Bridging Supply Chain Policy With Git-less GitOps and GUACMichael Lieberman, Kusari & Andrew Martin, ControlPlane 2025-04-03
  8. Identity-based Trust - Till Death Do We Part?John Kjell, ControlPlane & Kairo De Araujo, Independent 2025-04-03
  9. IAM, Agent: Identity for Autonomous AIMatthew Bates, Cofide 2025-04-03
  10. ​​SPIFFE in Practice: Universal Identity for WebAssembly WorkloadsJoonas Bergius, Cosmonic & Colin Murphy, Adobe 2025-04-03
  11. Zero Trust at Shopify Scale: Automating MTLS Across Thousands of ServicesDani Santos & Michelle Mali, Shopify 2025-04-04
  12. Why Don’t We Have Both? Track Build- and Run-time Information for Security With Kubescape and GUACJeff Mendoza, Kusari & Ben Hirschberg, ARMO 2025-04-04
  13. Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub ImagesGuillaume Valadon, GitGuardian 2025-04-04
  14. Enhancing Software Composition Analysis Resilience Against Container Image ObfuscationAgathe Blaise, Thales & Jacopo Bufalino, CNAM 2025-04-04
  15. EVAPorating Kubernetes Security Risk: Adopting Validating Admission Policy at ScaleKaitlyn Lee & Jordan Conard, Datadog 2025-04-04
  16. Do Your Containers Even Lift – A Hardening Guide for K8s ContainersCailyn Edwards & Daniel Murphy, Okta 2025-04-04
  17. Container Runtimes... on Lockdown: The Hidden Costs of Multi-tenant WorkloadsLewis Denham-Parry, Edera & Caleb Woodbine, ii.nz 2025-04-04
  18. Compliance at the Speed of Innovation: Leveraging AI-Driven Automation for Real-Time Regulatory ReadLarry Carvalho, RobustCloud LLC; Simon Metson, EnterpriseDB; Robert Ficcaglia, Sunstone Secure, LLC; Anca Sailer, Red Hat / IBM; Yuji Watanabe, IBM Japa 2025-04-04