Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You shouldn’t have 700k security groups though. I know that you end up with that, but it feels like a sign of organisational disease (not that we’re doing much better, but the ratio is more 1 to 1, instead of 3.5 to 1


> You shouldn’t have 700k security groups though

The 700k groups also comes about when the security tools are all inter-operating at the wrong abstraction level. If a third party appliance needs to import all 700k of your security groups it means the appliance is performing authorizations itself, logging it differently than your other apps, and even make decisions based on stale data it's cached (you can't load all 700k groups on every request.)

This task should really be delegated to a dedicated authz system, too bad more of the world doesn't run on Zanzibar.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: