[HN Gopher] Show HN: Sym, define just-in-time access workflows i...
___________________________________________________________________
Show HN: Sym, define just-in-time access workflows in code
Hello HN, My cofounder (jon918) and I started Sym three years ago
because we were frustrated with how hard it was to manage access to
cloud infrastructure. We wanted to build a tool for JIT access that
was _actually_ designed for developers. We were wary of tools that
tried to accommodate both devs and IT but ended up with usability
compromises for both. First, we figured no one wants another web
app to log into so we let administrators define access workflows in
Terraform and let developers request and gain access via Slack.
That seemed to pay off: being code-based was a big plus for our
early customers since it let them manage the logic in version
control and test in CI/CD. Second, we knew that updating
permissions/roles/access was a major source of toil and risk in the
world of cloud infrastructure. Have you ever tried to avoid
annoying, persistent access requests by setting policies that are a
bit more permissive than you'd like? We felt that fully automated
just-in-time access + approvals could really help here. But we also
knew that a simple approval tool could end up leading to request
fatigue - kind of defeating the purpose. So we built an SDK to let
you define checks in code (e.g. pagerduty.on_call,
okta.is_user_in_group, github.get_repo_collaborators) in order to
dynamically route requests or fast-track access when appropriate.
This seems to be paying off: users are creating Slack-based
approvals in front of different types of risky actions like
production access, sensitive queries and triggering Lambdas. We'd
love your feedback on our approach so far. Does this make sense to
you? Is this a tool you'd use? What would you want to see out of
it? To learn more, check out the video that Nick (nmeans (Sym
VPEng)) made [1]. You can also check out our docs [2] or set up
your own flow [3]. thanks! -adam [1]
https://vimeo.com/815222490/c717c18c42 [2] https://docs.symops.com
[3] https://symops.com/signup
Author : abuggia
Score : 42 points
Date : 2023-04-06 14:45 UTC (8 hours ago)
(HTM) web link (symops.com)
(TXT) w3m dump (symops.com)
| eropple wrote:
| Oh cool, glad to see this hit HN. I know Adam and Jon from way
| back and they're good folks. Congrats on how far you've come with
| this!
| abuggia wrote:
| Thanks Ed!
| zwitkali wrote:
| Love the code-first approach to building a JIT access management
| tool. Would love to see y'all build a pulumi provider to double
| down on the code-first approach.
| abuggia wrote:
| Providing support for other infra-as-code solutions like Pulumi
| is definitely on the roadmap!
| skuenzli wrote:
| I love this approach to integrating access control workflow into
| existing workflows using code.
|
| Really feels like security can actually be "everyone's job" when
| you're able to make good access management decisions from within
| your existing tools and their supporting context.
| jon918 wrote:
| Thanks - we've definitely seen Sym help our early customers
| safely distribute access decisions. Because the flows are
| managed in code, teams also get visibility into how these rules
| are defined and can contribute to improving them, as well as
| extend to new use cases.
| jon918 wrote:
| Hey I'm Adam's co-founder, we'd love feedback from the HN
| community on what we've been working on!
___________________________________________________________________
(page generated 2023-04-06 23:01 UTC)