fix(authz): reuse hierarchy and entity selector indexes - #3991
Draft
strantalis wants to merge 2 commits into
Draft
fix(authz): reuse hierarchy and entity selector indexes#3991strantalis wants to merge 2 commits into
strantalis wants to merge 2 commits into
Conversation
Signed-off-by: strantalis <strantalis@virtru.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: strantalis <strantalis@virtru.com>
Contributor
X-Test Failure Report |
Contributor
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Contributor
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Contributor
|
Contributor
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed Changes
Hierarchy evaluation rebuilt the value-rank map and scanned entitlements for every resource. Build rank maps with the PDP and compute the highest matching entitlement once per definition and decision, including the registered-resource subject path.
Index flattened entity selectors once per entity during static subject-mapping evaluation. Also populate the existing selector deduplication set before querying matched subject mappings.
Layer 6 of 7 in the authorization performance stack. Review and merge from the bottom upward.
Checklist
Testing Instructions
BenchmarkDecisionHierarchy, three samples on Apple M4 Max, 1,000 resources: a 1,000-value hierarchy went from about 17.8ms to 0.81ms; a 6,000-value hierarchy went from about 97ms to 1.23ms. For the latter, allocated bytes fell from about 221MB to 2.28MB per decision. The benchmark excludes PDP construction and measures in-process evaluation.go test ./service/internal/access/v2 -run '^$' -bench BenchmarkDecisionHierarchy -benchtime=1s -count=3.Stack-wide validation:
make testwas attempted with Colima configured. The round-trip suite failed because its required platform server at127.0.0.1:8080was not running.make lintstopped because the configured Buf API token is invalid. Separatemake go-lintreported existing repository issues; the formatting issue in the new hierarchy test was corrected.make govulncheckreported vulnerabilities in the existing dependencies and the installed Go 1.26.3 standard library. This stack changes no dependency versions.