[{"data":1,"prerenderedAt":24},["ShallowReactive",2],{"tag-list-en-rebac":3},[4,16],{"title":5,"description":6,"tags":7,"path":13,"date":14,"img":15},"From RBAC to ReBAC: Migrating a Role System to OpenFGA Without Downtime","Roles work until someone says 'share just this document with just this person.' That is the day RBAC runs out of road. This is the practical migration: mapping role tables to relation tuples, running OpenFGA in shadow next to your SQL checks, backfilling safely, and only then unlocking the per-object sharing and hierarchy that roles never could. With the traps nobody warns you about.",[8,9,10,11,12],"Authorization","ReBAC","RBAC","OpenFGA","Migration","\u002Fsecurity\u002Fauthz\u002Frbac-to-rebac","2026-07-19",null,{"title":17,"description":18,"tags":19,"path":22,"date":23,"img":15},"Zanzibar Demystified: How Google Answers 'Can This User Do This?'","Authorization looks like a one-line if statement until you run it ten million times a second across every product Google ships. Zanzibar is the system that made that question fast, consistent and global. This walks from the naive permission check to relationship-based access control, the tuple model, consistency with zookies, and the open-source heirs like OpenFGA you can actually run today.",[8,9,20,21,11],"Security","Distributed-Systems","\u002Fsecurity\u002Fauthz\u002Fzanzibar-explained","2026-07-18",1784570361321]