Cerbos reference architecture

The complete picture of Cerbos in production. A defense in depth architecture with consistent enforcement from the edge to the data layer.

Externalized authorization icon

This is where teams grow into, not where they begin. Pick one component, like your API gateway or a single service, and go from there.

Cerbos reference architecture diagram

Start with one service

You don't need to roll out Cerbos everywhere on day one. The platform is built for incremental adoption alongside your existing authorization.

1

Instrument

Add Cerbos to one service. Set your first policies to allow everything so nothing changes for your users. Your existing authorization keeps running.

2

Validate

Cerbos logs every decision it would make. Compare those against what your current system decides, in real time, and tune your policies with real traffic.

3

Enforce

When you're confident, turn enforcement on. Expand to the next service from there.