Cerbos enforces fine-grained authorization within AWS App Mesh, using the same Envoy ext_authz protocol that powers the native Envoy integration.
App Mesh uses Envoy sidecars as its data plane, so Cerbos integrates via the same native ext_authz protocol
The same Cerbos policies that govern your application layer extend to your service mesh
Authorization at every service hop, managed from a single control plane
AWS App Mesh provides a native integration point for Cerbos, extending policy-driven authorization to another layer of your stack without custom glue code.
Cerbos policies are written in human-readable YAML supporting RBAC, ABAC, and conditional rules. The same policies that govern your application layer now extend to AWS App Mesh, enforced consistently everywhere.
A unified control plane means one set of policies, one audit trail, and one management workflow, regardless of how many services and infrastructure layers your system spans.
AWS App Mesh is a managed service mesh that uses Envoy as its sidecar proxy. Because it uses Envoy as its data plane, Cerbos integrates via the same ext_authz gRPC protocol used in standalone Envoy deployments.
AWS App Mesh uses Envoy as its sidecar proxy, so it inherits Envoy's ext_authz protocol. Cerbos acts as the external authorization service — the Envoy sidecar forwards each request to Cerbos for policy evaluation before routing to your service.
Yes. App Mesh uses Envoy sidecars as its data plane. The Cerbos integration uses the same ext_authz gRPC protocol, same policy evaluation, and same configuration. You configure it via App Mesh virtual node settings.
No. Authorization happens at the sidecar proxy layer. Your services receive only pre-authorized traffic.
What is Cerbos?
Cerbos is an end-to-end enterprise authorization software for Zero Trust environments and AI-powered systems. It enforces fine-grained, contextual, and continuous authorization across apps, APIs, AI agents, MCP servers, services, and workloads.
Cerbos consists of an open-source Policy Decision Point, Enforcement Point integrations, and a centrally managed Policy Administration Plane (Cerbos Hub) that coordinates unified policy-based authorization across your architecture. Enforce least privilege & maintain full visibility into access decisions with Cerbos authorization.