Every Iceberg catalog can tell an engine where a table's metadata lives. The
hard part is deciding who may read it, who may write it, and
who gets handed a credential — across catalogs an organisation did not choose
to have in the same place. That is what Rustberg is.
Policy is the product
Every operation is decided by Cedar,
a formally verified policy engine that is a library rather than a service.
Resources form a hierarchy, so one policy covers a whole namespace subtree —
including tables that do not exist yet. Deny by default, including on
evaluation error.
How authorization works →
Federation, under one identity
Mount several catalogs — your own redb or Postgres, or somebody else's
Iceberg REST catalog — under one endpoint, routed by top-level namespace.
The mount is invisible on the wire, so a cross-catalog join is ordinary SQL.
Capabilities are negotiated per mount and published as an intersection.
How federation works →
Credentials that only narrow
AWS STS session policies, GCS credential access boundaries, Azure
user-delegation SAS — each a real downscoping exchange, scoped to one
table prefix. A vended credential is the intersection of the caller's
policy and the mount's own ceiling, and never wider.
How vending works →
Row and column policy, enforced
A row filter or column mask travels to the engine as the Iceberg spec's
read-restrictions — and is not merely advertised. Such a
table is refused a broad credential, pinned to server-side planning, and
handed pre-signed URLs for exactly the files the filter selected.
How restrictions work →
An audit trail, not a log line
Every decision — permit and deny alike — names the policy that made it and
the version of the policy set it came from. An empty rule list on a denial
is itself the answer: nothing forbade the request and nothing permitted it.
When the sink fails, mutations fail with it.
What is recorded →
A binary, or a crate
The same operations are reachable in-process, through the same
authorization guard and against the same catalog — no router, no socket,
no second implementation to keep honest. The equivalence is tested as
equivalence.
Use it as a library →
Nothing required underneath
A useful deployment is one binary and a filesystem. Add Postgres when you
want several replicas, object storage when your tables live there. Pure
Rust, no unsafe, no C dependencies in the default build, so
it cross-compiles statically.
Catalog and warehouse →