# Authorization service with GitLab

## Using GitLab as your source code provider

## Securing your source code

GitLab is a DevOps platform that can help you quickly ship, deploy, and store packages and containers. You can also use GitLab as a source code provider for storing and versioning authorization policy code.

Aserto expresses authorization policies as code. Developers can build, tag, sign, push, and pull access control policies like Docker containers.

### Benefits of using the Policy CLI with GitLab

Aserto natively supports GitLab as a source code provider for authorization policies. [Open Policy Containers](https://openpolicycontainers.com/) enables you can build, tag, and then push policy updates to your GitLab organization, at which point Aserto will automatically update connected policy instances. Leveraging the Open Policy Containers with GitLab streamlines building and evolving access control policies.

## What is Aserto?

Aserto is an [authorization service](/content/site-root.html) that helps developers build secure applications. It makes it easy to add fine-grained, policy-based, real-time access control to cloud applications and APIs. It offers blazing-fast authorization of a local library, coupled with a centralized control plane for managing policies, user attributes, resource and relationship data, and decision logs. And it comes with everything you need to deliver fine-grained RBAC, ABAC, or ReBAC.

## Resources

- [Tutorial for integrating GitLab with Aserto](/content/blog/gitlab-integration-is-here/index.html)

Built for developers with♥

#### Sam Hall

Head of Technology, Metrikus

> "Authorization has been a constant worry over the last two years - everyone was scared of it. With Aserto, I'm so much more comfortable with authorization because I can see what's going on. Before, it was a dark art - we had a muddled permission structure. With Aserto, we have clear policies that are easy to implement and obvious to analyze. Aserto has made AuthZ something we're not scared of anymore."

#### James Lindenbaum

Founder, Heroku & Heavybit

> “A policy-centric authorization solution for developers is a glaring hole in the market, and there is no team on the planet better equipped to build it to enterprise-grade."

#### Grant Miller

Co-founder / CEO, Replicated

> "B2B SaaS vendors have a huge opportunity going after the enterprise, but only if they meet enterprise expectations, as we've captured in [EnterpriseReady.io](http://enterpriseready.io/). Replicated serves 50% of the F100, and we know first-hand that authorization and RBAC are table-stakes for enterprise adoption. It's obvious to me that partnering with Aserto is a far better approach compared to rolling your own and having to reinvent the wheel."

#### David Kerber

VP of Technology

> "Authorization involves really hard problems that I want experts to solve. We like to focus our internal engineering efforts on our customers and their problems. Aserto allows us to do just that, at a small fraction of the cost it would take to build and maintain it ourselves, not to mention the opportunity cost."

#### Mathias Biilmann Christensen

Co-founder & CEO, Netlify

> "As millions of developers and businesses are adopting a Jamstack approach, most modern web applications involve multiple APIs and services. Aserto's promise of separating policies from code could radically simplify the implementation of authorization across the front-end UI and the larger world of back-end functions and endpoints."

#### Tom Preston-Werner

Co-founder, GitHub

> "Building & managing an authorization/RBAC system is a huge pain, especially at enterprise scale. So stop! Aserto has a distributed, millisecond latency, 100% availability API for that. I'm excited to help as an angel investor!"

## Authorization as easy as an API call
