Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 6 additions & 5 deletions docs/concepts/pdp/nexus-pdp-configuration.mdx
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
---
title: Nexus PDP configuration reference
sidebar_label: Configuration
description: "Look up the environment variables that configure Permit Nexus PDP (permitio/pdp-v3): credentials, storage, ports, logging, and storage-engine tuning."
description: "Look up the environment variables that configure Permit Nexus PDP (permitio/nexus-pdp): credentials, storage, ports, logging, and storage-engine tuning."
sidebar_position: 6
---

This reference lists the environment variables that configure Permit Nexus PDP (`permitio/pdp-v3`), a self-hosted policy decision point (PDP). It is for operators who deploy and tune Nexus PDP. The only required variable is `PDP_API_KEY`. For deployment requirements such as volumes, probes, and memory, see [Deploy Nexus PDP](/concepts/pdp/nexus-pdp-deployment).
This reference lists the environment variables that configure Permit Nexus PDP (`permitio/nexus-pdp`), a self-hosted policy decision point (PDP). It is for operators who deploy and tune Nexus PDP. The only required variable is `PDP_API_KEY`. For deployment requirements such as volumes, probes, and memory, see [Deploy Nexus PDP](/concepts/pdp/nexus-pdp-deployment).

:::caution Nexus PDP configuration can change between early-access releases
As of September 2026, Nexus PDP is in early access. Permit can rename, replace, or remove the variables and defaults on this page before general availability. Pin the Nexus PDP image to a specific tag, and check this page when you upgrade. If you depend on a specific variable, tell Permit support at [support@permit.io](mailto:support@permit.io).
As of September 2026, Nexus PDP is in early access. Permit can rename, replace, or remove the variables and defaults on this page before general availability. Pin the Nexus PDP image as described in [Image name and tags](/concepts/pdp/nexus-pdp#image-name-and-tags), not to a moving tag such as `0-beta`, and check this page when you upgrade. If you depend on a specific variable, tell Permit support at [support@permit.io](mailto:support@permit.io).
:::

The container PDP (the Edge PDP image `permitio/pdp-v2`) uses a different set of variables. See the [container PDP configuration reference](/concepts/pdp/configuration). A variable with the same name can mean something different on each PDP type.
Expand All @@ -17,14 +17,15 @@ The container PDP (the Edge PDP image `permitio/pdp-v2`) uses a different set of

| Variable | Default | Description |
| --- | --- | --- |
| `PDP_API_KEY` | Required | The API key of the Permit environment this Nexus PDP serves. |
| `PDP_API_KEY` | Required | The Nexus PDP API key of the Permit environment this Nexus PDP serves, from the Permit dashboard. As of September 2026, the dashboard labels this action **Copy PDP v3 API Key**. The ordinary environment API key does not work. |

`PDP_API_KEY` is the only credential Nexus PDP needs. The `PDP_API_KEY` value:

- binds the container to exactly one Permit environment,
- authenticates the container to Permit's control plane,
- carries the address of the control plane, so Nexus PDP connects without a separate URL setting,
- is the bearer token that the Nexus PDP authorization API accepts from your services.
- is the bearer token that the Nexus PDP authorization API accepts from your services,
- is accepted by the Permit API with the same access as the environment API key, so protect it the same way.

:::tip No control-plane URL to set on Nexus PDP
Leave `PDP_CONTROL_PLANE` unset unless Permit support asks you to set it. On the container PDP, `PDP_CONTROL_PLANE` is the Permit API URL. On Nexus PDP, `PDP_CONTROL_PLANE` overrides the control-plane address that `PDP_API_KEY` carries.
Expand Down
33 changes: 20 additions & 13 deletions docs/concepts/pdp/nexus-pdp-deployment.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,12 @@ description: "Run Permit Nexus PDP with Docker or Kubernetes, meet its storage,
sidebar_position: 5
---

Run Permit Nexus PDP (`permitio/pdp-v3`), a self-hosted policy decision point (PDP), with Docker or on Kubernetes, and verify that it answers permission checks. This page lists the storage, memory, port, probe, and shutdown requirements, gives a runnable command and a pod spec, and covers the Nexus PDP logs and security properties an operator needs. For what Nexus PDP is, see [Permit Nexus PDP](/concepts/pdp/nexus-pdp).
Run Permit Nexus PDP (`permitio/nexus-pdp`), a self-hosted policy decision point (PDP), with Docker or on Kubernetes, and verify that it answers permission checks. This page lists the storage, memory, port, probe, and shutdown requirements, gives a runnable command and a pod spec, and covers the Nexus PDP logs and security properties an operator needs. For what Nexus PDP is, see [Permit Nexus PDP](/concepts/pdp/nexus-pdp).

## Prerequisites

- Nexus PDP enabled for your Permit account. Nexus PDP is in early access as of September 2026; to request access, [book a call with Permit](https://www.permit.io/demo).
- The API key of the Permit environment the Nexus PDP serves. See [Get your API key](/overview/get-api-key).
- The Nexus PDP API key of the Permit environment the Nexus PDP serves. Once Permit activates Nexus PDP for an environment, select that environment in the Permit dashboard and copy the Nexus PDP API key. As of September 2026, the action is named **Copy PDP v3 API Key**. It is in the user menu and the environment card's menu, and it needs edit permission on the environment. The ordinary environment API key from [Get your API key](/overview/get-api-key) does not work with Nexus PDP: the container fails at startup. Services that query Nexus PDP send the same Nexus PDP API key as their SDK `token` (the `Authorization: Bearer` value); Nexus PDP rejects the environment API key with HTTP `401`. The Permit API (`permit.api`) also accepts the Nexus PDP API key, with the same access as the environment API key, so one SDK client configured with the Nexus PDP API key runs both permission checks and Permit API calls. Protect the Nexus PDP API key as you protect the environment API key.
- A container platform that provides persistent volumes, such as Kubernetes.

## Deployment requirements
Expand All @@ -19,8 +19,8 @@ Nexus PDP has operational requirements that the container PDP (the Edge PDP imag

| Requirement | Setting | What happens if you skip it |
| --- | --- | --- |
| Image | `permitio/pdp-v3`, pinned to a specific tag | An unpinned image can pull a release with renamed configuration variables. See [Nexus PDP configuration reference](/concepts/pdp/nexus-pdp-configuration). |
| One container per environment | Set `PDP_API_KEY` to the API key of one Permit environment | Nexus PDP has no multi-environment mode. The API key binds the container to exactly one environment. |
| Image | `permitio/nexus-pdp`, pinned by digest (`permitio/nexus-pdp@sha256:<digest>`) | `permitio/nexus-pdp` has no `latest` tag, so a pull without a tag fails. Tags can move: `0-beta` moves to each new beta or release build, and a numbered beta tag name can be published again for a later build. A new build can rename configuration variables. See [Nexus PDP configuration reference](/concepts/pdp/nexus-pdp-configuration). |
| One container per environment | Set `PDP_API_KEY` to the Nexus PDP API key of one Permit environment | Nexus PDP has no multi-environment mode. The Nexus PDP API key binds the container to exactly one environment. |
| Persistent storage | Mount a persistent volume at `/var/lib/edge-pdp`, which holds the embedded database and the event store at default paths | On ephemeral storage, every restart runs a full cold start with a snapshot transfer of your whole data set. |
| Memory | 4 GiB to start | At default storage-engine settings, a container with a few hundred MiB is killed for running out of memory (OOM) at startup. See [Nexus PDP resource footprint](/concepts/pdp/nexus-pdp-how-it-works#resource-footprint). |
| Volume permissions | The volume is writable by user ID and group ID `10001` | Nexus PDP runs as the non-root user `10001` and cannot write its database or event store. |
Expand All @@ -32,28 +32,35 @@ Nexus PDP has operational requirements that the container PDP (the Edge PDP imag

## Run Nexus PDP with Docker

Replace `<tag>` with a specific `permitio/pdp-v3` release tag, and set `PERMIT_API_KEY` in your shell to the API key of the environment this container serves. The command maps the authorization API to host port `7766`, keeps the health port on `7001`, and stores the embedded database in the named volume `nexus-data`:
Replace `<digest>` with the digest of the `permitio/nexus-pdp` build you deploy (see [Image name and tags](/concepts/pdp/nexus-pdp#image-name-and-tags)), and set `NEXUS_PDP_API_KEY` in your shell to the Nexus PDP API key of the environment this container serves. The command maps the authorization API to host port `7766`, keeps the health port on `7001`, and stores the embedded database in the named volume `nexus-data`:

```bash
docker run -d --name nexus-pdp \
-p 7766:7000 -p 7001:7001 \
-e PDP_API_KEY="$PERMIT_API_KEY" \
-e PDP_API_KEY="$NEXUS_PDP_API_KEY" \
-v nexus-data:/var/lib/edge-pdp \
--memory 4g \
permitio/pdp-v3:<tag>
permitio/nexus-pdp@sha256:<digest>
```

## Kubernetes pod settings for Nexus PDP

This pod-spec excerpt sets the ports, probes, memory request, volume, and shutdown budget from the requirements table. `fsGroup: 10001` makes the mounted volume writable by the non-root user that Nexus PDP runs as. Create the `permit-env-api-key` secret with the environment API key, size the `nexus-pdp-data` claim for your data set, and add a startup probe with enough time for a cold start:
This pod-spec excerpt sets the ports, probes, memory request, volume, and shutdown budget from the requirements table. `fsGroup: 10001` makes the mounted volume writable by the non-root user that Nexus PDP runs as. Create the `nexus-pdp-api-key` secret with the environment's Nexus PDP API key under the key `PDP_API_KEY`, which the pod spec reads, reusing the shell variable from the Docker step:

```bash
kubectl create secret generic nexus-pdp-api-key \
--from-literal=PDP_API_KEY="$NEXUS_PDP_API_KEY"
```

Then size the `nexus-pdp-data` claim for your data set, and add a startup probe with enough time for a cold start:

```yaml
terminationGracePeriodSeconds: 40
securityContext:
fsGroup: 10001
containers:
- name: nexus-pdp
image: permitio/pdp-v3:<tag>
image: permitio/nexus-pdp@sha256:<digest>
ports:
- containerPort: 7000 # authorization API
- containerPort: 7001 # health
Expand All @@ -64,7 +71,7 @@ containers:
- name: PDP_API_KEY
valueFrom:
secretKeyRef:
name: permit-env-api-key
name: nexus-pdp-api-key
key: PDP_API_KEY
livenessProbe:
httpGet: { path: /health, port: 7001 }
Expand All @@ -86,7 +93,7 @@ The macOS AirPlay Receiver uses port `7000`. Map the Nexus PDP authorization API
## Verify a Nexus PDP deployment

1. Send `GET /health/ready` to the health port, `7001`: `curl -i http://localhost:7001/health/ready`. Nexus PDP returns HTTP `200` when every component that gates readiness is up, and HTTP `503` while any of them is still starting. A cold start can take minutes on a large data set, so retry until the response is `200`.
2. Point an SDK at the authorization port and run a permission check. With the port mapping in [Run Nexus PDP with Docker](#run-nexus-pdp-with-docker), the PDP URL is `http://localhost:7766`. See [Check permissions](/how-to/enforce-permissions/check). A decision that matches your policy confirms that Nexus PDP has your policy and data.
2. Set the SDK's PDP URL to the authorization port and its `token` to the Nexus PDP API key, then run a permission check. With the port mapping in [Run Nexus PDP with Docker](#run-nexus-pdp-with-docker), the PDP URL is `http://localhost:7766`. See [Check permissions](/how-to/enforce-permissions/check), and use the Nexus PDP API key wherever that page uses the environment API key. A decision that matches your policy confirms that Nexus PDP has your policy and data.

## Health and readiness

Expand Down Expand Up @@ -143,7 +150,7 @@ Four properties of the container decide how you place, scope, and isolate a Nexu

| Property | What it means for your deployment |
|---|---|
| [Request authentication](#request-authentication) | Every caller needs the container's own `PDP_API_KEY`. Treat the key as a shared secret between the container and the services that query it. |
| [Request authentication](#request-authentication) | Every caller needs the container's own `PDP_API_KEY`. The key also has environment-level access to the Permit API, so give it the same protection as the environment API key. |
| [One environment per container](#one-environment) | Run one container per Permit environment, and route each service to the container for its environment. |
| [Child process isolation](#child-process-environment) | Variables you set on the container do not all reach OPA and the NATS leaf node. Set Nexus PDP variables, not OPA or NATS variables. |
| [Blast radius](#blast-radius) | A compromised container exposes one environment. Apply the network policy and secret scope of that environment to it. |
Expand All @@ -154,7 +161,7 @@ Nexus PDP compares the bearer token on each authorization request, in constant t

### One Nexus PDP container serves one environment \{#one-environment}

Nexus PDP fixes its environment at startup from `PDP_API_KEY`. A valid API key for a different environment does not authenticate against the container, and a caller cannot direct a request at data outside the container's environment.
Nexus PDP fixes its environment at startup from `PDP_API_KEY`, and accepts only that key. Any other key, including the environment API key of the same environment, does not authenticate against the container, and a caller cannot direct a request at data outside the container's environment.

### Child processes start with a cleared environment \{#child-process-environment}

Expand Down
6 changes: 3 additions & 3 deletions docs/concepts/pdp/nexus-pdp-feature-parity.mdx
Original file line number Diff line number Diff line change
@@ -1,19 +1,19 @@
---
title: Nexus PDP feature parity
sidebar_label: Feature Parity
description: "Compare the endpoints and capabilities of the container PDP (permitio/pdp-v2) and Permit Nexus PDP (permitio/pdp-v3) before you choose one."
description: "Compare the endpoints and capabilities of the container PDP (permitio/pdp-v2) and Permit Nexus PDP (permitio/nexus-pdp) before you choose one."
sidebar_position: 4
---

Use this page to check whether Permit Nexus PDP, a self-hosted policy decision point (PDP), supports the endpoints and capabilities your application uses before you choose Nexus PDP or move to it. The page compares Nexus PDP (`permitio/pdp-v3`) with the [container PDP](/concepts/pdp/overview#run-an-edge-pdp-with-docker), the Edge PDP image `permitio/pdp-v2`.
Use this page to check whether Permit Nexus PDP, a self-hosted policy decision point (PDP), supports the endpoints and capabilities your application uses before you choose Nexus PDP or move to it. The page compares Nexus PDP (`permitio/nexus-pdp`) with the [container PDP](/concepts/pdp/overview#run-an-edge-pdp-with-docker), the Edge PDP image `permitio/pdp-v2`.

:::info Nexus PDP support changes between releases
This comparison describes Nexus PDP as of September 2026, during early access. The set of supported capabilities changes between releases, so check this page before you upgrade.
:::

## Nexus PDP compatibility with container PDP endpoints

Nexus PDP accepts the same paths, request bodies, and response bodies as the container PDP on the endpoints that Nexus PDP implements. SDK calls to those endpoints work without code changes when you point the SDK at a Nexus PDP.
Nexus PDP accepts the same paths, request bodies, and response bodies as the container PDP on the endpoints that Nexus PDP implements. SDK calls to those endpoints work without other code changes when you set the SDK's PDP URL to a Nexus PDP and its `token` to the Nexus PDP API key.

Nexus PDP implements a subset of the container PDP's endpoints. Its capabilities match those of the managed [Cloud PDP](/concepts/pdp/cloud-pdp-capabilities), running in your own network.

Expand Down
4 changes: 2 additions & 2 deletions docs/concepts/pdp/nexus-pdp-how-it-works.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ A Nexus PDP that restarts with a backlog of changes becomes ready and serves req

Nexus PDP delivers a change to the PDP in fewer steps than the container PDP:

| | Container PDP (`pdp-v2`) | Nexus PDP (`pdp-v3`) |
| | Container PDP (`pdp-v2`) | Nexus PDP (`nexus-pdp`) |
| --- | --- | --- |
| Change notification | WebSocket notification | Push delivery on a durable subscription for each PDP |
| Data fetch | A second request to the Permit API | None. The message contains the change. |
Expand Down Expand Up @@ -117,7 +117,7 @@ Permit has not published measured throughput for Nexus PDP. The [Cloud PDP bench

Nexus PDP stores authorization data in a different place than the container PDP, which changes how you size the container.

| | Container PDP (`pdp-v2`) | Nexus PDP (`pdp-v3`) |
| | Container PDP (`pdp-v2`) | Nexus PDP (`nexus-pdp`) |
| --- | --- | --- |
| Authorization data | In OPA's in-memory document | On disk, in an embedded database |
| Memory as data grows | Grows with your data set | Limited by a cache size you configure |
Expand Down
8 changes: 7 additions & 1 deletion docs/concepts/pdp/nexus-pdp.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -11,14 +11,20 @@ import ProductOverviewLink from "@site/src/components/ProductOverviewLink";

Permit Nexus PDP is a self-hosted policy decision point (PDP) that keeps your environment's policy and authorization data in an embedded on-disk database. This page is for architects and platform engineers who decide whether to run Nexus PDP instead of, or next to, the container PDP.

Nexus PDP ships as the `permitio/pdp-v3` container image. You run one Nexus PDP container per Permit environment in your own network. Nexus PDP answers each authorization query from its local copy of the data, so no hop in the decision path leaves the container.
Nexus PDP ships as the `permitio/nexus-pdp` container image. You run one Nexus PDP container per Permit environment in your own network. Nexus PDP answers each authorization query from its local copy of the data, so no hop in the decision path leaves the container.
Comment thread
EliMoshkovich marked this conversation as resolved.

:::note Early access and relationship to the container PDP
Nexus PDP is an additional deployment option. It does not replace the container PDP (`permitio/pdp-v2`), which remains supported and is the PDP to use for the capabilities listed as unsupported in [Nexus PDP feature parity](/concepts/pdp/nexus-pdp-feature-parity).

As of September 2026, Nexus PDP is in early access and Permit enables it per account. To request access, [book a call with Permit](https://www.permit.io/demo).
:::

## Image name and tags \{#image-name-and-tags}

Nexus PDP releases up to 0.6.1 were published as `permitio/pdp-v3`. That repository receives no new tags; later builds are published only as `permitio/nexus-pdp`. To upgrade from `permitio/pdp-v3`, switch to `permitio/nexus-pdp` and pick a tag from it. Don't reuse a `pdp-v3` tag name: some tag names exist in both repositories and point to different images.

`permitio/nexus-pdp` has no `latest` tag, and its tags can move: `0-beta` moves to each new beta or release build, and a numbered beta tag name can be published again for a later build. Pin by digest. Pick a tag such as `0.7.0-beta.12` and read its digest with `docker buildx imagetools inspect --format '{{.Manifest.Digest}}' permitio/nexus-pdp:0.7.0-beta.12`. The command prints `sha256:` followed by the digest of the multi-platform image, which runs on both `amd64` and `arm64`. Deploy `permitio/nexus-pdp@sha256:<digest>`, where `<digest>` is the part after `sha256:`.

## Terms used on this page

| Term | Meaning |
Expand Down
Loading
Loading