# JAAS > JAAS is an enterprise layer on top of Juju that provides centralized controller management, OIDC authentication, and ReBAC authorization. 2026 CC-BY-SA, Canonical Group Ltd ## Pages in this subsection - [Explanation](https://documentation.ubuntu.com/jaas/latest/explanation.md): Understand JAAS concepts including reference architecture, authentication, authorization, ReBAC with OpenFGA, and security overview. - [Architecture](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-architecture.md): Understand JAAS architecture with JIMM, ReBAC authorization, OpenFGA, PostgreSQL database, and Vault secure storage components. - [Authentication](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-authentication.md): Understand JAAS authentication with OAuth 2.0 and OIDC, external identity providers, and how it differs from Juju local users. - [Authorization](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-authorization.md): Understand JAAS authorization with Relationship-Based Access Control (ReBAC) for flexible user permissions on controllers, models, and resources. - [ReBAC admin backend](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-rebac-admin-backend.md): Learn about the ReBAC Admin REST API for querying and manipulating relationships in JAAS authorization model with OpenAPI specification. - [Security overview](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-security.md): Comprehensive JAAS security overview covering cloud credentials, Vault storage, TLS communication, asymmetric cryptography, and data protection. - [Security scope](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-security-scope.md): Understand JAAS security scope including secure communication, TLS encryption, access control, authentication, and identity provider integration. - [Reference architecture](https://documentation.ubuntu.com/jaas/latest/explanation/reference-architecture.md): JAAS reference architecture covering automation, OAuth2/OIDC authentication, ReBAC authorization, Juju CLI, and Terraform Provider integration. ## Optional - [Top-level llms.txt](https://documentation.ubuntu.com/jaas/latest/llms.txt): Complete documentation index.