PageSourceSearch

https://opal.ac/assets/js/916d5c28.397097e8.js

js opal.ac collected 2026-10-04 00:22:26 UTC 6,366 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkdocumentation=globalThis.webpackChunkdocumentation||[]).push([[8281],{1675(e,n,t){t.r(n),t.d(n,{assets:()=>c,contentTitle:()=>r,default:()=>h,frontMatter:()=>a,metadata:()=>i,toc:()=>l});const i=JSON.parse('{"id":"getting-started/quickstart/docker-compose-config/opal-client","title":"OPAL Client","description":"The OPAL Client has three main functionalities that need to be highlighted.","source":"@site/docs/getting-started/quickstart/docker-compose-config/opal-client.mdx","sourceDirName":"getting-started/quickstart/docker-compose-config","slug":"/getting-started/quickstart/docker-compose-config/opal-client","permalink":"/getting-started/quickstart/docker-compose-config/opal-client","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{},"sidebar":"opalSidebar","previous":{"title":"Broadcast Channel","permalink":"/getting-started/quickstart/docker-compose-config/postgres-database"},"next":{"title":"OPAL Server","permalink":"/getting-started/quickstart/docker-compose-config/opal-server"}}');var s=t(1684),o=t(506);const a={},r="OPAL Client",c={},l=[{value:"1. The OPAL client can run OPA for you as an inline process",id:"1-the-opal-client-can-run-opa-for-you-as-an-inline-process",level:3},{value:"2. The OPAL client syncs OPA with latest policy code",id:"2-the-opal-client-syncs-opa-with-latest-policy-code",level:3},{value:"3. The OPAL client syncs OPA with latest policy data",id:"3-the-opal-client-syncs-opa-with-latest-policy-data",level:3},{value:"eOPA variant",id:"eopa-variant",level:3}];function d(e){const n={a:"a",admonition:"admonition",code:"code",h1:"h1",h3:"h3",header:"header",p:"p",pre:"pre",strong:"strong",...(0,o.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.header,{children:(0,s.jsx)(n.h1,{id:"opal-client",children:"OPAL Client"})}),"\n",(0,s.jsx)(n.p,{children:"The OPAL Client has three main functionalities that need to be highlighted."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yml",metastring:"showLineNumbers",children:'service:\n  opal_client:\n  image: permitio/opal-client:latest\n  environment:\n    - OPAL_SERVER_URL=http://opal_server:7002\n    - OPAL_LOG_FORMAT_INCLUDE_PID=true\n    - OPAL_INLINE_OPA_LOG_FORMAT=http\n  ports:\n    - "7766:7000"\n    - "8181:8181"\n  depends_on:\n    - opal_server\n  command: sh -c "./wait-for.sh opal_server:7002 --timeout=20 -- ./start.sh"\n'})}),"\n",(0,s.jsx)(n.h3,{id:"1-the-opal-client-can-run-opa-for-you-as-an-inline-process",children:"1. The OPAL client can run OPA for you as an inline process"}),"\n",(0,s.jsxs)(n.p,{children:["The OPAL client ",(0,s.jsx)(n.a,{href:"https://hub.docker.com/r/permitio/opal-client",children:"docker image"})," contains a built-in OPA agent,\nand can serve as fully-functional ",(0,s.jsx)(n.strong,{children:"authorization microservice"}),". OPA is solely responsible for ",(0,s.jsx)(n.strong,{children:"enforcing"})," and\n",(0,s.jsx)(n.strong,{children:"evaluating authorization queries"}),"."]}),"\n",(0,s.jsx)(n.admonition,{title:"FACT",type:"tip",children:(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"OPAL"})," is solely responsible for state-management, meaning it will keep the ",(0,s.jsx)(n.strong,{children:"policy"})," and ",(0,s.jsx)(n.strong,{children:"data"})," needed to evaluate queries\n",(0,s.jsx)(n.strong,{children:"up-to-date"}),"."]})}),"\n",(0,s.jsxs)(n.p,{children:["In our example ",(0,s.jsx)(n.code,{children:"docker-compose.yml"})," file, OPA is enabled and runs on port ",(0,s.jsx)(n.code,{children:":8181"})," which is exposed on the host machine."]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yml",metastring:"showLineNumbers {3}",children:'ports:\n  - "7766:7000"\n  - "8181:8181"\n'})}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"OPAL will manage the OPA process"}),". If the OPA process fails for some reason, OPAL will restart OPA and\nrehydrate the OPA cache with valid and up-to-date state. By rehydration, we mean that the policies and data\nwill be ",(0,s.jsx)(n.strong,{children:"re-downloaded"}),"."]}
1),"\n",(0,s.jsx)(n.h3,{id:"2-the-opal-client-syncs-opa-with-latest-policy-code",children:"2. The OPAL client syncs OPA with latest policy code"}),"\n",(0,s.jsxs)(n.p,{children:["OPAL ",(0,s.jsx)(n.strong,{children:"listens"})," to policy code update notifications and ",(0,s.jsx)(n.strong,{children:"downloads up-to-date policy bundles"})," from the server."]}),"\n",(0,s.jsx)(n.h3,{id:"3-the-opal-client-syncs-opa-with-latest-policy-data",children:"3. The OPAL client syncs OPA with latest policy data"}),"\n",(0,s.jsxs)(n.p,{children:["OPAL ",(0,s.jsx)(n.strong,{children:"listens"})," to policy data update notifications and ",(0,s.jsx)(n.strong,{children:"fetches the data from the sources"})," specified by the instructions\nsent from the server. OPAL can aggregate data from multiple sources. This may include your ",(0,s.jsx)(n.strong,{children:"APIs"}),", ",(0,s.jsx)(n.strong,{children:"databases"})," and ",(0,s.jsx)(n.strong,{children:"3rd party SaaS"}),"."]}),"\n",(0,s.jsx)(n.h3,{id:"eopa-variant",children:"eOPA variant"}),"\n",(0,s.jsx)(n.p,{children:"OPAL Client supports running eOPA as the inline engine."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yml",metastring:"showLineNumbers {3}",children:"service:\n  opal_client:\n    image: permitio/opal-client-eopa:latest\n"})}),"\n",(0,s.jsxs)(n.p,{children:["See ",(0,s.jsx)(n.code,{children:"docker/docker-compose-example-eopa.yml"})," for a full example. The engine exposes the same OPA-compatible HTTP API on ",(0,s.jsx)(n.code,{children:":8181"})," while OPAL keeps policies and data synchronized.\nRead more about eOPA ",(0,s.jsx)(n.a,{href:"https://github.com/open-policy-agent/eopa",children:"here"}),"."]})]})}function h(e={}){const{wrapper:n}={...(0,o.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},506(e,n,t){t.d(n,{R:()=>a,x:()=>r});var i=t(2888);const s={},o=i.createContext(s);function a(e){const n=i.useContext(o);return i.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function r(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:a(e.components),i.createElement(o.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.