1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[17508],{24435:(e,t,a)=>{a.d(t,{A:()=>n});const n=a.p+"assets/images/2-22de383d25e2ff8e848d4f491ea8d1d9.gif"},25982:e=>{e.exports=JSON.parse('{"permalink":"/blog/open-policy-agent-v0-19-release-921d49179440","source":"@site/blog/2020-04-23-open-policy-agent-v0-19-release-921d49179440.md","title":"Open Policy Agent v0.19 Release","description":"Open Policy Agent v0.19 release announcement banner","date":"2020-04-23T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Torin Sandall","page":{"permalink":"/blog/authors/tsandall"},"imageURL":"/img/blog/authors/tsandall.png","key":"tsandall"}],"frontMatter":{"title":"Open Policy Agent v0.19 Release","authors":["tsandall"],"date":"2020-04-23T00:00:00.000Z","slug":"open-policy-agent-v0-19-release-921d49179440"},"unlisted":false,"prevItem":{"title":"Open Policy Agent Survey Summary (Spring 2020)","permalink":"/blog/open-policy-agent-survey-summary-spring-2020-adaa46e61f0"},"nextItem":{"title":"Rego Design Principle #3: Optimize Performance Automatically","permalink":"/blog/rego-design-principle-3-optimize-performance-automatically-2d29ad3ce96d"}}')},25999:(e,t,a)=>{a.d(t,{A:()=>n});const n=a.p+"assets/images/1-df5f3f26bf616347c40fe1521314df6f.png"},28453:(e,t,a)=>{a.d(t,{R:()=>o,x:()=>i});var n=a(96540);const r={},s=n.createContext(r);function o(e){const t=n.useContext(s);return n.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function i(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:o(e.components),n.createElement(s.Provider,{value:t},e.children)}},53647:(e,t,a)=>{a.d(t,{A:()=>n});const n=a.p+"assets/images/banner-ed6f6401596843555ee2d652357f2220.webp"},71204:(e,t,a)=>{a.r(t),a.d(t,{assets:()=>l,contentTitle:()=>i,default:()=>d,frontMatter:()=>o,metadata:()=>n,toc:()=>c});var n=a(25982),r=a(74848),s=a(28453);const o={title:"Open Policy Agent v0.19 Release",authors:["tsandall"],date:new Date("2020-04-23T00:00:00.000Z"),slug:"open-policy-agent-v0-19-release-921d49179440"},i=void 0,l={authorsImageUrls:[void 0]},c=[{value:"Community Updates",id:"community-updates",level:2},{value:"Faster Parsing & Better Errors",id:"faster-parsing--better-errors",level:2},{value:"man(1) pages, http.send, and Emacs support",id:"man1-pages-httpsend-and-emacs-support",level:2},{value:"WebAssembly Update",id:"webassembly-update",level:2}];function h(e){const t={a:"a",blockquote:"blockquote",code:"code",em:"em",h2:"h2",img:"img",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.p,{children:(0,r.jsx)(t.img,{alt:"Open Policy Agent v0.19 release announcement banner",src:a(53647).A+"",width:"1232",height:"762"})}),"\n",(0,r.jsxs)(t.p,{children:["Last week we released OPA v0.19, containing 63 commits from 12 contributors (of which, 9 were external.) This release includes many important fixes and enhancements, as well as a new Rego parser written in Go that speeds up parsing time by ~100x in most cases. You can find more details on the ",(0,r.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/releases",children:"GitHub releases"})," page."]}),"\n",(0,r.jsx)(t.h2,{id:"community-updates",children:"Community Updates"}),"\n",(0,r.jsx)(t.p,{children:"Since many in-person events have gone virtual due to the COVID-19 crisis, there have been several virtual events, webinars and podcasts featuring OPA over the last few weeks. Here's a quick roundup:"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.a,{href:"https://twitter.com/LachlanEvenson",children:"@LachlanEvenson"}),' ("B-grade Bollywood Actor") and Serta\xe7 \xd6zercan (Software Engineer @Azure, OPA Gatekeeper maintainer, ',(0,r.jsx)(t.a,{href:"https://twitter.com/sozercan?lang=en",children:"@sozercan"}),") presented at the CNCF Member Webinar about ensuring compliance in Kubernetes using OPA Gatekeeper. ",(0,r.jsx)(t.a,{href:"https://www.cncf.io/webinars/ensuring-compliance-without-sacrificing-development-agility-and-operational-independence-in-k8s-with-opa-gatekeeper/",children:"Slides and recording are here"}),"."]}),"\n",(0,r.jsxs)(t.li,{children:["Michael Hausenblas (Developer Advocate at AWS, ",(0,r.jsx)(t.a,{href:"https://twitter.com/mhausenblas",children:"@mhausenblas"}),") ",(0,r.jsx)(t.a,{href:"https://www.youtube.com/watch?v=dlKXFYBngBw",children:"did a stream"})," talking about Deprek8 with Steve Wade (K8s consultant & Trainer and Platform Lead at Mettle). You can read more in this ",(0,r.jsx)(t.a,{href:"https://opensource.com/article/20/3/deprek8",children:"Deprek8 article on Opensource.com"}),"."]}),"\n",(0,r.jsxs)(t.li,{children:["Rosemary Wang (Developer Advocate at HashiCorp, ",(0,r.jsx)(t.a,{href:"https://twitter.com/joatmon08",children:"@joatmon08"}
1),") talked about security & policy for infrastructure as code on OWASP DevSlop! ",(0,r.jsx)(t.a,{href:"https://www.youtube.com/watch?v=KOTXCIN0yE0",children:"The stream included live demos of OPA, conftest and more."})]}),"\n",(0,r.jsxs)(t.li,{children:["Alex Krause (Software Engineer at QAware, ",(0,r.jsx)(t.a,{href:"https://twitter.com/alex0ptr",children:"@alex0ptr"}),") spoke at the Cloud Native Virtual Summit about cloud compliance with OPA. You can find the ",(0,r.jsx)(t.a,{href:"https://www.slideshare.net/QAware/cloud-compliance-with-open-policy-agent",children:"SlideShare presentation slides"}),". The stream is also ",(0,r.jsx)(t.a,{href:"https://gateway.on24.com/wcc/eh/2010041/lp/2235047/qaware-gmbh-cloud-compliance-with-open-policy-agent",children:"available"})," but requires registration."]}),"\n",(0,r.jsxs)(t.li,{children:["Kevin Harris (Cloud Architect at Microsoft) talked about how OPA and Kubernetes Admission Control at the ",(0,r.jsx)(t.a,{href:"https://www.youtube.com/watch?v=41Ecd8Uuyvs&feature=youtu.be",children:"Cyber Tech & Risk Virtual Event."})]}),"\n",(0,r.jsxs)(t.li,{children:["Daniel Mangum (Engineer at Crossplane.io, ",(0,r.jsx)(t.a,{href:"https://twitter.com/hasheddan?lang=en",children:"@hasheddan"}),") ",(0,r.jsx)(t.a,{href:"https://www.youtube.com/watch?v=TaF0_syejXc",children:"hosted me on The Binding Show to talk about OPA, Crossplane and more."})," I also joined SW Engineering Radio to talk about OPA and distributed policy enforcement in general. You can find the ",(0,r.jsx)(t.a,{href:"http://hwcdn.libsyn.com/p/b/c/c/bcc49f4be8bc53f1/Episode-406-Torin-Sandall-on-Distributed-Policy-Enforcement_.mp3?c_id=69980306&cs_id=69980306&destination_id=1520171&expiration=1587590198&hwt=48bcf40f509d2271f0952d1e51c23a6d",children:"SW Engineering Radio episode recording"}),"."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.a,{href:"https://thenewstack.io/open-policy-agent-authorization-for-the-cloud",children:"The New Stack published an article"})," from Tim Hinrichs (co-creator of OPA and founder of Styra, ",(0,r.jsx)(t.a,{href:"https://twitter.com/tlhinrichs",children:"@tlhinrichs"}),") describing various use cases organizations use OPA for today. Tim also recently published a ",(0,r.jsx)(t.a,{href:"/blog/rego-design-principle-1-syntax-should-reflect-real-world-policies-e1a801ab8bfb",children:"great series of blog posts about the design principles behind Rego"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(t.p,{children:["Since KubeCon 2019 in Barcelona, we have asked users to post Q&A style queries on Stack Overflow instead of slack.openpolicyagent.org. The reason is that most ",(0,r.jsx)(t.strong,{children:"answers posted on Slack are not discoverable"}),"! If you have Q&A style questions (e.g., ",(0,r.jsxs)(t.a,{href:"https://stackoverflow.com/questions/60083793/rego-testing-how-to-test-not-deny",children:['"How to test ',(0,r.jsx)(t.code,{children:"not deny"}),'?"']}),"), try posting on ",(0,r.jsx)(t.a,{href:"https://stackoverflow.com/questions/tagged/open-policy-agent",children:"Stack Overflow and tagging with open-policy-agent"}),"."]}),"\n",(0,r.jsx)(t.h2,{id:"faster-parsing--better-errors",children:"Faster Parsing & Better Errors"}),"\n",(0,r.jsxs)(t.p,{children:["The largest change in v0.19 is the new Rego parser, which is written from scratch in Go. Previously, OPA relied on a ",(0,r.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/blob/v0.18.0/ast/rego.peg",children:"generated"})," ",(0,r.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/blob/v0.18.0/ast/parser.go",children:"parser"})," that was defined using ",(0,r.jsx)(t.a,{href:"https://en.wikipedia.org/wiki/Parsing_expression_grammar",children:"PEG (Parsing Expression Grammar [wikipedia])"}),". Over the years, as the grammar has grown, and larger inputs have been thrown at it, the generated parser became a bottleneck (e.g., it could take about 10x longer to parse an input than compile and evaluate the query."]}),"\n",(0,r.jsx)(t.p,{children:'Inside OPA we were able to workaround the performance problems with caching, using Go\'s "encoding/json" package and manually convert
1ing to AST ("Abstract Syntax Tree") values when possible, etc. However, new users embedding OPA as a library would (understandably) make mistakes and wonder why performance was poor. The majority of the performance problems in the generated parser were due to a significant amount of heap allocations required to parse any input.'}),"\n",(0,r.jsx)(t.p,{children:'In addition to performance, we also struggled with usability around parser error messages. If the parser was not able to match an input, you would be presented with an error like "policy.rego:19: no match found". No match? Tell me more!'}),"\n",(0,r.jsxs)(t.p,{children:["Rather than attempt to continue incrementally improving the existing parser, we decided to rewrite it from scratch in Go. The result is a new parser that allocates significantly less memory (which improves performance by approximately 100x in most cases) and has better error messages. One important requirement for the new parser was backwards compatibility \u2014 the new parser could not break existing policies OR programs that embed OPA as a library (e.g., the parser APIs and the AST types also had to remain the same). To ensure we did not break existing (valid) policies, we checked for differences in the output of the old and new parser for hundreds of thousands of Rego snippets (which deserves another blog post in the future.) Lastly, we also applied the wonderful ",(0,r.jsx)(t.a,{href:"https://github.com/dvyukov/go-fuzz",children:"go-fuzz"})," project ",(0,r.jsx)(t.a,{href:"https://github.com/tsandall/fuzz-opa",children:"to the parser"})," to help catch crashes and other bugs."]}),"\n",(0,r.jsxs)(t.blockquote,{children:["\n",(0,r.jsxs)(t.p,{children:["Since we no longer have a declarative representation of the language grammar in Go, please refer to the ",(0,r.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#grammar",children:"ENBF grammar in the OPA documentation"})," as the authoritative source."]}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"The chart below shows the difference in performance between the old (v0.18 and earlier) and new (v0.19 and later) parser (log scale):"}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.img,{alt:"The chart below shows the difference in performance between the old (v0.18 and earlier) and new (v0.19 and later) parser (log scale)",src:a(25999).A+"",width:"1232",height:"762"})}),"\n",(0,r.jsx)(t.p,{children:"Overall, we are happy with the process. In the future we plan to continue optimizing performance in the parser and looking for ways to improve error messaging and usability."}),"\n",(0,r.jsx)(t.h2,{id:"man1-pages-httpsend-and-emacs-support",children:"man(1) pages, http.send, and Emacs support"}),"\n",(0,r.jsxs)(t.p,{children:["In addition to the new parser, v0.19 includes dozens of bugfixes and feature enhancements. ",(0,r.jsx)(t.a,{href:"https://github.com/olivierlemasle",children:"@olivierlemasle"})," contributed code to generate OPA man pages from the OPA CLI definitions. The ",(0,r.jsx)(t.code,{children:"man"})," pages are automatically available if you:"]}),"\n",(0,r.jsx)(t.pre,{children:(0,r.jsx)(t.code,{className:"language-bash",children:"brew install opa\n"})}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.img,{alt:"Install OPA with homebrew and use 'man opa' to learn about it.",src:a(24435).A+"",width:"1988",height:"1080"})}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.em,{children:"Install OPA with homebrew and use 'man opa' to learn about it."})}),"\n",(0,r.jsxs)(t.p,{children:[(0,r.jsx)(t.a,{href:"https://github.com/jpeach",children:"@jpeach"})," submitted a number of patches that improve testing and support for the ",(0,r.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#http",children:"http.send"})," built-in function. For example, policies can now explicitly set TLS server names as well as certificates and keys when invoking the built-in function (previously they could only come from the environment or local files). This is useful if you want to specify those values in data or as local variables inside the policy itself."]}),"\n",(0,r.jsxs)(t.p,{children:["Lastly, the release also includes a pointer to the new ",(0,r.jsx)(t.a,{href:"https://github.com/psibi/rego-mode",children:"rego-mode"})," Emacs package developed by ",(0,r.jsx)(t.a,{href:"https://github.com/psibi",children:"@psibi"}),". The package provides syntax highlighting, formatting and more. In the future, the package could be extended to support many of the same features as the OPA extension for VS Code."]}),"\n",(0,r.jsx)(t.h2,{id:"webassembly-update",children:"WebAssembly Update"}),"\n",(0,r.jsxs)(t.p,{children:["At KubeCon 2019 in San Diego we announced ",(0,r.jsx)(t.a,{href:"/blog/opa-v0-15-1-rego-on-webassembly-81c226c51be4",children:"support for compiling OPA policies into WebAssembly (Wasm)"}),". Wasm enables OPA policies to execute in new environments like CDNs, service proxies and more without requiring an out-of-process RPC call to query OPA."]}),"\n",(0,r.jsxs)(t.p,{children:["This week we are excited to release further support for Wasm in OPA with the new ",(0,r.jsx)(t.a,{href:"https://github.com/open-policy-agent/golang-opa-wasm",children:"golang-opa-wasm"})," project! This project wraps the ",(0,r.jsx)(t.a,{href:"http://wasmerio/go-ext-wasm",children:"wasmer
1io/go-ext-wasm"})," runtime library to provide convenient APIs for policy execution and more. The golang-opa-wasm SDK is still work-in-progress but feedback and contributions are welcome."]})]})}function d(e={}){const{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(h,{...e})}):h(e)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.