PageSourceSearch

https://www.openpolicyagent.org/assets/js/8570ad82.1f4ddc17.js

js openpolicyagent.org collected 2026-09-24 08:31:21 UTC 27,916 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[29158],{19537:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>r,default:()=>h,frontMatter:()=>s,metadata:()=>i,toc:()=>d});var i=n(80047),o=n(74848),a=n(28453);const s={title:"Open Policy Agent 2022, Year in Review",authors:["anderseknert"],date:new Date("2023-01-26T00:00:00.000Z"),slug:"open-policy-agent-2022-year-in-review-79324ad54535"},r=void 0,l={authorsImageUrls:[void 0]},d=[{value:"Notable Events",id:"notable-events",level:2},{value:"2022 User Survey",id:"2022-user-survey",level:3},{value:"Open Policy Day with OPA",id:"open-policy-day-with-opa",level:3},{value:"Conferences and Meetups",id:"conferences-and-meetups",level:3},{value:"New Features",id:"new-features",level:2},{value:"New Keywords",id:"new-keywords",level:3},{value:"Refs in Rule Heads",id:"refs-in-rule-heads",level:3},{value:"Built-in Function Metadata and Metadata Introspection",id:"built-in-function-metadata-and-metadata-introspection",level:3},{value:"Testing",id:"testing",level:3},{value:"Policy and Data Distribution",id:"policy-and-data-distribution",level:3},{value:"Disk Storage",id:"disk-storage",level:3},{value:"Compiler Strict mode",id:"compiler-strict-mode",level:3},{value:"Intermediate Representation (IR)",id:"intermediate-representation-ir",level:3},{value:"Built-in functions",id:"built-in-functions",level:2},{value:"Performance Improvements",id:"performance-improvements",level:2},{value:"Ecosystem and integrations",id:"ecosystem-and-integrations",level:2},{value:"Gatekeeper",id:"gatekeeper",level:3},{value:"Conftest",id:"conftest",level:3},{value:"Integrations",id:"integrations",level:3},{value:"Credits",id:"credits",level:2}];function c(e){const t={a:"a",code:"code",em:"em",h2:"h2",h3:"h3",img:"img",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(t.p,{children:(0,o.jsx)(t.img,{alt:"Banner image for OPA 2022 year in review blog post",src:n(79261).A+"",width:"1400",height:"1400"})}),"\n",(0,o.jsx)(t.p,{children:"It's a new year, and once again it's time to look back and reflect on the year that passed in the world of Open Policy Agent! 2022 was OPA's first full year as a CNCF graduated project, and while it would be easy to think that things would slow down after reaching that point of maturity and recognition, things have rather sped up. In community growth as well as pace of development \u2014 both of which we'll take a closer look at here."}),"\n",(0,o.jsx)(t.p,{children:"This year, tech communities like ours enjoyed finally getting to meet in person again, and major conferences in our space, like KubeCon / CloudNativeCon, saw thousands of attendees in both Europe and North America. We also saw meetups, hackathons and other smaller gatherings move back from virtual to in-person events. On the topic of events \u2014 let's start our review of the year 2022 for Open Policy Agent there."}),"\n",(0,o.jsx)(t.h2,{id:"notable-events",children:"Notable Events"}),"\n",(0,o.jsx)(t.h3,{id:"2022-user-survey",children:"2022 User Survey"}),"\n",(0,o.jsxs)(t.p,{children:["While we queried our nearest OPA instance for policy decisions, we also queried the OPA community to learn about their experience of interacting with the project, documentation and tooling. The ",(0,o.jsx)(t.a,{href:"/blog/open-policy-agent-2022-user-survey-summary-370cf0243bb7",children:"survey results"})," provided us valuable insights into where we might want to spend some extra time and effort in 2023 \u2014 richer documentation with more examples was requested by many. We're also seeing a need to better highlight the benefits of the various management capabilities in OPA, like decision logging and monitoring. An interesting trend which continues from 2022 is the increasing number of OPA use cases inside organizations. While infrastru
1cture policies (including Kubernetes) still come out on top, we're seeing more organizations embrace OPA for policy across their whole stack. A standardized way of working with policy was always a goal of the project, so it's really exciting to see more organizations seeing the benefits of this approach!"]}),"\n",(0,o.jsx)(t.h3,{id:"open-policy-day-with-opa",children:"Open Policy Day with OPA"}),"\n",(0,o.jsxs)(t.p,{children:["This year we were excited to see an entire event dedicated to OPA \u2014 the Open Policy Day with OPA co-located with KubeCon North America. During the course of the day, attendees got to hear end-user stories on using OPA in production, with speakers from organizations like Nvidia, T-Mobile. Capital One, Chime and Snowflake. If you couldn't attend in person, all the talks are up on ",(0,o.jsx)(t.a,{href:"https://www.youtube.com/@styra6251/videos",children:"YouTube"}),"!"]}),"\n",(0,o.jsx)(t.h3,{id:"conferences-and-meetups",children:"Conferences and Meetups"}),"\n",(0,o.jsxs)(t.p,{children:["In the cloud-native space, OPA was represented in talks at both KubeCon / CloudNativeCon ",(0,o.jsx)(t.a,{href:"https://www.youtube.com/watch?v=MhyQxIp1H58&t=4s",children:"Europe"})," as well as ",(0,o.jsx)(t.a,{href:"https://www.youtube.com/watch?v=RMiovzGGCfI",children:"North America"}),". As the interest in policy as code grew over the year, we saw a number of talks, workshops and events focused on the topic, and many discovered the benefits of unified policy management across tech stacks and organizations."]}),"\n",(0,o.jsxs)(t.p,{children:["Additionally \u2014 while OPA has been, and continues to be, a popular topic at cloud-native, security and DevOps themed meetups, it's great to see new meetup groups dedicated entirely to the topic of OPA. Several OPA meetups took place in 2022, and we'd love to see that trend continue in the new year! If you'd like to host your own, ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/community",children:"let us know"}),"."]}),"\n",(0,o.jsx)(t.p,{children:"It was great to see so much buzz around OPA at these events, and much of that is thanks to the amazing work going on within the OPA projects \u2014 let's look into what's been going on there next!"}),"\n",(0,o.jsx)(t.h2,{id:"new-features",children:"New Features"}),"\n",(0,o.jsx)(t.p,{children:"OPA and Rego saw a record number of new features added in 2022."}),"\n",(0,o.jsx)(t.h3,{id:"new-keywords",children:"New Keywords"}),"\n",(0,o.jsxs)(t.p,{children:["A few new keywords made a big difference both to the aesthetics of Rego, as well as its functionality. First off, the new ",(0,o.jsxs)(t.a,{href:"https://www.openpolicyagent.org/docs/v0.38.1/policy-language/#every-keyword",children:[(0,o.jsx)(t.code,{children:"every"})," keyword"]}),' elegantly helps solve the problem of expressing "',(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/#for-some-and-for-all",children:"for all"}),'" type of queries:']}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-rego",children:'import future.keywords.every\n\nonly_dev_servers {\n    some site in sites\n    site.name == "dev"\n\n    every server in site.servers {\n        endswith(server.name, "-dev")\n    }\n}\n'})}),"\n",(0,o.jsxs)(t.p,{children:["Next, the new ",(0,o.jsx)(t.code,{children:"if"}),' keyword helps policy authors express their rules in the same way as they normally should be read \u2014 as conditional assignments: "allow is true if conditions x, y and z are true". As an added bonus, the ',(0,o.jsx)(t.code,{children:"if"})," keyword allows skipping the braces around single-line rule bodies, leading to rule constructs that read more like plain English:"]}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-rego",children:'allow {\n    "admin" in input.user.roles\n}\n'})}),"\n",(0,o.jsx)(t.p,{children:"May now be written as:"}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-rego",children:'allow if "admin" in input.user.roles\n'})}),"\n",(0,o.jsxs)(t.p,{children:["Similarly, the new ",(0,o.jsx)(t.code,{children:"contains"}),' keyword allows set-building partial rules to be expressed as "the set ',(0,o.jsx)(t.strong,{children:"contains"}),' x if conditions x, y and z are true":']}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-rego",children:'deny[message] {\n    input.user.security_clearance_level < 2\n    message := "Security clearance level 2 or higher required"\n}\n'})}),"\n",(0,o.jsx)(t.p,{children:"May now be written as:"}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-rego",children:'deny contains message if {\n    input.user.security_clearance_level < 2\n    message := "Security clearance level 2 or higher required"\n}\n'})}),"\n",(0,o.jsx)(t.h3,{id:"refs-in-rule-heads",children:"Refs in Rule Heads"}),"\n",(0,o.jsxs)(t.p,{children:['It is said that one of the hardest things in computer science is naming things\u2026 "',(0,o.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/releases/tag/v0.46.1",children:"refs in rule heads"}),"\" seems to support that claim! Don't let the name intimidate you though, this is a great addition to Rego! Dynamically creating deeply nested objects would previously often require the use of nested packages, with each package provided in its own file. This is no longer the case, as nesting can now be expressed in one place:"]}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-rego",children:'package policy\n\nclaims.user.name := concat(" ", [input.user.first_name, input.user.last_name])\n\nrequest.method := input.request.method\nrequest.valid := validate(input.request)\n'})}),"\n",(0,o.jsx)(t.p,{children:"Evaluating the policy package will now provide something like the below result:"}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-json",children:'{\n  "claims": {\n    "user": {\n      "name": "John Doe"\n    }\n  },\n  "request": {\n    "method": "PUT",\n    "valid": true\n  }\n}\n'})}),"\n",(0,o.jsx)(t.h3,{id:"built-in-function-metadata-and-metadata-introspection",children:"Built-in Function Metadata and Metadata Introspection"}),"\n",(0,o.jsxs)(t.p,{children:["Another exciting addition to Rego this year was the introduction of ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/annotations/",children:"metadata annotations"}),'. Previously, policy authors would have to devise custom methods and formats for annotating their policies, packages and rules with metadata in the form of comments. Native support for annotations now provides a unified way not only for authoring structured annotations, but also for parsing them using either the "opa inspect" command, programmatically from Go, or even from Rego policies themselves via the new built-in rego.metadata functions. Having a standardized way of annotating packages and rules with metadata should benefit both human consumers as well as tooling.']}),"\n",(0,o.jsx)(t.h3,{id:"testing",children:"Testing"}),"\n",(0,o.jsxs)(t.p,{children:["A major advantage of treating policy as code is that code is testable. Unit testing provides effective guardrails around policies and rules, and allows frequent updates without the risk of breaking things. While test-driven development has been considered a best practice for Rego since the start, one feature that many foun
1d missing was the ability to mock functions. ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-testing/#data-and-function-mocking",children:"Function mocking"})," allows replacing built-in functions, like http.send, or custom functions, with different implementations, commonly free of side-effects, all using the same ",(0,o.jsx)(t.code,{children:"with"})," keyword familiar to test authors."]}),"\n",(0,o.jsx)(t.h3,{id:"policy-and-data-distribution",children:"Policy and Data Distribution"}),"\n",(0,o.jsxs)(t.p,{children:["Policy is commonly only half of the equation when OPA makes decisions \u2014 having access to up-to-date ",(0,o.jsx)(t.em,{children:"data"})," related to users, endpoints or resources is often just as important. Data tends to be more dynamic in nature than policy, and certain types of deployments require a ",(0,o.jsx)(t.strong,{children:"lot"})," of data. The combination of huge datasets and frequently changing data would previously require continuous transfer of all required data in a bundle \u2014 even when only a few attributes had been updated. The introduction of ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/management-bundles/#delta-bundles",children:"delta bundles"})," solves this by providing a new bundle type containing only the changes to data made since the last fetch, i.e. the ",(0,o.jsx)(t.em,{children:"delta"}),". A much-awaited feature, and one that will help ensure OPA covers even the most complex of use cases going forward."]}),"\n",(0,o.jsxs)(t.p,{children:["Another introduction this year was support for ",(0,o.jsx)(t.a,{href:"https://opencontainers.org/",children:"OCI"})," ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/management-bundles/#oci-registry",children:"bundle registries"}),". In an increasingly containerized world, distribution of applications is no longer the only use case for containers, and providing policy and data using the same channels as you would for e.g. Docker images, simplify things considerably in many environments."]}),"\n",(0,o.jsx)(t.h3,{id:"disk-storage",children:"Disk Storage"}),"\n",(0,o.jsxs)(t.p,{children:["While delta bundles may solve the problem of ",(0,o.jsx)(t.em,{children:"distributing"}),' large volumes of data, that data must eventually still be stored somewhere for OPA to make use of it. Up until this year, only a single option for storage was provided: in-memory. While this is normally the best place to store it for fast access, large datasets distributed in-memory across a large number of running instances quickly adds up, and many are those who learnt the hard way that the old slogan of "memory is cheap" isn\'t always true at scale. The ',(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/configuration/#disk-storage",children:"disk based storage"})," option now provides a balance between performance and costs, and is a welcome addition to OPA in many types of integrations."]}),"\n",(0,o.jsx)(t.h3,{id:"compiler-strict-mode",children:"Compiler Strict mode"}),"\n",(0,o.jsxs)(t.p,{children:["The Topdown compiler in OPA was enhanced with a new ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/strict/",children:"strict mode"})," option, allowing policy authors to catch common mistakes before deploying their policy to production. Unused imports and variables, or use of deprecated built-in functions \u2014 now all flagged by the compiler with strict mode turned on. Together with JSON schema-based ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/schemas/",children:"type checking"}),", developers are provided some powerful tools to ensure the robustness of their policy. Guard rails around the guard rails!"]}),"\n",(0,o.jsx)(t.h3,{id:"intermediate-representation-ir",children:"Intermediate Representation (IR)"}),"\n",(0,o.jsxs)(t.p,{children:["The OPA project has the ambitious goal of standardizing policy across the full stack, because of this it's sometimes necessary to consider alternative deployment models to the traditional standalone service. This year we saw OPA provide a new ",(0,o.jsx)(t.a,{href:"/blog/i-have-a-plan-exploring-the-opa-intermediate-representation-ir-format-7319cd94b37d",children:"intermediate representation"})," format, allowing custom implementations to parse and execute evaluation plans. An implementation for the JVM and Javascript has already been made available with the ",(0,o.jsx)(t.a,{href:"https://github.com/borgeby/jarl",children:"Jarl"})," project, and hopefully we'll see more to follow in 2023!"]}),"\n",(0,o.jsx)(t.h2,{id:"built-in-functions",children:"Built-in functions"}),"\n",(0,o.jsxs)(t.p,{children:["20 new ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#built-in-functions",children:"built-in functions"})," got added in 2022 \u2014 more than any year before! We saw new functions in almost every existing category, and OPA's exciting new ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/graphql-api-authorization/",children:"GraphQL"})," capabilities create a category of their own."]}),"\n",(0,o.jsxs)(t.p,{children:[(0,o.jsx)(t.strong,{children:"GraphQL"}),": ",(0,o.jsx)(t.code,{children:"graphql.is_valid"}),", ",(0,o.jsx)(t.code,{children:"graphql.parse"}),", ",(0,o.jsx)(t.code,{children:"graphql.parse_and_verify"}),", ",(0,o.jsx)(t.code,{children:"graphql.parse_query"}),", ",(0,o.jsx)(t.code,{children:"graphql.parse_schema"}
1),", ",(0,o.jsx)(t.code,{children:"graphql.schema_is_valid"})]}),"\n",(0,o.jsxs)(t.p,{children:[(0,o.jsx)(t.strong,{children:"Strings"}),": ",(0,o.jsx)(t.code,{children:"indexof_n"}),", ",(0,o.jsx)(t.code,{children:"regex.replace"}),", ",(0,o.jsx)(t.code,{children:"strings.any_prefix_match"}),", ",(0,o.jsx)(t.code,{children:"strings.any_suffix_match"})]}),"\n",(0,o.jsxs)(t.p,{children:[(0,o.jsx)(t.strong,{children:"Objects"}),": ",(0,o.jsx)(t.code,{children:"object.subset"}),", ",(0,o.jsx)(t.code,{children:"object.union_n"}),", ",(0,o.jsx)(t.code,{children:"object.keys"})]}),"\n",(0,o.jsxs)(t.p,{children:[(0,o.jsx)(t.strong,{children:"Crypto"}),": ",(0,o.jsx)(t.code,{children:"crypto.hmac.md5"}),", ",(0,o.jsx)(t.code,{children:"crypto.hmac.sha1"}),", ",(0,o.jsx)(t.code,{children:"crypto.hmac.sha256"}),", ",(0,o.jsx)(t.code,{children:"crypto.hmac.sha512"})]}),"\n",(0,o.jsxs)(t.p,{children:[(0,o.jsx)(t.strong,{children:"Misc"}),": ",(0,o.jsx)(t.code,{children:"providers.aws.sign_req"}),", ",(0,o.jsx)(t.code,{children:"net.cidr_is_valid"}),", ",(0,o.jsx)(t.code,{children:"graph.reachable_paths"})]}),"\n",(0,o.jsx)(t.h2,{id:"performance-improvements",children:"Performance Improvements"}),"\n",(0,o.jsx)(t.p,{children:"Some improvements are more understated, though no less noteworthy. As a mature software project, deployed in production in thousands of organizations across the world, OPA needs to be both robust and performant. This year saw the following exciting improvements in OPA performance:"}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsxs)(t.li,{children:["The \u2014 optimize flag now works for more commands (previously only available for ",(0,o.jsx)(t.code,{children:"opa build"}),")"]}),"\n",(0,o.jsx)(t.li,{children:"Lazy objects optimization allows delaying evaluation of attributes until needed"}),"\n",(0,o.jsxs)(t.li,{children:["Built-in function optimizations for ",(0,o.jsx)(t.code,{children:"object.get"}),", ",(0,o.jsx)(t.code,{children:"in"}),", ",(0,o.jsx)(t.code,{children:"object.union_n"}),", and others"]}),"\n",(0,o.jsxs)(t.li,{children:["Two new highly optimized built-in functions for doing prefix and suffix matching ",(0,o.jsx)(t.em,{children:"en masse"}),": ",(0,o.jsx)(t.code,{children:"strings.any_prefix_match"})," and ",(0,o.jsx)(t.code,{children:"strings.any_suffix_match"})]}),"\n",(0,o.jsx)(t.li,{children:"Internal optimizations to set element addition, object insertion and set union."}),"\n"]}),"\n",(0,o.jsx)(t.h2,{id:"ecosystem-and-integrations",children:"Ecosystem and integrations"}),"\n",(0,o.jsx)(t.h3,{id:"gatekeeper",children:"Gatekeeper"}),"\n",(0,o.jsxs)(t.p,{children:["A whole lot of great things landed in the Gatekeeper project this year! Following recent developments, Gatekeeper was made compatible with the Kubernetes v1.25 shift from Pod Security Policies to Pod Security Admission. On the topic of Kubernetes workloads, the new ",(0,o.jsx)(t.a,{href:"https://open-policy-agent.github.io/gatekeeper/website/docs/expansion",children:"Validation of Workload Resources"})," feature allows writing rules that apply to any Pod spec, whether deployed as a standalone pod or embedded in a parent resource, like a Deployment. Similarly, Gatekeeper now also allows validating subresources. The ",(0,o.jsx)(t.a,{href:"https://open-policy-agent.github.io/gatekeeper/website/docs/externaldata",children:"external data feature"}),", which, as the name implies, allows Gatekeeper to interface with various external data sources for validation and mutation, moved to beta this year, and the next feature to do so is ",(0,o.jsx)(t.a,{href:"https://open-policy-agent.github.io/gatekeeper/website/docs/gator",children:"Gator"}),", which allows testing of Gatekeeper ConstraintTemplates and Constraints in a local environment. Finally, the mutation feature is now considered stable."]}),"\n",(0,o.jsx)(t.p,{children:"In addition to all the features listed above, Gatekeeper is now faster than ever before! Some of the most notable improvements include reduced time for template compilation, adding and evaluating constraints, a whopping ~20X reduction in persistent audit memory usage, reduced request duration for policies with replicated data and reduced CPU time when adding data to OPA storage."}),"\n",(0,o.jsxs)(t.p,{children:["The ecosystem around Gatekeeper also saw improvements this year, where the most notable ones were the new Gatekeeper Policies ",(0,o.jsx)(t.a,{href:"https://open-policy-agent.github.io/gatekeeper-library/website",children:"website"}),", and the inclusion of Gatekeeper policies on ",(0,o.jsx)(t.a,{href:"https://artifacthub.io/packages/search?repo=gatekeeper-policies",children:"ArtifactHub"}),"."]}),"\n",(0,o.jsx)(t.h3,{id:"conftest",children:"Conftest"}),"\n",(0,o.jsx)(t.p,{children:"Conftest saw a rapid pace of development this year, with 12 releases pushed \u2014 from version 0.29.0, and ending in ver
1sion 0.37.0! The project added support for policy authoring using a number of additional file types \u2014 like env, hcl, jsonc, CycloneDX, and SPDX \u2014 as input. Possibly even more exciting is the addition of several new built-in functions exclusive to Conftest, like parse_config, parse_config_file, and parse_combined_config. These functions all allow policy authors to pull in configuration to test from inside of a policy, allowing a greater deal of flexibility in how config tests are executed."}),"\n",(0,o.jsxs)(t.p,{children:["The tooling around Conftest improved as well: when using the ",(0,o.jsx)(t.code,{children:"--version"})," flag, the version of OPA used by Conftest will now also be displayed. Additionally, the new ",(0,o.jsx)(t.code,{children:"--quiet"})," flag allows excluding anything but errors in the output, which should help in quickly identifying issues."]}),"\n",(0,o.jsx)(t.h3,{id:"integrations",children:"Integrations"}),"\n",(0,o.jsxs)(t.p,{children:["OPA would not be what it is without its massive ecosystem of tools, integrations and useful and fun projects. The year started out with some great news in the infrastructure space, with AWS opening up for the possibility of externalizing compliance checks of CloudFormation templates via hooks, and it did not take long for the ",(0,o.jsx)(t.a,{href:"https://github.com/StyraInc/opa-aws-cloudformation-hook",children:"AWS CloudFormation hook for OPA"})," to arrive on the scene. Later this year, Hashicorp announced ",(0,o.jsx)(t.a,{href:"https://developer.hashicorp.com/terraform/cloud-docs/policy-enforcement",children:"support for OPA"})," in their Terraform Cloud offering. A ",(0,o.jsx)(t.a,{href:"https://github.com/pulumi/pulumi-policy-opa",children:"Pulumi"})," integration was also added to the ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/ecosystem/",children:"ecosystem"}),". The message seems clear \u2014 the tool to use for infrastru
1cture as code (IaC) compliance is OPA, and the language to define IaC policies is Rego!"]}),"\n",(0,o.jsxs)(t.p,{children:["Outside of the infrastructure space, we saw a number of interesting integrations being built by the community, like ",(0,o.jsx)(t.a,{href:"https://github.com/dolevf/Open-Policy-Agent-Alfred",children:"Alfred"}),", a Rego Playground you can self host, a ",(0,o.jsx)(t.a,{href:"https://circleci.com/docs/config-policy-management-overview/",children:"CircleCI"})," integration for CI/CD pipeline policies, ",(0,o.jsx)(t.a,{href:"https://github.com/open-policy-agent/contrib/tree/main/opa_fig_autocomplete",children:"fig"})," support for command line auto-completion goodness, ",(0,o.jsx)(t.a,{href:"https://docs.walt.id/v/ssikit/ssi-kit/open-policy-agent",children:"self-sovereign identity"})," (SSI) integrations, and even policy-driven access to remote systems via ",(0,o.jsx)(t.a,{href:"https://github.com/Snowflake-Labs/sansshell",children:"SansShell"}),". OPA-powered policy enforcement even made it to the desktop this year, with the CISA-developed ",(0,o.jsx)(t.a,{href:"https://github.com/cisagov/ScubaGear/",children:"ScubaGear"})," project using Rego for validating M365 tenant configurations!"]}),"\n",(0,o.jsxs)(t.p,{children:["Finally, a much awaited addition to the OPA ecosystem \u2014 the ",(0,o.jsx)(t.a,{href:"https://github.com/StyraInc/rego-style-guide",children:"Rego Style Guide"})," now offers policy authors a comprehensive set of rules and best practices for authoring Rego."]}),"\n",(0,o.jsxs)(t.p,{children:["For a more comprehensive list of OPA integrations, check out the OPA ",(0,o.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/ecosystem/",children:"ecosystem page"}),", and the ",(0,o.jsx)(t.a,{href:"https://github.com/anderseknert/awesome-opa",children:"Awesome OPA"})," list."]}),"\n",(0,o.jsx)(t.h2,{id:"credits",children:"Credits"}),"\n",(0,o.jsx)(t.p,{children:"None of the above would have been made possible without the amazing community around OPA. In 2022, we saw an incredible number of people contribute to the project in all imaginable ways \u2014 code, documentation, bug reports, support discussions, integrations and tools. OPA is being used more and more widely around the world, and in different domains. With this growth, it'd be easy to overlook the huge effort in growing a community to support the project. We know how hard the community has worked to get to where we are and for that we are immensely grateful. Thank you all for getting us to where we are today and laying the foundation for another fantastic year with Open Policy Agent."})]})}function h(e={}){const{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,o.jsx)(t,{...e,children:(0,o.jsx)(c,{...e})}):c(e)}},28453:(e,t,n)=>{n.d(t,{R:()=>s,x:()=>r});var i=n(96540);const o={},a=i.createContext(o);function s(e){const t=i.useContext(a);return i.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function r(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:s(e.components),i.createElement(a.Provider,{value:t},e.children)}},79261:(e,t,n)=>{n.d(t,{A:()=>i});const i=n.p+"assets/images/banner-fcb0ffaf1ef2b6e0249ff05f54423e9a.webp"},80047:e=>{e.exports=JSON.parse('{"permalink":"/blog/open-policy-agent-2022-year-in-review-79324ad54535","source":"@site/blog/2023-01-26-open-policy-agent-2022-year-in-review-79324ad54535.md","title":"Open Policy Agent 2022, Year in Review","description":"Banner image for OPA 2022 year in review blog post","date":"2023-01-26T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Anders Eknert","page":{"permalink":"/blog/authors/anderseknert"},"imageURL":"/img/blog/authors/anderseknert.jpeg","key":"anderseknert"}],"frontMatter":{"title":"Open Policy Agent 2022, Year in Review","authors":["anderseknert"],"date":"2023-01-26T00:00:00.000Z","slug":"open-policy-agent-2022-year-in-review-79324ad54535"},"unlisted":false,"prevItem":{"title":"Open Policy Agent 2023, Year in Review","permalink":"/blog/open-policy-agent-2023-year-in-review-4c12df22e351"},"nextItem":{"title":"OPA Newsletter: November 2022","permalink":"/blog/november-newsletter-9f3bbcb29405"}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.