PageSourceSearch

https://www.openpolicyagent.org/assets/js/991a6e95.5d81c9c3.js

js openpolicyagent.org collected 2026-09-24 08:28:38 UTC 7,488 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[9638],{28453:(e,n,t)=>{t.d(n,{R:()=>a,x:()=>r});var o=t(96540);const i={},s=o.createContext(i);function a(e){const n=o.useContext(s);return o.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function r(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:a(e.components),o.createElement(s.Provider,{value:n},e.children)}},31277:(e,n,t)=>{t.d(n,{A:()=>o});const o=t.p+"assets/images/2-5123de0363753f61cc9d17a244023290.webp"},36203:e=>{e.exports=JSON.parse('{"permalink":"/blog/what-is-policy-part-one-enforcement-bad8ea8eb35c","source":"@site/blog/2017-02-28-what-is-policy-part-one-enforcement-bad8ea8eb35c.md","title":"What is Policy? Part One: Enforcement","description":"Welcome to the Open Policy Agent project. If you\'re interested in topics like policy, enforcement, remediation, and compliance we\'d love to hear from you! Join us on Slack or check out the project on GitHub.","date":"2017-02-28T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Torin Sandall","page":{"permalink":"/blog/authors/tsandall"},"imageURL":"/img/blog/authors/tsandall.png","key":"tsandall"}],"frontMatter":{"title":"What is Policy? Part One: Enforcement","authors":["tsandall"],"date":"2017-02-28T00:00:00.000Z","slug":"what-is-policy-part-one-enforcement-bad8ea8eb35c"},"unlisted":false,"prevItem":{"title":"What is Policy? Part Two: Policy Engines","permalink":"/blog/what-is-policy-part-two-policy-engines-7ee1d972386b"}}')},62211:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>c,contentTitle:()=>r,default:()=>h,frontMatter:()=>a,metadata:()=>o,toc:()=>l});var o=t(36203),i=t(74848),s=t(28453);const a={title:"What is Policy? Part One: Enforcement",authors:["tsandall"],date:new Date("2017-02-28T00:00:00.000Z"),slug:"what-is-policy-part-one-enforcement-bad8ea8eb35c"},r=void 0,c={authorsImageUrls:[void 0]},l=[];function d(e){const n={a:"a",em:"em",img:"img",li:"li",p:"p",strong:"strong",ul:"ul",...(0,s.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(n.p,{children:(0,i.jsxs)(n.em,{children:["Welcome to the Open Policy Agent project. If you're interested in topics like policy, enforcement, remediation, and compliance we'd love to hear from you! Join us on ",(0,i.jsx)(n.a,{href:"http://slack-inviter-1327627577.us-west-2.elb.amazonaws.com",children:"Slack"})," or check out the project on ",(0,i.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa",children:"GitHub"}),"."]})}),"\n",(0,i.jsx)(n.p,{children:"This is the first in a two-part series about policy where we introduce definitions, concepts, and challenges in policy enforcement. In future series we'll examine the state of policy in the cloud-native ecosystem."}),"\n",(0,i.jsxs)(n.p,{children:["The word ",(0,i.jsx)(n.strong,{children:"policy"})," means different things to different people in different contexts. In the context of software systems, policies are the rules that govern how the system behaves."]}),"\n",(0,i.jsx)(n.p,{children:"Computers and humans use policy to answer questions such as:"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsx)(n.li,{children:"Is this user allowed to change the config of that service?"}),"\n",(0,i.jsx)(n.li,{children:"Is this VM allowed to accept TCP connections from that VM?"}),"\n",(0,i.jsx)(n.li,{children:"Which host should this container be deployed on?"}),"\n",(0,i.jsx)(n.li,{children:"Which workloads are running in the wrong geographic region?"}),"\n"]}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.img,{alt:"Diagram showing where policy decisions occur across a Scheduler, Host, Container, App, sshd, Network, and DB",src:t(88192).A+"",width:"396",height:"308"})}),"\n",(0,i.jsx)(n.p,{children:"We define policy to avoid repeating mistakes and ensure important requirements are met around cost, technology, security, legislation, internal conventions, and so on."}),"\n",(0,i.jsxs)(n.p,{children:["Understanding where requirements are met and where they aren't is by itself quite valuable (more on this in a later post), but eventually we need to ",(0,i.jsx)(n.strong,{children:"enforce"})," policy to ensure that systems behave the way policy says they should."]}),"\n",(0,i.jsx)(n.p,{children:"We enforce policy differently depending on the organization, the technology the policy applies to, and of course, the policy in question. In some cases, we rely on in-person communication whereas in other cases we embed special-purpose components into our systems that enforce policy automatically."}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.img,{alt:"Diagram of the policy maturity spectrum from tribal knowledge and wiki to hard-coded, config, and policy engines",src:t(31277).A+"",width:"425",height:"285"})}),"\n",(0,i.jsxs)(n.p,{children:["At one end of the spectrum, policies are ",(0,i.jsx)(n.strong,{children:"tribal knowledge"}),". They are not recorded anywhere, so if we to want to modify the system, or even understand how it's expected to behave, we ask someone."]}),"\n",(0,i.jsxs)(n.p,{children:["Eventually, we tire of answering (or asking) the same question so we record the answer ",(0,i.jsx)(n.strong,{children:"on the wiki"})," or ",(0,i.jsx)(n.strong,{children:"in the docs"}),". These docs always fall out of date eventually."]}),"\n",(0,i.jsxs)(n.p,{children:["When our companies grow rapidly, introduce automation, or are faced with frequent policy violations, we usually start ",(0,i.jsx)(n.strong,{children:"hard-coding"})," policy into our software. If policy could be defined once and forgotten, we would stop there. In reality, policy evolves. With hard-coded solutions we have to read the code to understand (let alone modify) policy. As a result policy becomes less accessible and more expensive to maintain."]}),"\n",(0,i.jsxs)(n.p,{children:["Once the pain of hard-coding becomes evident, we make our policies ",(0,i.jsx)(n.strong,{children:"configurable"})," in software (e.g., including config parameters or even going as far as defining custom ",(0,i.jsx)(n.a,{href:"https://en.wikipedia.org/wiki/Domain-specific_language",children:"DSLs"}),".) However, our ",(0,i.jsx)(n.a,{href:"https://en.wikipedia.org/wiki/Leaky_abstraction",children:"abstractions often leak"})," or cannot be adapted for future requirements. As a result, we spend more time and money on development, re-education, and upgrades. It turns out that predicting future requirements around cost, technology, internal 
1conventions, and so on, is HARD."]}),"\n",(0,i.jsxs)(n.p,{children:["The eventual conclusion of this progression is the ",(0,i.jsx)(n.strong,{children:"policy engine"}),": a tool for codifying and enforcing policies that is flexible enough to encompass a wide range of future requirements around cost, technology, internal conventions, and the like. It balances the desire to have programmatic enforcement (like hard-coding and configuration) with the need to update policy frequently and inexpensively (like tribal knowledge and the wiki)."]}),"\n",(0,i.jsx)(n.p,{children:"In our next post we'll look at policy engines, declarative languages, and the decoupling of policy decisions from enforcement. Thanks for reading!"})]})}function h(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(d,{...e})}):d(e)}},88192:(e,n,t)=>{t.d(n,{A:()=>o});const o=t.p+"assets/images/1-4ba5e0a4a923961357d763d331596529.webp"}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.