1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[10092],{2607:e=>{e.exports=JSON.parse('{"permalink":"/blog/open-policy-agent-2023-year-in-review-4c12df22e351","source":"@site/blog/2023-12-20-open-policy-agent-2023-year-in-review-4c12df22e351.md","title":"Open Policy Agent 2023, Year in Review","description":"Banner image for Open Policy Agent 2023 year in review post","date":"2023-12-20T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Anders Eknert","page":{"permalink":"/blog/authors/anderseknert"},"imageURL":"/img/blog/authors/anderseknert.jpeg","key":"anderseknert"}],"frontMatter":{"title":"Open Policy Agent 2023, Year in Review","authors":["anderseknert"],"date":"2023-12-20T00:00:00.000Z","slug":"open-policy-agent-2023-year-in-review-4c12df22e351"},"unlisted":false,"prevItem":{"title":"OPA 1.0 is coming. Here\'s what you need to know.","permalink":"/blog/opa-1-0-is-coming-heres-what-you-need-to-know-c8fb0d258368"},"nextItem":{"title":"Open Policy Agent 2022, Year in Review","permalink":"/blog/open-policy-agent-2022-year-in-review-79324ad54535"}}')},7684:(e,t,n)=>{n.d(t,{A:()=>o});const o=n.p+"assets/images/6-7fdde80ad41cb48c7568f7203040b47a.webp"},16936:(e,t,n)=>{n.d(t,{A:()=>o});const o=n.p+"assets/images/2-a6cff581d70f84e973887e3740a57cd0.webp"},28453:(e,t,n)=>{n.d(t,{R:()=>s,x:()=>r});var o=n(96540);const a={},i=o.createContext(a);function s(e){const t=o.useContext(i);return o.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function r(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:s(e.components),o.createElement(i.Provider,{value:t},e.children)}},34827:(e,t,n)=>{n.d(t,{A:()=>o});const o=n.p+"assets/images/3-02bfff9e02eb50a6cb90a77948a8a420.webp"},37750:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>r,default:()=>d,frontMatter:()=>s,metadata:()=>o,toc:()=>c});var o=n(2607),a=n(74848),i=n(28453);const s={title:"Open Policy Agent 2023, Year in Review",authors:["anderseknert"],date:new Date("2023-12-20T00:00:00.000Z"),slug:"open-policy-agent-2023-year-in-review-4c12df22e351"},r=void 0,l={authorsImageUrls:[void 0]},c=[{value:"OPA 'Away From Keyboard'",id:"opa-away-from-keyboard",level:2},{value:"From Strength to Strength",id:"from-strength-to-strength",level:2},{value:"New Features",id:"new-features",level:2},{value:"General references in rule heads",id:"general-references-in-rule-heads",level:3},{value:"Default keyword on functions",id:"default-keyword-on-functions",level:3},{value:"New built-in functions",id:"new-built-in-functions",level:3},{value:"Package scoped annotations",id:"package-scoped-annotations",level:3},{value:"Debugging",id:"debugging",level:3},{value:"Performance",id:"performance",level:3},{value:"Server",id:"server",level:3},{value:"Monitoring",id:"monitoring",level:3},{value:"Security",id:"security",level:3},{value:"Ecosystem",id:"ecosystem",level:2},{value:"Gatekeeper",id:"gatekeeper",level:3},{value:"Conftest",id:"conftest",level:3},{value:"OPA Ecosystem",id:"opa-ecosystem",level:3},{value:"Thanks",id:"thanks",level:2}];function h(e){const t={a:"a",code:"code",h2:"h2",h3:"h3",img:"img",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,i.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(t.p,{children:(0,a.jsx)(t.img,{alt:"Banner image for Open Policy Agent 2023 year in review post",src:n(89168).A+"",width:"1400",height:"800"})}),"\n",(0,a.jsx)(t.p,{children:"As 2023 draws to a close, the time has come to reflect on another important year for Open Policy Agent (OPA). Now more than two years deep into CNCF Graduated status, OPA continues to see accelerated growth in production deployments \u2014 and across a diverse range of use cases. Such use cases demand both performance and stability, while user base growth depends on learning resources and ease of use. This year, the OPA community has worked hard and delivered on all fronts, for new and experienced users alike. This post takes time to share how this was achieved; highlight prominent events and updates; celebrate input from the wider community and set the scene for a historic year of OPA in 2024."}),"\n",(0,a.jsx)(t.h2,{id:"opa-away-from-keyboard",children:"OPA 'Away From Keyboard'"}),"\n",(0,a.jsx)(t.p,{children:"While OPA users and maintainers predominantly collaborate online, there were a good number of occasions where OPA existed very much in the physical realm this year too."}),"\n",(0,a.jsxs)(t.p,{children:["KubeCon EU enabled a few OPA events in Amsterdam early this summer. For the first time ever, an OPA-themed ContribFest session was held, where OPA, ",(0,a.jsx)(t.a,{href:"https://www.conftest.dev",children:"Conftest"})," and ",(0,a.jsx)(t.a,{href:"https://github.com/open-policy-agent/gatekeeper",children:"OPA Gatekeeper"}
1)," maintainers worked with new contributors to the different OPA projects. In Amsterdam we also saw an OPA meet-up where speakers from ",(0,a.jsx)(t.a,{href:"https://medium.com/miro-engineering/how-miro-leverages-open-policy-agent-to-implement-authorization-as-a-service-763f08469e5",children:"Miro"}),", ",(0,a.jsx)(t.a,{href:"https://www.bankdata.dk",children:"Bankdata"})," and ",(0,a.jsx)(t.a,{href:"http://styra.com",children:"Styra"})," presented. At this KubeCon EU there were four OPA talks:"]}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.a,{href:"https://www.youtube.com/watch?v=XoWf4QcSbDw",children:"The Compliance Business Case for Kubernetes in the EU: Anders Eknert"})}),"\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.a,{href:"https://www.youtube.com/watch?v=6RNp3m_THw4",children:"Open Policy Agent. (OPA) Intro & Deep Dive \u2014 Charlie Egan, Rita Zhang"})}),"\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.a,{href:"https://www.youtube.com/watch?v=JSKNch6piyY",children:"Calling OPA from eBPF, Through WASM, in the Kernel? You've Gone Mad! \u2014 Nandor Kracser"})}),"\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.a,{href:"https://www.youtube.com/watch?v=BdeBhukLwt4",children:"Scratching an Itch: Running Policy in Hard to Reach Places with WASM & OPA \u2014 Charlie Egan"})}),"\n"]}),"\n",(0,a.jsx)(t.p,{children:(0,a.jsx)(t.img,{alt:"Contribfest session at KubeCon EU in Amsterdam",src:n(16936).A+"",width:"1400",height:"1051"})}),"\n",(0,a.jsx)(t.p,{children:(0,a.jsx)(t.img,{alt:"OPA Meetup in Amsterdam hosted by Miro",src:n(34827).A+"",width:"1400",height:"1051"})}),"\n",(0,a.jsxs)(t.p,{children:["Rolling forward a few months, OPA also had a strong presence in Chicago at KubeCon NA. KubeCon is a huge event and it was great to get so many eyes on OPA as part of the graduated projects update in the keynote session. On top of that, the OPA kiosk in the project pavilion was an important meeting place for maintainers and users at the event. Discussions covered all sorts of use cases from authorization of applications, Kubernetes admission, IAC policy and beyond. Don't forget to check out the ",(0,a.jsx)(t.a,{href:"https://www.youtube.com/watch?v=wJkjsvVpj_Q",children:"OPA project update"})," from the conference's maintainer track."]}),"\n",(0,a.jsx)(t.p,{children:(0,a.jsx)(t.img,{alt:"OPA Update on the big stage",src:n(72454).A+"",width:"1290",height:"641"})}),"\n",(0,a.jsx)(t.p,{children:(0,a.jsx)(t.img,{alt:"Open Policy Agent kiosk in the project pavilion",src:n(42209).A+"",width:"1400",height:"1051"})}),"\n",(0,a.jsx)(t.h2,{id:"from-strength-to-strength",children:"From Strength to Strength"}),"\n",(0,a.jsx)(t.p,{children:"OPA grows in so many different ways each year it's sometimes hard to know how to quantify it. Here are some highlighted figures which illustrate OPA's trajectory as we enter 2024."}),"\n",(0,a.jsxs)(t.p,{children:[(0,a.jsx)(t.strong,{children:"2700 Contributors"}),". ",(0,a.jsx)(t.a,{href:"https://opa.devstats.cncf.io/",children:"Nearly 3000"})," people have helped make OPA into the project it is today. Contributors help make OPA better by making changes to docs and code; by participating in GitHub discussions and by filing bugs. What's equally impressive is how these contributors are from over 450 different companies. OPA is a general purpose, domain agnostic policy engine so it's vital the project is guided by such a varied contributor base."]}),"\n",(0,a.jsxs)(t.p,{children:[(0,a.jsx)(t.strong,{children:"9 years"})," spent by users reading the documentation on the OPA website. This year OPA contributors worked hard and made over ",(0,a.jsx)(t.a,{href:"https://gist.github.com/charlieegan3/533ca9795787265c8b536b32fd8e2c8b",children:"160"})," updates to the docs; and so it's reassuring to look back at the end of the year and see just how many users benefited from the hard work."]}),"\n",(0,a.jsxs)(t.p,{children:[(0,a.jsx)(t.strong,{children:"2000 Go repositories build on OPA"}),". ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/integration/",children:"Integrating with OPA"})," has always been a priority so it's fantastic to see that just so many different projects are adding policy functionality in this way. With the ",(0,a.jsx)(t.a,{href:"https://pkg.go.dev/github.com/open-policy-agent/opa/sdk",children:"OPA SDK"}),", it's possible to bring all the best parts of OPA right into your Go application making it a powerful tool when standardizing your policy as code stack."]}),"\n",(0,a.jsxs)(t.p,{children:[(0,a.jsx)(t.strong,{children:"1.5 million Playground Runs."})," The ",(0,a.jsx)(t.a,{href:"https://play.openpolicyagent.org",children:"Rego Playground"})," is for every OPA user, it's there as a learning tool, as a collaborative scratch pad and now also integrates the output from ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/projects/regal",children:"Regal"}),", the new linter for Rego. On average, every 20s someone clicks the 'Evaluate' button on the playground, all day long, all year long. One of the major uses of the playground is for users and maintainers collaborating on supp
1ort in the OPA Slack, if you're interested in getting help within your team or on the Slack, creating a minimal example on the playground is a place to start."]}),"\n",(0,a.jsx)(t.p,{children:"It's not just OPA's community that's moving forward in leaps and bounds, OPA itself has been keeping pace and has received loads of great updates this year too. Let's dig into that now."}),"\n",(0,a.jsx)(t.h2,{id:"new-features",children:"New Features"}),"\n",(0,a.jsx)(t.h3,{id:"general-references-in-rule-heads",children:"General references in rule heads"}),"\n",(0,a.jsx)(t.p,{children:'The single most important addition to Rego this year was arguably general references in rule heads. Simply put, it is now possible to include variables in rule names (or "references"), making it possible to build complex, nested map structures which would previously require multiple rules distributed over several packages.'}),"\n",(0,a.jsx)(t.p,{children:'Example using dynamic policy composition to collect informative notices from all "rules" policies, and have them organized by category and title.'}),"\n",(0,a.jsx)(t.pre,{children:(0,a.jsx)(t.code,{className:"language-rego",children:"grouped_notices[category][title] contains notice if {\n some category, title\n rules_to_run[category][title]\n\n some notice in data.rules[category][title].notices\n}\n"})}),"\n",(0,a.jsx)(t.p,{children:"Output would be a nested structure, as expected:"}),"\n",(0,a.jsx)(t.pre,{children:(0,a.jsx)(t.code,{className:"language-json",children:'{\n "grouped_notices": {\n "testing": {\n "file-missing-test-suffix": ["ignored"]\n },\n "custom": {\n "naming-convention": ["ignored"],\n "one-liner-rule": ["obsolete", "ignored"]\n }\n }\n}\n'})}),"\n",(0,a.jsxs)(t.p,{children:["For more examples and information, see the ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-language/#rule-heads-containing-references",children:"OPA docs"})," on the topic."]}),"\n",(0,a.jsx)(t.h3,{id:"default-keyword-on-functions",children:"Default keyword on functions"}),"\n",(0,a.jsxs)(t.p,{children:['The default keyword has been around since forever, and is considered idiomatic for scenarios where a "fallback" value is needed, should rule evaluation fail in other rules sharing the same name. A long requested feature has been to extend support for default to cover custom functions, and 2023 was the year it ',(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-language/#default-keyword",children:"happened"}),"."]}),"\n",(0,a.jsx)(t.pre,{children:(0,a.jsx)(t.code,{className:"language-rego",children:'package functions\n\ndefault first_name(_) := "unknown"\n\nfirst_name(full_name) := split(full_name, " ")[0]\n'})}),"\n",(0,a.jsx)(t.h3,{id:"new-built-in-functions",children:"New built-in functions"}),"\n",(0,a.jsxs)(t.p,{children:["Seven new built-in functions were added to Rego this year. The ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-object-jsonverify_schema",children:"json.verify_schema"})," and ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-object-jsonmatch_schema",children:"json.match_schema"})," functions are both recent additions for evaluating policy against JSON schemas \u2014 a use case that's been increasingly common in recent times. The ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-time-timeformat",children:"time.format"})," function will help policy authors present dates and time using either a custom format, or one of the supported constants for ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#timestamp-parsing",children:"datetime formats"})," that were also added this year. Three new crypto functions were added: ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-crypto-cryptohmacequal",children:"crypto.hmac.equal"}),", ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-crypto-cryptox509parse_keypair",children:"crypto.x509.parse_keypair"}),", and ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-crypto-cryptoparse_private_keys",children:"crypto.parse_private_keys"}),". Finally, the new ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-numbers-numbersrange_step",children:"numbers.range_step"})," function, which works just as numbers.range, but with a configurable step value."]}),"\n",(0,a.jsx)(t.h3,{id:"package-scoped-annotations",children:"Package scoped annotations"}),"\n",(0,a.jsxs)(t.p,{children:["A metadata annotation using the scope of package is now truly ",(0,a.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/releases/tag/v0.50.0",children:"scoped to the package"}
1),', and not just the file in which it is declared. This allows for some interesting opportunities to separate metadata declarations from "implementing" packages, and build things like lightweight frameworks leveraging Rego\'s metadata annotations. Additionally, it\'ll allow defining package scoped annotations for "packages" created via general references in rule heads, where the package scope isn\'t directly allowed on the rule itself.']}),"\n",(0,a.jsx)(t.h3,{id:"debugging",children:"Debugging"}),"\n",(0,a.jsxs)(t.p,{children:['The Swiss army knife of OPA also known as "opa eval" got a new flag to help debugging policy this year. Using the ',(0,a.jsx)(t.code,{children:"--show-builtin-errors"})," flag, policy authors may now get a list of all errors produced by built-in functions as part of evaluation, making it much faster to identify certain types of problems."]}),"\n",(0,a.jsx)(t.h3,{id:"performance",children:"Performance"}),"\n",(0,a.jsxs)(t.p,{children:["OPA keeps getting faster, and in 2023 we saw some great improvements in this area. The ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-reference/#builtin-object-jsonpatch",children:"json.patch"})," built-in function was remodeled entirely and now performs extremely well even when provided with a huge list of changes. Performance isn't entirely in the hands of OPA though. Some ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-performance/",children:"optimizations"})," can only be performed at the level of an actual Rego policy, and OPA provides several tools to help policy authors with this. The ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-performance/#profiling",children:"profiler"})," (",(0,a.jsx)(t.code,{children:"opa eval --profile"}),") is one such tool, and from this year it'll now also include the number of generated expressions in evaluation. This helps policy authors better understand why some expressions are evaluated more times than what one might expect."]}),"\n",(0,a.jsx)(t.h3,{id:"server",children:"Server"}),"\n",(0,a.jsxs)(t.p,{children:["Several improvements to the server (and by extension, the ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/integration/#integrating-with-the-go-sdk",children:"OPA SDK"}),") landed in OPA this year. Bundle fetching now works with ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/configuration/#aws-signature",children:"AWS Signing Version 4A"}),", allowing bundles hosted on AWS to be distributed across different geographical regions. Also, a new shorthand format for quickly running the server pointed at a remote bundle was ",(0,a.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/releases/tag/v0.50.0",children:"introduced"}),". The OCI downloader saw several ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/v0.52.0/configuration/#using-private-image-from-oci-repositories",children:"new authentication methods"})," added. Finally, instance ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/v0.52.0/management-discovery/#limitations",children:"labels"})," may now be added via discovery allowing for greater flexibility in runtime re-configuration of long running OPAs."]}),"\n",(0,a.jsx)(t.h3,{id:"monitoring",children:"Monitoring"}),"\n",(0,a.jsxs)(t.p,{children:["Given the large number of OPA instances running in production, having a good story around monitoring is essential. The ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/management-status/#status-service-api",children:"status API"})," provides a way for any OPA deployed to report its current status to a centralized control plane or monitoring system. In 2023, several new metrics got added to the status reports, including most notably the request count for unauthorized calls to the OPA REST API when an ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/security/#authentication-and-authorization",children:"authentication/authorization policy"})," is in use, as well as errors that might have happened in ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/management-decision-logs/",children:"decision logging"}),"."]}),"\n",(0,a.jsx)(t.h3,{id:"security",children:"Security"}),"\n",(0,a.jsx)(t.p,{children:'2023 was the year the OPA docker images finally made rootless the default, and the special "-rootless" images that previously existed for this purpose are now obsolete. If you\'re still using them, make sure to remove the suffix from the image on your next version upgrade!'}),"\n",(0,a.jsx)(t.h2,{id:"ecosystem",children:"Ecosystem"}),"\n",(0,a.jsx)(t.h3,{id:"gatekeeper",children:"Gatekeeper"}),"\n",(0,a.jsx)(t.p,{children:"The OPA Gatekeeper project had a busy 2023, with many improvements landing this year. The external data feature allows users to connect with external data sources as part of policy evaluation. This year it gained support for caching of responses from external data providers for both audit and admission. A new AssignImage mutator which enables mutation of image registry or tag was also made available. The new PubSub feature (currently in alpha) enables users to subscribe to pubsub services to consume a large number of audit violations. Additionally, observability statistics for admission, audit and gator CLI are now available!"}),"\n",(0,a.jsx)(t.p,{children:"Speaking of the Gator CLI \u2014 the tool now prints violating object names on test output, and additionally supports trace and image flags. It may now also be provided an AdmissionReview object for verification."}),"\n",(0,a.jsx)(t.p,{children:"Using the new (experimental) Kubernetes Native Validation feature, users can now write CEL (Common Expression Language) based rules in addition to Rego rules in constraint templates, similar to Kubernetes ValidatingAdmissionPolicy. Finally, the ExpansionTemplate feature, which enables validation of workload resources, has graduated to beta."}),"\n",(0,a.jsx)(t.h3,{id:"conftest",children:"Conftest"}),"\n",(0,a.jsxs)(t.p,{children:["The Conftest project saw many improvements around tooling this year. A new ",(0,a.jsx)(t.code,{children:"--strict"})," flag was added to the verify and test commands, which will enforce additional safety checks on the policies such as unused arguments, duplicate imports, ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/docs/latest/policy-language/#strict-mode",children:"and more"}),". Two more flags got added: the ",(0,a.jsx)(t.code,{children:"--quiet"})," flag to the verify command which will silence success notifications and only show errors, and a ",(0,a.jsx)(t.code,{children:"--config"})," flag which allows users to specify where the config file to be tested lives. Test results may now also be emitted in a format compatible with Azure DevOps. On the topic of formats, a new input format was added to the already long list of supported ones, and ",(0,a.jsx)(t.a,{href:"https://protobuf.dev/reference/protobuf/textformat-spec/",children:"textproto"})," files may now be targeted for policy evaluation too. Finally, the Confest Docker images now also support both the ",(0,a.jsx)(t.code,{children:"linux/amd64"})," and ",(0,a.jsx)(t.code,{children:"linux/arm64"})," platforms."]}),"\n",(0,a.jsx)(t.h3,{id:"opa-ecosystem",children:"OPA Ecosystem"}),"\n",(0,a.jsxs)(t.p,{children:["One goal of the OPA project is to build a domain agnostic policy engine. Being domain agnostic is achieved by simultaneously building generic core policy functionality, while also supporting a range of out-of-the-box integrations for different use cases. This year, the wider OPA community has wholeheartedly delivered on the latter and listed 22 new integrations on the website. The OPA Ecosystem also has a
1new home as a top level page, where integrations can be browsed by category, ",(0,a.jsx)(t.a,{href:"http://openpolicyagent.org/ecosystem/",children:"check it out"}),"!"]}),"\n",(0,a.jsx)(t.p,{children:(0,a.jsx)(t.img,{alt:"New OPA Ecosystem Showcase",src:n(7684).A+"",width:"1400",height:"1064"})}),"\n",(0,a.jsx)(t.p,{children:"Most new ecosystem additions this year have been with other open source tools, generally adding policy functionality to a larger tool or leaning on Rego to provide a solid foundation for a domain-specific policy tool. Some notable examples include:"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsxs)(t.li,{children:["Source Code Management: ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/reposaur/",children:"Reposaur"}),", a repository compliance tool; and ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/legitify/",children:"Legitify"}),", a repository security configuration scanner."]}),"\n",(0,a.jsxs)(t.li,{children:["Supply Chain Security: ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/dependency-management-data/",children:"dependency-management-data"}),", helps understand software dependency posture; and ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/enterprise-contract/",children:"Enterprise Contract"})," verifies supply chain security artifacts with Rego policy."]}),"\n",(0,a.jsxs)(t.li,{children:["Infrastructure CD checks: ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/torque/",children:"Torque"}),", ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/spinnaker-pipeline/",children:"Spinnaker"})," integrate Rego-based checks for continuous deployment while ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/wirelesssecuritylab/",children:"ccbr"})," and ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/carbonetes/",children:"\u200b\u200bBrainIAC"})," support a range of checks on existing IAC codebases."]}),"\n",(0,a.jsxs)(t.li,{children:["Extending Authorization with OPA: The data orchestration tool ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/alluxio/",children:"Alluxio"})," now also supports delegation of permissions to OPA."]}),"\n"]}),"\n",(0,a.jsxs)(t.p,{children:[(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/digger/",children:"Digger"}),", an open source CI/CD orchestrator for Terraform both integrates OPA for user RBAC and leaning into existing tooling by leveraging OPA project ",(0,a.jsx)(t.a,{href:"http://conftest.dev",children:"conftest"})," for IAC policy."]}),"\n",(0,a.jsxs)(t.p,{children:["Meanwhile, other integrations went deeper and applied Rego in previously unexplored ways. ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/regocpp/",children:"regocpp"})," is a cutting-edge project from collaborators at Microsoft that aims to bring Rego to other environments, natively. Based on C++, regocpp supports a number of Rego built-ins and the grammar as of v0.55.0."]}),"\n",(0,a.jsxs)(t.p,{children:["The aforementioned linter, ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/integrations/regal/",children:"Regal"})," also pushes the boundaries of where Rego can be used to write policies. Using the JSON representation of the Rego abstract syntax tree, this project implements a range of ",(0,a.jsx)(t.a,{href:"https://www.openpolicyagent.org/projects/regal/rules",children:"linting rules"}),"\u2026 in Rego! Regal has already been deployed by a number of open source Rego policy libraries and now supports over 60 rules. Integrated with the ",(0,a.jsx)(t.a,{href:"https://play.openpolicyagent.org",children:"Rego Playground"})," the linter is already available to everyone. There's no doubt that this will be a great tool for OPA learners and long-timers alike while continuing to help ",(0,a.jsx)(t.a,{href:"https://thenewstack.io/scaling-open-source-community-by-getting-closer-to-users/",children:"scale"})," the OPA community."]}),"\n",(0,a.jsxs)(t.p,{children:["If you're interested in listing your OPA integration or project, please see ",(0,a.jsx)(t.a,{href:"https://github.com/open-policy-agent/opa/tree/main/docs#opa-ecosystem",children:"the instructions"})," or stop by the #ecosystem channel in the ",(0,a.jsx)(t.a,{href:"https://communityinviter.com/apps/openpolicyagent/signup",children:"OPA slack"})," if you have any questions."]}),"\n",(0,a.jsx)(t.h2,{id:"thanks",children:"Thanks"}),"\n",(0,a.jsx)(t.p,{children:"2023 was an exciting year for OPA and its community. With so many projects using, integrating or extending OPA for all sorts of use cases \u2014 and so many users helping to contribute in all sorts of ways \u2014 this community is truly a great place to be. Thank y
1ou all who helped make it so! Your efforts are seen and appreciated."}),"\n",(0,a.jsxs)(t.p,{children:["There's a lot of great stuff lined up for next year already, so buckle up, and let's ",(0,a.jsx)(t.code,{children:"import future.2024"}),"!"]}),"\n",(0,a.jsx)(t.p,{children:"Special thanks to Charlie Egan, Rita Zhang and John Reese for having helped contribute to this blog."})]})}function d(e={}){const{wrapper:t}={...(0,i.R)(),...e.components};return t?(0,a.jsx)(t,{...e,children:(0,a.jsx)(h,{...e})}):h(e)}},42209:(e,t,n)=>{n.d(t,{A:()=>o});const o=n.p+"assets/images/5-f20658f0ef54809dd759f3d3fa1f02ef.webp"},72454:(e,t,n)=>{n.d(t,{A:()=>o});const o=n.p+"assets/images/4-c712245c32f5b27dc7c35062c7c02c91.webp"},89168:(e,t,n)=>{n.d(t,{A:()=>o});const o=n.p+"assets/images/banner-3aef5a9f6f8712fbc815b94807a6c4f3.webp"}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.