1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[22488],{12352:(n,e,t)=>{t.d(e,{A:()=>O});var i=t(96540),r=t(67489),a=t(12181),o=t(72444),s=t(10467),c=t(6342),l=t(95293);function u(){return d.apply(this,arguments)}function d(){return(d=(0,s.A)((0,o.A)().m((function n(){var e,i;return(0,o.A)().w((function(n){for(;;)switch(n.n){case 0:return n.n=1,Promise.all([t.e(59679),t.e(60483),t.e(37131)]).then(t.bind(t,37131));case 1:return e=n.v.default,n.n=2,t.e(92227).then(t.bind(t,92227));case 2:i=n.v.default,e.registerLayoutLoaders(i);case 3:return n.a(2,e)}}),n)})))).apply(this,arguments)}var h=null;function g(){return f.apply(this,arguments)}function f(){return(f=(0,s.A)((0,o.A)().m((function n(){return(0,o.A)().w((function(n){for(;;)if(0===n.n)return h||(h=u()),n.a(2,h)}),n)})))).apply(this,arguments)}var p="docusaurus-mermaid-container";function m(){var n=(0,l.G)().colorMode,e=(0,c.p)().mermaid,t=e.theme[n],r=e.options;return(0,i.useMemo)((function(){return Object.assign({startOnLoad:!1},r,{theme:t})}),[t,r])}function A(){return(A=(0,s.A)((0,o.A)().m((function n(e){var t,i,r,a,s,c;return(0,o.A)().w((function(n){for(;;)switch(n.p=n.n){case 0:return t=e.id,i=e.text,r=e.config,n.n=1,g();case 1:return(a=n.v).initialize(r),n.p=2,n.n=3,a.render(t,i);case 3:return n.a(2,n.v);case 4:throw n.p=4,c=n.v,null==(s=document.querySelector("#d"+t))||s.remove(),c;case 5:return n.a(2)}}),n,null,[[2,4]])})))).apply(this,arguments)}function b(n){var e=n.text,t=n.config,r=(0,i.useState)(null),a=r[0],o=r[1],s=(0,i.useState)("mermaid-svg-"+Math.round(1e7*Math.random()))[0],c=m(),l=null!=t?t:c;return(0,i.useEffect)((function(){(function(n){return A.apply(this,arguments)})({id:s,text:e,config:l}).then(o).catch((function(n){o((function(){throw n}))}))}),[s,e,l]),a}const P={container:"container_lyt7"};var v=t(74848);function y(n){var e=n.renderResult,t=(0,i.useRef)(null);return(0,i.useEffect)((function(){var n=t.current;null==e.bindFunctions||e.bindFunctions(n)}),[e]),(0,v.jsx)("div",{ref:t,className:p+" "+P.container,dangerouslySetInnerHTML:{__html:e.svg}})}function x(n){var e=b({text:n.value});return null===e?null:(0,v.jsx)(y,{renderResult:e})}function O(n){return(0,v.jsx)(r.A,{fallback:function(n){return(0,v.jsx)(a.MN,Object.assign({},n))},children:(0,v.jsx)(x,Object.assign({},n))})}},28243:(n,e,t)=>{t.r(e),t.d(e,{assets:()=>A,contentTitle:()=>m,default:()=>v,frontMatter:()=>p,metadata:()=>i,toc:()=>b});const i=JSON.parse('{"id":"management-introduction/index","title":"OPA Management APIs and Architecture","description":"OPA exposes a set of APIs that enable unified, logically centralized policy","source":"@site/docs/management-introduction/index.md","sourceDirName":"management-introduction","slug":"/management-introduction/","permalink":"/docs/management-introduction/","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{"title":"OPA Management APIs and Architecture","sidebar_label":"Overview"},"sidebar":"docsSidebar","previous":{"title":"CLI Reference","permalink":"/docs/cli"},"next":{"title":"Bundles","permalink":"/docs/management-bundles/"}}');var r=t(74848),a=t(28453),o=t(12352),s=t(75605).A,c='\ngraph TD;\n subgraph LM[<b>Library Model</b>]\n style LM fill:none,stroke:none;\n direction LR\n subgraph SI[Service Instance]\n style SI fill:none,stroke-dasharray: 7 5\n B_Service["Service Logic"] <--\x3e|Function Call| B_OPA["<img src=\''+s+"' width='30' height='30'/><br/>OPA\"];\n end\n B_Policy[\"Policy & Data\"] --\x3e B_OPA;\n end\n\n subgraph AM[<b>Agent Model</b>]\n style AM fill:none,stroke:none;\n direction LR\n subgraph NP[Node/Pod]\n style NP fill:none,stroke-dasharray: 7 5\n direction LR\n subgraph \"OPA Instance\"\n A_OPA[\"<img src='"+s+'\' width=\'30\' height=\'30\' /><br/>OPA"];\n end\n subgraph "App Instance"\n A_Service["Service Logic"] <--\x3e|HTTP Call| A_OPA\n end\n end\n A_Policy["Policy & Data"] --\x3e A_OPA;\n end\n';const l=function(){return(0,r.jsx)(o.A,{value:c})};var u=t(75605).A,d='\ngraph TD;\n subgraph SB[<b>Service B</b>]\n style SB fill:none,stroke:none;\n direction LR\n subgraph SBNP[Node/Pod]\n style SBNP fill:none,stroke-dasharray: 7 5\n direction LR\n subgraph "Local OPA Instance"\n B_OPA["<img src=\''+u+'\' width=\'30\' height=\'30\' /><br/>OPA"];\n end\n subgraph "App Instance"\n B_Service["Service Logic"] --\x3e|HTTP Call| B_OPA\n end\n end\n end\n\n subgraph SA[<b>Service A</b>]\n style SA fill:none,stroke:none;\n direction LR\n subgraph SANP[Node/Pod]\n style SANP fill:none,stroke-dasharray: 7 5\n direction LR\n subgraph "Local OPA Instance"\n A_OPA["<img src=\''+u+"' width='30' height='30' /><br/>OPA\"];\n end\n subgraph \"App Instance\"\n A_Service[\"Service Logic\"] --\x3e|HTTP Call| A_OPA\n end\n end\n end\n";const h=function(){return(0,r.jsx)(o.A,{value:d})};var g="\ngraph LR\n subgraph CP[Control Plane]\n Monitoring\n Logging\n Config\n Bundles\n end\n\n OPA[\"<img src='"+t(75605).A+"' width='30' height='30' /><br/>OPA\"];\n Service[\"Service\"] --- OPA\n\n OPA --\x3e|Status| Monitoring\n OPA --\x3e|Decisions| Logging\n Bundles --\x3e|Bundles| OPA\n Config --\x3e|Discovery<br/>Bundles| OPA\n\n";const f=function(){return(0,r.jsx)(o.A,{value:g})},p={title:"OPA Management APIs and Architecture",sidebar_label:"Overview"},m=void 0,A={},b=[];function P(n){const e={a:"a",em:"em",li:"li",p:"p",ul:"ul",...(0,a.R)(),...n.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(e.p,{children:"OPA exposes a set of APIs that enable unified, logically centralized policy\nmanagement. Read this page if you are interested in how to build a control plane\naround OPA that enables policy distribution and collection of important\ntelemetry data like decision logs."}),"\n",(0,r.jsx)(e.p,{children:"OPA enables low-latency, highly-available policy enforcement by providing a\nlightweight engine for distributed architectures. By default, all of the policy\nand data that OPA uses to make decisions is kept in-memory:"}),"\n","\n",(0,r.jsx)(l,{}),"\n",(0,r.jsxs)(e.p,{children:["OPA is designed to enable ",(0,r.jsx)(e.em,{children:"distributed"})," policy enforcement. You can run OPA next\nto each and every service that needs to offload policy decision-making. By\nco-locating OPA with the services that require decision-making, you ensure that\npolicy decisions are rendered as fast as possible and in a highly-available\nmanner."]}
1),"\n","\n",(0,r.jsx)(h,{}),"\n",(0,r.jsx)(e.p,{children:"To control and observe a set of OPA instances, each OPA can be configured to connect to\nmanagement APIs that enable:"}),"\n",(0,r.jsxs)(e.ul,{children:["\n",(0,r.jsxs)(e.li,{children:["Policy distribution (",(0,r.jsx)(e.a,{href:"./management-bundles",children:"Bundles"}),")"]}),"\n",(0,r.jsxs)(e.li,{children:["Decision telemetry (",(0,r.jsx)(e.a,{href:"./management-decision-logs",children:"Decision Logs"}),")"]}),"\n",(0,r.jsxs)(e.li,{children:["Agent telemetry (",(0,r.jsx)(e.a,{href:"./management-status",children:"Status"}),")"]}),"\n",(0,r.jsxs)(e.li,{children:["Dynamic agent configuration (",(0,r.jsx)(e.a,{href:"./management-discovery",children:"Discovery"}),")"]}),"\n"]}),"\n",(0,r.jsx)(e.p,{children:"By configuring and implementing these management APIs you can unify control and\nvisibility over OPA instances in your environments. OPA does not provide a control plane\nservice out-of-the-box."}),"\n","\n",(0,r.jsx)(f,{})]})}function v(n={}){const{wrapper:e}={...(0,a.R)(),...n.components};return e?(0,r.jsx)(e,{...n,children:(0,r.jsx)(P,{...n})}):P(n)}},28453:(n,e,t)=>{t.d(e,{R:()=>o,x:()=>s});var i=t(96540);const r={},a=i.createContext(r);function o(n){const e=i.useContext(a);return i.useMemo((function(){return"function"==typeof n?n(e):{...e,...n}}),[e,n])}function s(n){let e;return e=n.disableParentContext?"function"==typeof n.components?n.components(r):n.components||r:o(n.components),i.createElement(a.Provider,{value:e},n.children)}},75605:(n,e,t)=>{t.d(e,{A:()=>i});const i=t.p+"assets/images/logo-92a1aebfb4ea664b7d9c550b29f450a5.png"}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.