PageSourceSearch

https://www.openpolicyagent.org/assets/js/ea14652c.c8d6eb65.js

js openpolicyagent.org collected 2026-09-24 08:28:50 UTC 8,735 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[10548],{28453:(e,o,n)=>{n.d(o,{R:()=>s,x:()=>a});var t=n(96540);const r={},i=t.createContext(r);function s(e){const o=t.useContext(i);return t.useMemo((function(){return"function"==typeof e?e(o):{...o,...e}}),[o,e])}function a(e){let o;return o=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:s(e.components),t.createElement(i.Provider,{value:o},e.children)}},69948:(e,o,n)=>{n.r(o),n.d(o,{assets:()=>l,contentTitle:()=>a,default:()=>h,frontMatter:()=>s,metadata:()=>t,toc:()=>d});const t=JSON.parse('{"id":"opa-one-dot-zero","title":"opa-one-dot-zero","description":"OPA 1.0 | Regal","source":"@site/projects/regal/opa-one-dot-zero.md","sourceDirName":".","slug":"/opa-one-dot-zero","permalink":"/projects/regal/opa-one-dot-zero","draft":false,"unlisted":false,"tags":[],"version":"current","sidebarPosition":14,"frontMatter":{"sidebar_label":"OPA 1.0","sidebar_position":14},"sidebar":"autoSidebar","previous":{"title":"Adopters","permalink":"/projects/regal/adopters"}}');var r=n(74848),i=n(28453);const s={sidebar_label:"OPA 1.0",sidebar_position:14},a="OPA 1.0 and Regal",l={},d=[{value:"Telling Regal which Rego version to target",id:"telling-regal-which-rego-version-to-target",level:2},{value:"Rules disabled with OPA 1.0",id:"rules-disabled-with-opa-10",level:2},{value:"Related Resources",id:"related-resources",level:2}];function c(e){const o={a:"a",code:"code",h1:"h1",h2:"h2",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,i.R)(),...e.components},{Head:n}=o;return n||function(e,o){throw new Error("Expected "+(o?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("Head",!0),(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n,{children:(0,r.jsx)("title",{children:"OPA 1.0 | Regal"})}),"\n",(0,r.jsx)(o.header,{children:(0,r.jsx)(o.h1,{id:"opa-10-and-regal",children:"OPA 1.0 and Regal"})}),"\n",(0,r.jsx)(o.p,{children:"While we always recommend using the latest version of OPA, we're well aware that there may be situations where \u2014 for\none reason or another \u2014 that might not be possible. As we want everyone to benefit from Regal, we do our very best to\nensure it works seamlessly with OPA versions both before and after 1.0, and even projects that use a mix of both! While\nthis should mostly work out of the box and without additional configuration, it's good to be aware of how Regal parses\nand lints policies of different versions of Rego, and how you can tell Regal to target only a specific version."}),"\n",(0,r.jsxs)(o.p,{children:[(0,r.jsx)(o.strong,{children:"Note:"})," This document does not cover the specifics of OPA 1.0, but rather how Regal works with it. If you want to\nlearn more about what OPA 1.0 is and how to upgrade, see the ",(0,r.jsx)(o.a,{href:"#related-resources",children:"related resources"})," at the bottom of\nthis page."]}),"\n",(0,r.jsx)(o.h2,{id:"telling-regal-which-rego-version-to-target",children:"Telling Regal which Rego version to target"}),"\n",(0,r.jsx)(o.p,{children:"While Regal pretty accurately guesses the Rego version of the policies it's linting \u2014 and will adapt how it parses and\nasseses Rego files accordingly \u2014 telling Regal which version to target is always going to produce the most reliable\nresults \u2014 and much faster too! Guessing which Rego version to target often involves multiple passes of parsing, and\nas some files are both valid Rego v0 and v1, there will always be some ambiguity. In order to avoid this, our\nrecommendation is to always provide Regal with the Rego version(s) targeted. This can be done in a couple of ways, and\nthe precedence of these methods is as listed below:"}),"\n",(0,r.jsxs)(o.ol,{children:["\n",(0,r.jsxs)(o.li,{children:["Setting the ",(0,r.jsx)(o.code,{children:"rego-version"})," configuration option under ",(0,r.jsx)(o.code,{children:"project.roots"})," attribute"]}),"\n",(0,r.jsxs)(o.li,{children:["Setting the ",(0,r.jsx)(o.code,{children:"rego-version"})," configuration option under ",(0,r.jsx)(o.code,{children:"project"})," attribute"]}),"\n",(0,r.jsxs)(o.li,{children:["Setting the ",(0,r.jsx)(o.code,{children:"rego_version"})," in a ",(0,r.jsx)(o.code,{children:".manifest"})," file in any directory (will apply to that directory and any below it)"]}),"\n"]}),"\n",(0,r.jsxs)(o.p,{children:["Note that it is perfectly possible to use different ",(0,r.jsx)(o.code,{children:"rego-version"}),"s for different roots of a project:"]}),"\n",(0,r.jsx)(o.pre,{children:(0,r.jsx)(o.code,{className:"language-yaml",children:"project:\n  rego-version: 1\n  roots:\n  # lib/legacy overriding project version to set version 0\n  - path: lib/legacy\n    rego-version: 0\n  # main directory will inherit version 1 from project\n  - path: main\n"})}),"\n",(0,r.jsxs)(o.p,{children:["See the documentation covering Regal's ",(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal#configuration",children:"configuration"})," for more information\non ",(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal#configuring-rego-version",children:"configuring Rego version"})," for your project."]}),"\n",(0,r.jsxs)(o.p,{children:["Finally, Regal will automatically parse and lint any file with a ",(0,r.jsx)(o.code,{children:"_v0.rego"})," suffix as Rego v0. This is intended only\nfor testing and development, where you sometimes may want to try something out using and older Rego version without\nconfiguration. Note that this has lower precedence than Rego versions set by other means, and should not be considered\nas anything but a convenience for testing."]}),"\n",(0,r.jsx)(o.h2,{id:"rules-disabled-with-opa-10",children:"Rules disabled 
1with OPA 1.0"}),"\n",(0,r.jsx)(o.p,{children:"Some linter rules don't really make sense to enforce post OPA 1.0, as they are now either enforced by OPA itself or\notherwise no longer relevant. The following rules are now disabled by default, unless Regal is configured to target\nRego versions before 1.0, or in the case where no configuration is provided, Regal determines that the project being\nlinted is not yet using OPA 1.0:"}),"\n",(0,r.jsxs)(o.ul,{children:["\n",(0,r.jsx)(o.li,{children:(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/rules/bugs/deprecated-builtin",children:"deprecated-builtin"})}),"\n",(0,r.jsx)(o.li,{children:(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/rules/imports/import-shadows-import",children:"import-shadows-import"})}),"\n",(0,r.jsx)(o.li,{children:(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/rules/bugs/rule-named-if",children:"rule-named-if"})}),"\n",(0,r.jsx)(o.li,{children:(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/rules/idiomatic/use-contains",children:"use-contains"})}),"\n",(0,r.jsx)(o.li,{children:(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/rules/idiomatic/use-if",children:"use-if"})}),"\n",(0,r.jsx)(o.li,{children:(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/rules/imports/use-rego-v1",children:"use-rego-v1"})}),"\n"]}),"\n",(0,r.jsxs)(o.p,{children:["Except for the ",(0,r.jsx)(o.code,{children:"deprecated-builtin"})," rule \u2014 which is disabled simply because there currently are no deprecated built-ins\nin OPA 1.0 \u2014 these rules are now enforced automatically by OPA, and so there's no reason for Regal to duplicate that\neffort."]}),"\n",(0,r.jsx)(o.h2,{id:"related-resources",children:"Related Resources"}),"\n",(0,r.jsxs)(o.ul,{children:["\n",(0,r.jsxs)(o.li,{children:["OPA Docs: ",(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/docs/v0-upgrade",children:"Upgrading to v1.0"})]}),"\n",(0,r.jsxs)(o.li,{children:["OPA Docs: ",(0,r.jsx)(o.a,{href:"https://www.openpolicyagent.org/docs/v0-compatibility",children:"v0 Backwards Compatibility"})]}),"\n",(0,r.jsxs)(o.li,{children:["Styra Blog: ",(0,r.jsx)(o.a,{href:"https://web.archive.org/web/https://www.styra.com/blog/renovating-rego/",children:"Renovating Rego"})]}),"\n",(0,r.jsxs)(o.li,{children:["OPA Blog: ",(0,r.jsx)(o.a,{href:"https://blog.openpolicyagent.org/opa-1-0-is-coming-heres-what-you-need-to-know-c8fb0d258368",children:"OPA 1.0 Is Coming, Here's What You Need to Know"})]}),"\n",(0,r.jsxs)(o.li,{children:["OPA Blog: ",(0,r.jsx)(o.a,{href:"https://blog.openpolicyagent.org/announcing-opa-1-0-a-new-standard-for-policy-as-code-a6d8427ee828",children:"Announcing OPA 1.0: A New Standard for Policy as Code"})]}),"\n"]})]})}function h(e={}){const{wrapper:o}={...(0,i.R)(),...e.components};return o?(0,r.jsx)(o,{...e,children:(0,r.jsx)(c,{...e})}):c(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.