PageSourceSearch

https://www.openpolicyagent.org/assets/js/99d750ec.81c1e00f.js

js openpolicyagent.org collected 2026-09-24 08:30:54 UTC 13,881 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[25101],{2710:e=>{e.exports=JSON.parse('{"permalink":"/blog/open-policy-agent-2021-survey-summary-e749bbd7b824","source":"@site/blog/2021-08-31-open-policy-agent-2021-survey-summary-e749bbd7b824.md","title":"Open Policy Agent 2021 Survey Summary","description":"OPA 2021 community survey results banner","date":"2021-08-31T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Torin Sandall","page":{"permalink":"/blog/authors/tsandall"},"imageURL":"/img/blog/authors/tsandall.png","key":"tsandall"}],"frontMatter":{"title":"Open Policy Agent 2021 Survey Summary","authors":["tsandall"],"date":"2021-08-31T00:00:00.000Z","slug":"open-policy-agent-2021-survey-summary-e749bbd7b824"},"unlisted":false,"prevItem":{"title":"Serverless Policy Enforcement: Connecting OPA and AWS Lambda","permalink":"/blog/serverless-policy-enforcement-connecting-opa-and-aws-lambda-e624f7176a3"},"nextItem":{"title":"OPA Slack Tune Up","permalink":"/blog/opa-slack-tune-up-b3c52492e2fc"}}')},28453:(e,s,t)=>{t.d(s,{R:()=>o,x:()=>d});var n=t(96540);const r={},i=n.createContext(r);function o(e){const s=n.useContext(i);return n.useMemo((function(){return"function"==typeof e?e(s):{...s,...e}}),[s,e])}function d(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:o(e.components),n.createElement(i.Provider,{value:s},e.children)}},70068:(e,s,t)=>{t.r(s),t.d(s,{assets:()=>a,contentTitle:()=>d,default:()=>c,frontMatter:()=>o,metadata:()=>n,toc:()=>l});var n=t(2710),r=t(74848),i=t(28453);const o={title:"Open Policy Agent 2021 Survey Summary",authors:["tsandall"],date:new Date("2021-08-31T00:00:00.000Z"),slug:"open-policy-agent-2021-survey-summary-e749bbd7b824"},d=void 0,a={authorsImageUrls:[void 0]},l=[{value:"Use Cases and Adoption",id:"use-cases-and-adoption",level:2},{value:"OPA adoption driven by authorization use cases across the stack",id:"opa-adoption-driven-by-authorization-use-cases-across-the-stack",level:3},{value:"From experiments to production in 6 months (or less)",id:"from-experiments-to-production-in-6-months-or-less",level:3},{value:"Policy library adoption is growing",id:"policy-library-adoption-is-growing",level:3}
1,{value:"OPA Feedback",id:"opa-feedback",level:2},{value:"Debugging needs some love",id:"debugging-needs-some-love",level:3},{value:"SDKs for various languages",id:"sdks-for-various-languages",level:3},{value:"Wrap Up",id:"wrap-up",level:2}];function h(e){const s={a:"a",em:"em",h2:"h2",h3:"h3",img:"img",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,i.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(s.p,{children:(0,r.jsx)(s.img,{alt:"OPA 2021 community survey results banner",src:t(73955).A+"",width:"508",height:"582"})}),"\n",(0,r.jsx)(s.p,{children:(0,r.jsx)(s.em,{children:"\u2026happy OPA 2021 survey from Cal [credit: @eileen_kemp]"})}),"\n",(0,r.jsx)(s.p,{children:"Last month we surveyed the OPA community to learn more about user adoption and help us plan and improve the project. We received over 300 responses from users across financial services, healthcare, public sector, automotive, cloud technology providers and more. This post highlights some of the survey results."}),"\n",(0,r.jsx)(s.h2,{id:"use-cases-and-adoption",children:"Use Cases and Adoption"}),"\n",(0,r.jsx)(s.h3,{id:"opa-adoption-driven-by-authorization-use-cases-across-the-stack",children:"OPA adoption driven by authorization use cases across the stack"}),"\n",(0,r.jsx)(s.p,{children:"Like last year, we used the survey to gauge use case adoption among respondents. We're interested in understanding where and why companies are deploying OPA because it helps us steer the project's long-term roadmap in the right direction. This year we asked respondents about the high-level goals they're trying to achieve by using OPA. We found that implementation of internal compliance and governance rules was the most common goal, however, nearly 60% of respondents indicated two or more goals being highly relevant."}),"\n",(0,r.jsxs)(s.table,{children:[(0,r.jsx)(s.thead,{children:(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.th,{children:"Goal"}),(0,r.jsx)(s.th,{children:"% of Respondents"})]})}),(0,r.jsxs)(s.tbody,{children:[(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Internal compliance/governance"}),(0,r.jsx)(s.td,{children:"64%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Operational excellence"}),(0,r.jsx)(s.td,{children:"49%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Implementing end-user IAM"}),(0,r.jsx)(s.td,{children:"44%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"External compliance (e.g., PCI)"}),(0,r.jsx)(s.td,{children:"28%"})]})]})]}),"\n",(0,r.jsx)(s.p,{children:"In terms of use cases (e.g., Kubernetes admission control, Microservice authorization, etc.), the results were similar to the previous year with 50% of respondents indicating they use OPA for two or more use cases:"}),"\n",(0,r.jsxs)(s.table,{children:[(0,r.jsx)(s.thead,{children:(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.th,{children:"# of Use Cases"}),(0,r.jsx)(s.th,{children:"% of Respondents"})]})}),(0,r.jsxs)(s.tbody,{children:[(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"1"}),(0,r.jsx)(s.td,{children:"48%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"2"}),(0,r.jsx)(s.td,{children:"34%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"3"}),(0,r.jsx)(s.td,{children:"13%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"4+"}),(0,r.jsx)(s.td,{children:"3%"})]})]})]}),"\n",(0,r.jsx)(s.p,{children:"Kubernetes admission control continues to be the most common use case for OPA with 54% of respondents indicating they run OPA or OPA Gatekeeper to enforce various policies on their clusters:"}),"\n",(0,r.jsxs)(s.table,{children:[(0,r.jsx)(s.thead,{children:(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.th,{children:"Use Case"}),(0,r.jsx)(s.th,{children:"% of Respondents"})]})}),(0,r.jsxs)(s.tbody,{children:[(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Kubernetes admission control"}),(0,r.jsx)(s.td,{children:"54%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Application authorization"}),(0,r.jsx)(s.td,{children:"39%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Microservice authorization"}),(0,r.jsx)(s.td,{children:"39%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Terraform validation"}),(0,r.jsx)(s.td,{children:"25%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Other"}),(0,r.jsx)(s.td,{children:"5%"})]})]})]}),"\n",(0,r.jsx)(s.h3,{id:"from-experiments-to-production-in-6-months-or-less",children:"From experiments to production in 6 months (or less)"}),"\n",(0,r.jsx)(s.p,{children:"The survey showed the distribution of respondents OPA usage maturity was roughly equal:"}),"\n",(0,r.jsxs)(s.table,{children:[(0,r.jsx)(s.thead,{children:(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.th,{children:"Stage"}),(0,r.jsx)(s.th,{children:"% of Respondents"})]})}),(0,r.jsxs)(s.tbody,{children:[(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Experimentation"}),(0,r.jsx)(s.td,{children:"33%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Pre-production & QA"}),(0,r.jsx)(s.td,{children:"32%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Production"}),(0,r.jsx)(s.td,{children:"35%"})]})]})]}),"\n",(0,r.jsx)(s.p,{children:"What was more interesting was that about half of respondents indicated they had only been using OPA since January 2021. Of those users, nearly 40% had already reached production. Furthermore, the survey results show that most respondents reached production within 6 months. Beyond that, the percentage of users that are still in experimental stages drops to single digits:"}),"\n",(0,r.jsxs)(s.table,{children:[(0,r.jsx)(s.thead,{children:(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.th,{}),(0,r.jsx)(s.th,{children:"Experimentation"}),(0,r.jsx)(s.th,{children:"Pre-prod/QA"}),(0,r.jsx)(s.th,{children:"Production"})]})}),(0,r.jsxs)(s.tbody,{children:[(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"< 3 months"}),(0,r.jsx)(s.td,{children:"54%"}),(0,r.jsx)(s.td,{children:"28%"}),(0,r.jsx)(s.td,{children:"14%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"3-6 months"}),(0,r.jsx)(s.td,{children:"22%"}),(0,r.jsx)(s.td,{children:"54%"}),(0,r.jsx)(s.td,{children:"25%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"6-12 months"}),(0,r.jsx)(s.td,{children:"4%"}),(0,r.jsx)(s.td,{children:"38%"}),(0,r.jsx)(s.td,{children:"58%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Over 12 months"}),(0,r.jsx)(s.td,{children:"7%"}),(0,r.jsx)(s.td,{children:"15%"}),(0,r.jsx)(s.td,{children:"76%"})]})]})]}),"\n",(0,r.jsx)(s.p,{children:"These results are encouraging and also give us high-level metrics to improve on \u2014 ideally the time to production with OPA will continue to decrease as we improve the user experience and harden the project."}),"\n",(0,r.jsx)(s.p,{children:"The survey results also highlighted a range of deployment sizes for production users. The following chart breaks down the deployment size responses by use case:"}),"\n",(0,r.jsxs)(s.table,{children:[(0,r.jsx)(s.thead,{children:(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.th,{children:"Use Case"}),(0,r.jsx)(s.th,{children:"<10"}),(0,r.jsx)(s.th,{children:"10-50"}),(0,r.jsx)(s.th,{children:"50-200"}),(0,r.jsx)(s.th,{children:">200"})]})}),(0,r.jsxs)(s.tbody,{children:[(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Kubernetes admission control"}),(0,r.jsx)(s.td,{children:"42%"}),(0,r.jsx)(s.td,{children:"31%"}),(0,r.jsx)(s.td,{children:"13%"}),(0,r.jsx)(s.td,{children:"12%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Terraform validation"}),(0,r.jsx)(s.td,{children:"43%"}),(0,r.jsx)(s.td,{children:"25%"}),(0,r.jsx)(s.td,{children:"18%"}),(0,r.jsx)(s.td,{children:"12%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Microservice authorization"}),(0,r.jsx)(s.td,{children:"37%"}),(0,r.jsx)(s.td,{children:"37%"}),(0,r.jsx)(s.td,{children:"12%"}),(0,r.jsx)(s.td,{children:"11%"})]}),(0,r.jsxs)(s.tr,{children:[(0,r.jsx)(s.td,{children:"Application authorization"}),(0,r.jsx)(s.td,{children:"44%"}),(0,r.jsx)(s.td,{children:"32%"}),(0,r.jsx)(s.td,{children:"10%"}),(0,r.jsx)(s.td,{children:"11%"})]})]})]}),"\n",(0,r.jsx)(s.h3,{id:"policy-library-adoption-is-growing",children:"Policy library adoption is growing"}),"\n",(0,r.jsxs)(s.p,{children:["The survey asked users about various features in OPA and one of the most encouraging bits of information was that policy library adoption is growing within platform authorization use cases, like Kubernetes admission control and Terraform plan validation. Specifically, we found that nearly 60% of Kubernetes admission control users rely on the official ",(0,r.jsx)(s.a,{href:"https://github.com/open-policy-agent/gatekeeper-library",children:"gatekeeper-library"})," policies that implement various best practices as well as PSP. We also found that nearly 30% of users that run OPA to validate Terraform plans rely on various open source policy libraries."]}),"\n",(0,r.jsx)(s.h2,{id:"opa-feedback",children:"OPA Feedback"}),"\n",(0,r.jsx)(s.p,{children:"In addition to gauging adoption we also used the survey to solicit feedback about the project."}),"\n",(0,r.jsx)(s.h3,{id:"debugging-needs-some-love",children:"Debugging needs some love"}),"\n",(0,r.jsxs)(s.p,{children:["After poring over the feedback comments, we found that the most common area for improvement is ",(0,r.jsx)(s.em,{children:"debugging"}),". As with all surveys, some comments were non-specific, however multiple respondents requested better ",(0,r.jsx)(s.a,{href:"https://github.com/open-policy-agent/opa/issues/2089",children:"tracing modes"})," and explanation presentation formats. Improved ",(0,r.jsx)(s.a,{href:"https://github.com/open-policy-agent/opa/issues/3319",children:"debug output"})," support was another common request, and respondents also mentioned a desire for an ",(0,r.jsx)(s.a,{href:"https://github.com/open-policy-agent/opa/issues/3191",children:"interactive debugger"})," similar to what you find in typical programming languages."]}),"\n",(0,r.jsx)(s.h3,{id:"sdks-for-various-languages",children:"SDKs for various languages"}),"\n",(0,r.jsxs)(s.p,{children:["Aside from debugging, the next most common request was better SDK support for OPA in various languages. Several respondents indicated interest in ",(0,r.jsx)(s.a,{href:"https://www.openpolicyagent.org/docs/latest/wasm/",children:"Wasm-based SDKs"})," for OPA, and others requested regular SDKs for Java, NodeJS and other languages. One of the reasons we haven't developed SDKs for OPA yet is because the OPA API is ",(0,r.jsx)(s.em,{children:"extremely simple"})," (e.g., you can query OPA for decisions with a single HTTP PO
1ST request). However, with the Wasm compiler in OPA improving with every release, and the Wasm ecosystem growing rapidly, it feels like it's time to invest into language-specific integration libraries."]}),"\n",(0,r.jsx)(s.h2,{id:"wrap-up",children:"Wrap Up"}),"\n",(0,r.jsxs)(s.p,{children:["Thanks to everyone who completed the survey! The OPA t-shirts for completing the survey will be shipped soon. If you have not filled out the survey but would like to do so, you can still ",(0,r.jsx)(s.a,{href:"https://form.typeform.com/to/pL0jDuyT",children:"complete the OPA survey"}),". As always, if you have questions or feedback, we're available on Slack, GitHub, etc."]})]})}function c(e={}){const{wrapper:s}={...(0,i.R)(),...e.components};return s?(0,r.jsx)(s,{...e,children:(0,r.jsx)(h,{...e})}):h(e)}},73955:(e,s,t)=>{t.d(s,{A:()=>n});const n=t.p+"assets/images/banner-62cc22b9793c4233a18a7b23eac448b1.webp"}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.