PageSourceSearch

https://www.openpolicyagent.org/assets/js/58c26da0.fcc151d4.js

js openpolicyagent.org collected 2026-09-24 08:28:15 UTC 9,361 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[7214],{21904:e=>{e.exports=JSON.parse('{"permalink":"/blog/announcing-opa-1-0-a-new-standard-for-policy-as-code-a6d8427ee828","source":"@site/blog/2024-12-20-announcing-opa-1-0-a-new-standard-for-policy-as-code-a6d8427ee828.md","title":"Announcing OPA 1.0: A New Standard for Policy as Code","description":"Banner graphic announcing the OPA 1.0 release","date":"2024-12-20T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Charlie Egan","page":{"permalink":"/blog/authors/charlie"},"imageURL":"/img/blog/authors/charlie.jpeg","key":"charlie"}],"frontMatter":{"title":"Announcing OPA 1.0: A New Standard for Policy as Code","authors":["charlie"],"date":"2024-12-20T00:00:00.000Z","slug":"announcing-opa-1-0-a-new-standard-for-policy-as-code-a6d8427ee828"},"unlisted":false,"prevItem":{"title":"Introducing Swift OPA: Native Policy Evaluation for Swift","permalink":"/blog/introducing-swift-opa-native-policy-evaluation-for-swift-d5136c8a662e"},"nextItem":{"title":"OPA 1.0 is coming. Here\'s what you need to know.","permalink":"/blog/opa-1-0-is-coming-heres-what-you-need-to-know-c8fb0d258368"}}')},28453:(e,o,t)=>{t.d(o,{R:()=>i,x:()=>s});var n=t(96540);const a={},r=n.createContext(a);function i(e){const o=n.useContext(r);return n.useMemo((function(){return"function"==typeof e?e(o):{...o,...e}}),[o,e])}function s(e){let o;return o=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:i(e.components),n.createElement(r.Provider,{value:o},e.children)}},68245:(e,o,t)=>{t.d(o,{A:()=>n});const n=t.p+"assets/images/banner-1e952515cea7614741ccacde3a63a705.webp"},75440:(e,o,t)=>{t.r(o),t.d(o,{assets:()=>l,contentTitle:()=>s,default:()=>h,frontMatter:()=>i,metadata:()=>n,toc:()=>c});var n=t(21904),a=t(74848),r=t(28453);const i={title:"Announcing OPA 1.0: A New Standard for Policy as Code",authors:["charlie"],date:new Date("2024-12-20T00:00:00.000Z"),slug:"announcing-opa-1-0-a-new-standard-for-policy-as-code-a6d8427ee828"},s=void 0,l={authorsImageUrls:[void 0]},c=[];function d(e){const o={a:"a",code:"code",em:"em",img:"img",li:"li",p:"p",ul:"ul",...(0,r.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(o.p,{children:(0,a.jsx)(o.img,{alt:"Banner graphic announcing the OPA 1.0 release",src:t(68245).A+"",width:"1400",height:"560"})}),"\n",(0,a.jsx)(o.p,{children:"We are excited to announce OPA 1.0, a milestone release consolidating an improved developer experience for the future of Policy as Code. After nearly 10 years of innovations and contributions from over 450 developers, OPA 1.0 is finally here. The release makes new functionality designed to simplify policy writing and improve the language's consistency the default. This release marks the beginning of a new era for our project and represents a robust foundation for Policy as Code projects in the years ahead."}),"\n",(0,a.jsxs)(o.p,{children:["Since the project's ",(0,a.jsx)(o.a,{href:"https://www.cncf.io/announcements/2021/02/04/cloud-native-computing-foundation-announces-open-policy-agent-graduation/",children:"CNCF graduation"})," at the start of 2021, our work has been focused on Rego's developer experience and consistency. While much of the new functionality has been around for some time, OPA 1.0 will make new features the default \u2014 warranting the ",(0,a.jsx)(o.a,{href:"https://semver.org/",children:"SemVer"})," bump to ",(0,a.jsx)(o.code,{children:"v1.0.0"}),". At this time, we would like to take the chance to highlight the following key changes to the defaults in Rego v1:"]}),"\n",(0,a.jsxs)(o.ul,{children:["\n",(0,a.jsxs)(o.li,{children:["Using ",(0,a.jsx)(o.code,{children:"if"})," for all rule definitions and ",(0,a.jsx)(o.code,{children:"contains"})," for multi-value rules is now mandatory, not just when using the ",(0,a.jsx)(o.code,{children:"rego.v1"})," import."]}),"\n",(0,a.jsxs)(o.li,{children:["Other new keywords (",(0,a.jsx)(o.code,{children:"every"}),", ",(0,a.jsx)(o.code,{children:"in"}),") are available without any imports."]}),"\n",(0,a.jsxs)(o.li,{children:['Previously requirements that were only run in "strict mode" (like ',(0,a.jsx)(o.code,{children:"opa check --strict"}),") are now the default. Duplicate imports and imports which shadow each other are no longer allowed."]}),"\n",(0,a.jsxs)(o.li,{children:["OPA 1.0 comes with a range of backwards compatibility features to aid your migrations, please see the ",(0,a.jsx)(o.a,{href:"https://www.openpolicyagent.org/docs/latest/v0-compatibility/",children:"v0 compatibility guide"}
1)," if you must continue to support v0 Rego."]}),"\n"]}),"\n",(0,a.jsx)(o.p,{children:"Many users have already started using the new syntax (we started adding the new keywords three years ago back in v0.34.0) but for those who haven't; in order to get the best of OPA 1.0; and to remain abreast of follow on updates; users are encouraged to upgrade as soon as possible (using the backwards compatibility functionality if required). Most users will be able to update their Rego quickly as the process can be largely automated using the Rego tools already built into OPA. The process can be summarized as follows:"}),"\n",(0,a.jsxs)(o.ul,{children:["\n",(0,a.jsxs)(o.li,{children:["Download and install an ",(0,a.jsx)(o.a,{href:"https://github.com/open-policy-agent/opa/releases/tag/v1.0.0",children:"OPA 1.0 binary"})," before running the following commands."]}),"\n",(0,a.jsxs)(o.li,{children:[(0,a.jsx)(o.code,{children:"opa check --v0-v1"}),": Find parser and compiler errors that might be present in old code."]}),"\n",(0,a.jsxs)(o.li,{children:[(0,a.jsx)(o.code,{children:"opa check --v0-v1 --strict"}),": Find problems in Rego code no longer permitted in OPA 1.0."]}),"\n",(0,a.jsxs)(o.li,{children:[(0,a.jsx)(o.code,{children:"opa fmt --write --v0-v1"}),": Automatically update code to the OPA 1.0 syntax."]}),"\n",(0,a.jsxs)(o.li,{children:[(0,a.jsx)(o.code,{children:"regal lint"}),": using Regal, the linter for Rego is also recommended to find bugs and performance issues."]}),"\n"]}),"\n",(0,a.jsxs)(o.p,{children:["For users looking for more detailed information, please see the following resources: ",(0,a.jsx)(o.a,{href:"http://openpolicyagent.org/docs/latest/v0-upgrade/",children:"OPA Documentation on upgrading to 1.0"}),"; the ",(0,a.jsx)(o.a,{href:"https://web.archive.org/web/https://www.styra.com/blog/renovating-rego/",children:"Renovating Rego"})," post for older projects which digs into the above process in detail; the ",(0,a.jsx)(o.a,{href:"https://youtu.be/QuotLxFb2f4?feature=shared&t=800",children:"Maintainer Track presentation"})," from KubeCon NA 2024 for a video overview."]}),"\n",(0,a.jsxs)(o.p,{children:["Those ",(0,a.jsx)(o.a,{href:"https://www.openpolicyagent.org/docs/latest/integration/",children:"integrating with OPA's Go packages"})," \u2014 both via the SDK and the low-level Rego package \u2014 are encouraged to update their applications to use the new v1 packages. This is also documented in the ",(0,a.jsx)(o.a,{href:"http://openpolicyagent.org/docs/latest/v0-upgrade/",children:"upgrading documentation"})," and is a straightforward process. In some cases, users or integrators will need to support both v0 and v1 Rego simultaneously in the same application. This is generally only applicable to those offering OPA as part of a managed offering where the Rego is controlled by end users. Those who do have this use case, please review the ",(0,a.jsx)(o.a,{href:"https://www.openpolicyagent.org/docs/latest/v0-compatibility/",children:"v0 compatibility guide"})," to review the most suitable option for your application."]}),"\n",(0,a.jsxs)(o.p,{children:["One last thing, while OPA 1.0 is primarily about consolidating the Rego developer experience, the release also comes with some significant improvements to performance. Check the ",(0,a.jsx)(o.a,{href:"https://github.com/open-policy-agent/opa/releases/tag/v1.0.0",children:"release notes"})," to dig into the details."]}),"\n",(0,a.jsxs)(o.p,{children:["And that's a wrap! OPA 1.0 is here, it's a milestone release for our project and we're proud of the effort this release represents. We're excited for you to upgrade and experience these improvements firsthand. As you do, please report any issues via ",(0,a.jsx)(o.a,{href:"http://slack.openpolicyagent.org/",children:"Slack"})," or ",(0,a.jsx)(o.a,{href:"https://github.com/orgs/open-policy-agent/discussions",children:"GitHub Discussions"}),", and feel free to open bug reports or feature requests to help shape future releases. Also, don't forget to use the ",(0,a.jsx)(o.a,{href:"https://www.openpolicyagent.org/projects/regal/editor-support",children:"Regal language server"}
1)," to ensure your Rego code is efficient & error-free too."]}),"\n",(0,a.jsx)(o.p,{children:"We want to extend our gratitude to our incredible community for always testing the latest versions, reporting bugs, contributing code and supporting fellow community members on their Rego journeys. We're not done yet and look forward to working together for years to come."}),"\n",(0,a.jsx)(o.p,{children:(0,a.jsx)(o.em,{children:"Happy holidays \u2014 the OPA team"})})]})}function h(e={}){const{wrapper:o}={...(0,r.R)(),...e.components};return o?(0,a.jsx)(o,{...e,children:(0,a.jsx)(d,{...e})}):d(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.