1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[25497],{7259:(e,n,t)=>{t.d(n,{A:()=>i});const i=t.p+"assets/images/banner-6b2170bcc2595287ef76f19c3e7be0c7.gif"},28453:(e,n,t)=>{t.d(n,{R:()=>a,x:()=>r});var i=t(96540);const o={},s=i.createContext(o);function a(e){const n=i.useContext(s);return i.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function r(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:a(e.components),i.createElement(s.Provider,{value:n},e.children)}},44756:e=>{e.exports=JSON.parse('{"permalink":"/blog/v0-10-release-277da41b9ed1","source":"@site/blog/2018-10-25-v0-10-release-277da41b9ed1.md","title":"v0.10 Release","description":"OPA v0.10.0 release announcement banner animation","date":"2018-10-25T00:00:00.000Z","tags":[],"hasTruncateMarker":false,"authors":[{"name":"Torin Sandall","page":{"permalink":"/blog/authors/tsandall"},"imageURL":"/img/blog/authors/tsandall.png","key":"tsandall"}],"frontMatter":{"title":"v0.10 Release","authors":["tsandall"],"date":"2018-10-25T00:00:00.000Z","slug":"v0-10-release-277da41b9ed1"},"unlisted":false,"prevItem":{"title":"Securing the Kubernetes API with Open Policy Agent","permalink":"/blog/securing-the-kubernetes-api-with-open-policy-agent-ce93af0552c3"},"nextItem":{"title":"Write Policy in OPA. Enforce Policy in SQL.","permalink":"/blog/write-policy-in-opa-enforce-policy-in-sql-d9d24db93bf4"}}')},77776:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>l,contentTitle:()=>r,default:()=>u,frontMatter:()=>a,metadata:()=>i,toc:()=>c});var i=t(44756),o=t(74848),s=t(28453);const a={title:"v0.10 Release",authors:["tsandall"],date:new Date("2018-10-25T00:00:00.000Z"),slug:"v0-10-release-277da41b9ed1"},r=void 0,l={authorsImageUrls:[void 0]},c=[{value:"WebAssembly",id:"webassembly",level:2},{value:"Improved Test Support with Data Mocking",id:"improved-test-support-with-data-mocking",level:2},{value:"Partial Evaluation: Negation Optimization",id:"partial-evaluation-negation-optimization",level:2},{value:"More Great Contributions",id:"more-great-contributions",level:2}];function d(e){const n={a:"a",code:"code",em:"em",h2:"h2",img:"img",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,s.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(n.p,{children:(0,o.jsx)(n.img,{alt:"OPA v0.10.0 release announcement banner animation",src:t(7259).A+"",width:"1600",height:"1361"})}),"\n",(0,o.jsxs)(n.p,{children:["We're excited to announce the v0.10.0 release of OPA. This release contains more than 60 commits from 8 authors across 5 organizations. For a detailed list of changes see the ",(0,o.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/releases",children:"GitHub releases"})," page."]}),"\n",(0,o.jsx)(n.h2,{id:"webassembly",children:"WebAssembly"}),"\n",(0,o.jsx)(n.p,{children:"This release adds experimental support for compiling OPA policies into WebAssembly (Wasm) binaries that can be executed in any Wasm runtime (e.g., V8)."}),"\n",(0,o.jsx)(n.p,{children:"The compiler is designed to be lightweight and embedded inside other programs. The package does not depend on any third-party compiler toolchains like LLVM or Wasm-specific toolchains like Emscripten. The compiled policies are fairly small in size (10KB for toy examples) and have no system call dependencies \u2014 making them easy to instantiate inside your app, serverless function, etc."}),"\n",(0,o.jsxs)(n.p,{children:["We are excited about the potential that Wasm brings to the policy enforcement space because it provides a portable, secure, and efficient runtime for answering policy queries. You can find out more about Wasm at ",(0,o.jsx)(n.a,{href:"https://webassembly.org/",children:"https://webassembly.org/"}),"."]}),"\n",(0,o.jsxs)(n.p,{children:["If you are feeling adventurous, you can try out the Wasm compiler today with the new ",(0,o.jsx)(n.code,{children:"opa build"})," command. We only support a limited subset of the language today but ",(0,o.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/issues/1024",children:"we plan to extend coverage over the next few months"}),". If you run into any problems, please file an issue on GitHub."]}),"\n",(0,o.jsx)(n.h2,{id:"improved-test-support-with-data-mocking",children:"Improved Test Support with Data Mocking"}),"\n",(0,o.jsxs)(n.p,{children:["This release adds support for replacing (or mocking) values under the ",(0,o.jsx)(n.code,{children:"data"})," document using the ",(0,o.jsx)(n.code,{children:"with"})," keyword. You can use the ",(0,o.jsx)(n.code,{children:"with"})," keyword to replace both external JSON loaded into OPA as well as JSON generated by rules."]}
1),"\n",(0,o.jsxs)(n.p,{children:["Prior to v0.10, OPA only allowed you to replace values under the ",(0,o.jsx)(n.code,{children:"input"})," document. This made it hard to test contextual policies using ",(0,o.jsx)(n.a,{href:"https://www.openpolicyagent.org/docs/how-do-i-test-policies.html",children:"OPA's test framework"}),'. For example, the following policy depends on "roles" data being loaded into OPA:']}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-rego",children:'package authz\n\nimport data.roles\n\ndefault allow = false\n\nallow {\n input.method == "GET"\n input.subject.role == roles[_]\n}\n'})}),"\n",(0,o.jsxs)(n.p,{children:["In v0.10.0, you can write a test rule that mocks the value of ",(0,o.jsx)(n.code,{children:"data.roles"})," using the ",(0,o.jsx)(n.code,{children:"with"})," keyword:"]}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-rego",children:'# Define some dummy inputs.\ndev_input = {"method": "GET", "subject": {"role": "dev"}}\nhr_input = {"method": "GET", "subject": {"role": "hr"}}\n\n# Define some dummy role data.\nfake_roles = ["hr"]\n\n# Test the allow rule.\ntest_allow {\n allow with input as hr_input with data.roles as fake_roles\n not allow with input as dev_input with data.roles as fake_roles\n}\n'})}),"\n",(0,o.jsx)(n.h2,{id:"partial-evaluation-negation-optimization",children:"Partial Evaluation: Negation Optimization"}),"\n",(0,o.jsx)(n.p,{children:"Earlier this year we added a feature called Partial Evaluation that helps pre-compute portions of your policy. Today, a large fragment of the language is covered by Partial Evaluation but some constructs are not fully supported."}),"\n",(0,o.jsxs)(n.p,{children:["Prior to v0.10, OPA would generate ",(0,o.jsx)(n.em,{children:"support rules"})," for negated expressions (which can be difficult to post-process.) This was required because Rego queries only consist of a series of expressions AND-ed together. If you need to express an OR condition, you need multiple queries. When you negate an expression (e.g., ",(0,o.jsx)(n.strong,{children:"not deny"}),'), the in-lined result may be a series of expressions OR-ed together. For example, given the following policy that says (in English) "no one is allowed to buy more bitcoin or eat pizza":']}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-rego",children:'allow {\n not deny\n}\n\ndeny {\n input.action = "buy"\n input.resource = "bitcoin"\n}\n\ndeny {\n input.action = "eat"\n input.resource = "pizza"\n}\n'})}),"\n",(0,o.jsxs)(n.p,{children:["We can partially evaluate the ",(0,o.jsx)(n.code,{children:"deny"})," rule to yield the following simplified queries:"]}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{children:'+---------+----------------------------+\n| Query 1 | input.action = "buy" |\n| | input.resource = "bitcoin" |\n+---------+----------------------------+\n| Query 2 | input.action = "eat" |\n| | input.resource = "pizza" |\n+---------+----------------------------+\n'})}),"\n",(0,o.jsxs)(n.p,{children:["However, it's a bit trickier to partially evaluate the ",(0,o.jsx)(n.code,{children:"allow"})," rule. OPA does not allow you to negate multiple expressions at once (you have to factor those expressions into a separate rule). In some cases though, it's reasonable to in-line the result of partially evaluating a negated expression by computing the cross-product. In this case the answer is:"]}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{children:'+---------+--------------------------------+\n| Query 1 | not input.action = "buy" |\n| | not input.action = "eat" |\n+---------+--------------------------------+\n| Query 2 | not input.action = "buy" |\n| | not input.resource = "pizza" |\n+---------+--------------------------------+\n| Query 3 | not input.resource = "bitcoin" |\n| | not input.action = "eat" |\n+---------+--------------------------------+\n| Query 4 | not input.resource = "bitcoin" |\n| | not input.resource = "pizza" |\n+---------+--------------------------------+\n'})}),"\n",(0,o.jsxs)(n.p,{children:["By in-lining negated expressions like this, we avoid the need for support rules (which are more difficult to optimize and ",(0,o.jsx)(n.a,{href:"/blog/write-policy-in-opa-enforce-policy-in-sql-d9d24db93bf4",children:"translate into other languages like SQL and Elasticsearch"}),".) Of course, the size of the cross-product can get quite big, so we put a cap on what OPA will in-line."]}),"\n",(0,o.jsx)(n.h2,{id:"more-great-contributions",children:"More Great Contributions"}),"\n",(0,o.jsx)(n.p,{children:"This release also included a many other contributions from members of the community. Here are some highlights:"}),"\n",(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/issues/884",children:"JWT decode & verify built-in function."})," This helps implement best practices around checking the aud, exp, and nbf
1claims automatically."]}),"\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/issues/684",children:"Client certificate support for service authentication."})," This allows services to authenticate OPA bundle download, status report, and decision log upload requests using client-side certificates (which may be preferred to bearer tokens.)"]}),"\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/issues/856",children:"Trace output in test failures."})," This helps policy authors debug test failures faster by pinpointing the source of the issue."]}),"\n",(0,o.jsx)(n.li,{children:"\u2026and many more!"}),"\n"]})]})}function u(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,o.jsx)(n,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.