OSS TanbouSign in with GitHub

Define authorization and configuration rules in Rego and evaluate them separately

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
12,322
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 5, 2026
On this page

Overview

Open Policy Agent is a general-purpose policy engine that expresses authorization and configuration decisions in Rego and evaluates them against input data through the CLI, REST API, Go SDK, or Wasm.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Move decisions into declarative policy

It accepts JSON describing users, actions, and resources and returns allow, deny, or configuration decisions.

Sources: [1]

Best fit

Fit shared controls across services and infrastructure

It fits API authorization, Kubernetes, Terraform, and CI where teams want consistent decisions outside application code.

Sources: [1]

Before adoption

Operate policy tests and stable input contracts

Policy mistakes can affect many systems. Maintain Rego tests, input schemas, bundle delivery, and fail-open or fail-closed behavior with each change.

Sources: [1][3]

Official sources

  1. [1]OPA README at v1.21.1(2026-10-05)
  2. [2]OPA policy testing documentation(2026-10-05)
  3. [3]OPA LICENSE at v1.21.1(2026-10-05)
  4. [4]OPA v1.21.1 release(2026-10-05)
Supplemental curator note

Define the input fields and types as a contract, then begin with a small default-deny policy. Keep allow and deny examples in the same test change to catch policy regressions.

Try it in 3 steps

  1. 1

    Fetch the pinned OPA CLI

    On Linux AMD64 with curl and zsh or bash, download the OPA v1.21.1 static CLI and make it executable.

    mkdir opa-demo && cd opa-demo && curl -fsSLo opa https://github.com/open-policy-agent/opa/releases/download/v1.21.1/opa_linux_amd64_static && chmod +x opa
  2. 2

    Write a policy and tests

    Write a default-deny Rego policy with role as its input contract plus unit tests for an allowed admin and denied reader.

    printf '%s\n' 'package example.authz' 'import rego.v1' 'default allow := false' 'allow if input.role == "admin"' > policy.rego && printf '%s\n' 'package example.authz_test' 'import rego.v1' 'import data.example.authz.allow' 'test_admin if allow with input as {"role": "admin"}' 'test_reader_denied if not allow with input as {"role": "reader"}' > policy_test.rego
  3. 3

    Verify tests and a deny decision

    Run opa test for both cases, then verify that the comparison asserting reader allow is false evaluates to true and exits with status 0.

    ./opa test . && ./opa eval --fail --data policy.rego --input <(printf '%s\n' '{"role":"reader"}') 'data.example.authz.allow == false'
Check the official README

Growth

Growth trends · Last 30 days

12,322 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
155
Open PRs
12
Issues opened
54
Issues closed
108
PRs opened
407
PRs merged
369

Issues

54 / 108

Jul 8Oct 5
Issues openedIssues closed

Pull requests

407 / 369

Jul 8Oct 5
PRs openedPRs merged

Maintenance

Median first response
4.1 hr
Issue response rate
32.4% (12/37)

Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • opa
  • policy
  • declarative
  • json
  • compliance
  • cloud-native
  • authorization
  • open-policy-agent
Stars
12,322
Forks
1,692
Watchers
133
Open issues
292
Contributors
414
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 5, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?