On this page
Overview
Open Policy Agent is a general-purpose policy engine that expresses authorization and configuration decisions in Rego and evaluates them against input data through the CLI, REST API, Go SDK, or Wasm.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Move decisions into declarative policy
It accepts JSON describing users, actions, and resources and returns allow, deny, or configuration decisions.
Sources: [1]
Best fit
Fit shared controls across services and infrastructure
It fits API authorization, Kubernetes, Terraform, and CI where teams want consistent decisions outside application code.
Sources: [1]
Before adoption
Official sources
- [1]OPA README at v1.21.1(2026-10-05)
- [2]OPA policy testing documentation(2026-10-05)
- [3]OPA LICENSE at v1.21.1(2026-10-05)
- [4]OPA v1.21.1 release(2026-10-05)
Supplemental curator note
Define the input fields and types as a contract, then begin with a small default-deny policy. Keep allow and deny examples in the same test change to catch policy regressions.
Try it in 3 steps
- 1
Fetch the pinned OPA CLI
On Linux AMD64 with curl and zsh or bash, download the OPA v1.21.1 static CLI and make it executable.
mkdir opa-demo && cd opa-demo && curl -fsSLo opa https://github.com/open-policy-agent/opa/releases/download/v1.21.1/opa_linux_amd64_static && chmod +x opa - 2
Write a policy and tests
Write a default-deny Rego policy with role as its input contract plus unit tests for an allowed admin and denied reader.
printf '%s\n' 'package example.authz' 'import rego.v1' 'default allow := false' 'allow if input.role == "admin"' > policy.rego && printf '%s\n' 'package example.authz_test' 'import rego.v1' 'import data.example.authz.allow' 'test_admin if allow with input as {"role": "admin"}' 'test_reader_denied if not allow with input as {"role": "reader"}' > policy_test.rego - 3
Verify tests and a deny decision
Run opa test for both cases, then verify that the comparison asserting reader allow is false evaluates to true and exits with status 0.
./opa test . && ./opa eval --fail --data policy.rego --input <(printf '%s\n' '{"role":"reader"}') 'data.example.authz.allow == false'
Growth
Growth trends · Last 30 days
12,322 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 155
- Open PRs
- 12
- Issues opened
- 54
- Issues closed
- 108
- PRs opened
- 407
- PRs merged
- 369
Issues
54 / 108
Pull requests
407 / 369
Maintenance
- Median first response
- 4.1 hr
- Issue response rate
- 32.4% (12/37)
Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- opa
- policy
- declarative
- json
- compliance
- cloud-native
- authorization
- open-policy-agent
- Stars
- 12,322
- Forks
- 1,692
- Watchers
- 133
- Open issues
- 292
- Contributors
- 414
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 5, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- 1Panel37,104 Stars
1 shared tag(s) · 1 shared category(s) · Same language
centralize Linux server, Docker, web, database, backup, and AI operations in one privileged control plane
Go - minikube32,175 Stars
1 shared tag(s) · 1 shared category(s) · Same language
create a workstation Kubernetes cluster for pre-deployment testing
Go - Dokku32,168 Stars
1 shared tag(s) · 1 shared category(s) · Same language
turn a single Linux VM into a PaaS from git push through build, release, and routing
Go - Helm30,304 Stars
1 shared tag(s) · 1 shared category(s) · Same language
package Kubernetes applications as Charts and manage install, upgrade, and rollback as releases
Go - Consul30,091 Stars
1 shared tag(s) · 1 shared category(s) · Same language
combine service discovery, health checks, service mesh, and API gateway capabilities for distributed infrastructure
Go - Kyverno8,212 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Continuously apply policy as code through Kubernetes admission and background scans
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.