There are 20 repositories under open-policy-agent topic.
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Policy and data administration, distribution, and real-time updates on top of Policy Agents (OPA, Cedar, ...)
Write tests against structured configuration data using the Open Policy Agent Rego query language
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.
A curated list of OPA related tools, frameworks and articles
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
A policy management tool for interacting with Gatekeeper
Regal is a linter and language server for Rego, bringing your policy development experience to the next level!
Integrations, examples, and proof-of-concepts that are not part of OPA proper.
SCuBA Secure Configuration Baselines and assessment tool for Google Workspace
Scan Kubernetes resource files , and helm charts for security configurations issues and best practices.
Style guide for Rego
Flux v1: Manage a multi-tenant cluster with Flux and Kustomize
This repository offers a comprehensive library of security policies designed to enhance the security of Kubernetes cluster configurations. The policies are developed in accordance with the CIS Kubernetes benchmark.
Create Kubernetes AdmissionReview requests from Kubernetes resource manifests
Open Policy Agent WebAssembly NPM module (opa-wasm)
Traefik plugin which checks JWT tokens for required fields. Supports Open Policy Agent (OPA) and signature validation with JWKS
An extension for VS Code which provides support for OPA and the Rego policy language
DevSpace Cloud ⚡ Turn Kubernetes into a Powerful Developer Platform (new on-premise edition)
Kubernetes Operator to manage Dynamic Admission Controllers using Open Policy Agent
Golang REST API Template
The Container Security Book—a free book for practitioners
HTTP/3-enable existing HTTP apps. Leverage HTTP3 native features and auto-enable workload identity (SPIFFE), AuthN (mTLS/x509, OIDC/Auth0-Okta), AuthZ (OPA), defense-in-depth (WAAP/WAF), and observability (metrics, logs, alerting, dashboard).
OPA Gatekeeper vs Kyverno
A set of shared policies for use with Conftest and other Open Policy Agent tools
Fastapi OPA middleware incl. auth flow.
This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)
Open Policy Agent (OPA) plug-in for Kafka authorization
Python client for Open Policy Agent
Experimental AWS ApiGateway Authorizer Go Lambda with embedded Open Policy Agent
Watch your in cluster Kubernetes manifests for OPA policy violations and export them as Prometheus metrics
OPA-Envoy-SPIRE External Authorization Example.
Call Open Policy Agent (OPA) policies in WASM (Web Assembly) from .NET Core
Implements OPA-based preventive security controls for AWS Infrastructure using Terraform Infrastructure as Code (IaC), that can establish a security baseline and safeguard resources before deployment into the AWS Accounts and reduce security risks.