5 ms·
Co-author of OPA here. I’m happy to answer any questions about the project!
by tsandall 8y ago
Co-author of OPA here. I’m happy to answer any questions about the project!
- im_down_w_otp 8y agoHowdy! This having looked through the repo and docs, this feels to be very Prolog-y, or more specifically a fairly domain specific implementation of a thing that's otherwise generalized typically by Prolog. I'm really curious to hear if it was in any way informed or inspired by other logic programming systems, and/or what some of the more challenging aspects were of implementing a predicate logic system like this in Golang.
- tsandall 8y agoHello! The semantics are based on Datalog--but we've added a few features that make it more expressive than just plain Datalog. For example, OPA has first-class support for accessing nested data structures like JSON. At the same time, OPA does not support recursion today, however we've found you can get quite far without it. I don't think that Golang introduces any unique challenges for implementing a logic system, just the usual suspects like garbage collection, lack of generics, etc. Hope this helps.
- linux2647 8y agoIs there any way of including an external data source, like a database, instead of data documents? For example, the management hierarchy for my company lives in an ERP system and I'd like the data to be as up to date as possible. Also, are there any theoretical limits to how much data could be loaded in to OPA?
- tsandall 8y agoThere are a few ways of doing this. 1. You can include JSON data as input when you execute a policy query. In your example, you could include the management hierarchy or a user in a JWT that's provided as input to the policy query. 2. You can load JSON data into OPA out-of-band. OPA will cache this data in-memory and you can refer to it in your policies. There are two ways to do this. (a) use OPA's REST API to push data into the engine (e.g., PUT /v1/data/management/hierarchy <JSON body>) or (b) use OPA's Bundle feature to pull down bundles of policy and data from a remote endpoint. 3. If providing the data as input or out-of-band will not work, we have an experimental HTTP built-in function that you can call inside your policies to query the external data source on-the-fly when the policy is evaluated. This feature is still experimental but over time we intend to improve support for it (e.g., currently you can't mock out these built-in calls, but it's on the ROADMAP.) Regarding limits, OPA keeps policies and data in-memory, so you're limited by RAM on a single host.
- aappleby 8y ago"The Open Policy Agent (OPA) is an open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack." To someone who doesn't already know what a "policy engine" is, that intro is completely meaningless. Might want to at least move a tiny blurb from the later doc to that opening paragraph.
- tsandall 8y agoThanks, this is helpful. We'll look at improving the opening paragraph for the wider audience.
- scottybowl 8y agoWell, what is a policy engine?!
- martin1975 8y agoIs one of you Greek?
- tsandall 8y agoThere are no Greeks among the core contributors :-(
- martin1975 8y agoWas curious if the OPA acronym for the project is an allusion to a often used word among Greeks.. an exclamation during celebration or when lighting this deep fried goat cheese called saganaki after it's been sprayed with alcohol. Technically asking a question about the authors is a project question, so I'm not sure why I got downvoted :/.
- superdimwit 8y agoOPA!!!
- arkh 8y agoHow does it compare against XACML?
- tsandall 8y agoOPA draws some inspiration from XACML. For example, OPA helps systems separate policy decision-making from policy enforcement. Decoupling means that policy decisions can be more easily updated and more readily understood. XACML as a specification covers multiple things (e.g., access control language, overall architecture, etc.) If you wanted to map OPA to a component in XACML, it's closest to the PDP. That being said, OPA gives you a more expressive language to author policy. Also, OPA is intended to be used as building block in other systems. OPA exposes APIs to offload policy decisions from services and manage the policies and data that are evaluated. One of the non-goals of OPA is management-plane concerns around policy storage, policy administration, etc.
- perlgeek 8y agoIs there an example of a simple service that uses OPA for authorization?
- tsandall 8y agoThere are tutorials that show how to integrate OPA with different projects on the website. One of them is a simple Python-based HTTP service: https://www.openpolicyagent.org/docs/http-api-authorization.html https://www.openpolicyagent.org/docs/http-api-authorization....
- bjourne 8y agoBefore OPA existed, what policy engine did you use and why weren't you happy with what you had? If you didn't use a policy engine, why did you decide to create one rather than use an existing one?
- lawrenceong 8y agohello, does it enable HATEOAS? tks
- lawrenceong 8y agohi again, just watched the youtube where you presented OPA on KubeCon 2018. i'm interested in it, but it appears most of your use case is around infrastructure. do you have use cases where it is applied in the application itself? for example, you mentioned Netflix used it for their infrastructure -- would Netflix use this to manage all the paying subscriber functions too? I imagine functions such as 1. what movies are available to my region 2. is this profile allowed to watch a certain movie? 3. can i view my account settings? may be a good fit, but just wanted to be sure. another area may be in gaming, where new functions such as: 1. am i allowed to access this weapon 2. am i allowed to be on this terrain map 3. who my team members are may pop up. I have some application use cases that are very similar along these lines, so I'd like to know more about this before going in deeper to evaluate OPA. that being said, all looks positive and i thank you for the good work you have done, specially open sourcing it to make it available.
- tsandall 8y agoHello! You can certainly use OPA to answer the kinds of policy questions in your examples. OPA is not tied to a particular domain (which is why we call it general-purpose.) Whether you're writing policy over movies, games, etc. it's all the same to OPA (JSON).
- lawrenceong 8y agotks for getting back to me @tsandall. what i was wondering was OPA's performance scalability when it comes to millions of hits -- do you have any metrics or known implementations you can share with me?
- valenciarose 8y agoWhat about translation of rule subsets to other enforcement mechanisms? ACLs and rules for physical infrastructure like switches and routers being one possible target where embedding the agent itself may be impractical. I understand that SDN dominates the core infrastructure, but more traditional infrastructure is frequently in place closer to enterprise users. The point being defense in depth, rather than relying on physical infrastructure as a sole enforcement mechanism.